• Vulnerability Summary for the Week of May 18, 2026

    From CISA@cisa@messages.cisa.gov to cisa@toolazy.synchro.net on Tue May 26 16:15:28 2026
    --===============4836405085985877004==
    Content-Type: multipart/alternative; boundary="===============5510240496706666731=="
    MIME-Version: 1.0

    --===============5510240496706666731==
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    Cybersecurity and Infrastructure Security Agency (CISA)

    You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrast= ructure Security Agency. This information has recently been updated and is = now available.

    The CISA Vulnerability Bulletin provides a summary of new vulnerabilities t= hat have been recorded in the past week. In some cases, the vulnerabilities=
    in the bulletin may not yet have assigned CVSS scores.

    Vulnerabilities are based on the=C2=A0Common Vulnerabilities and Exposures =
    [ https://www.cve.org/ ]=C2=A0(CVE) vulnerability naming standard and are o= rganized according to severity, determined by the=C2=A0Common Vulnerability=
    Scoring System [ https://www.cve.org/about/relatedefforts ]=C2=A0(CVSS) st= andard. The division of high, medium, and low severities correspond to the = following scores:


    * *High*: vulnerabilities with a CVSS base score of 7.0=E2=80=9310.0=20
    * *Medium*: vulnerabilities with a CVSS base score of 4.0=E2=80=936.9=20
    * *Low*: vulnerabilities with a CVSS base score of 0.0=E2=80=933.9=20

    Entries may include additional information provided by organizations and ef= forts sponsored by CISA. This information may include identifying informati= on, values, definitions, and related links. Patch information is provided w= hen available. Please note that some of the information in the bulletin is = compiled from external, open-source reports and is not a direct result of C= ISA analysis.

    Vulnerability Summary for the Week of May 18, 2026 [ https://www.cisa.gov/n= ews-events/bulletins/sb26-145 ] 05/26/2026 12:15 PM EDT=20
    High Vulnerabilities

    Primary
    Vendor -- Product Description Published CVSS Score Source Info 10-Strike--N= etwork Inventory Explorer 10-Strike Network Inventory Explorer 8.54 contain=
    s a stack-based buffer overflow vulnerability in the registration key input=
    field that allows local attackers to execute arbitrary code by triggering =
    a structured exception handler overwrite. Attackers can craft a malicious r= egistration key string with 4188 bytes of padding followed by SEH chain val= ues and shellcode, then paste it into the registration dialog to achieve co=
    de execution with application privileges. 2026-05-23 8.4 CVE-2018-25344 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2018-25344 ] 10-Strike--Network Scann=
    er 10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerabi= lity in the host name field that allows attackers to bypass SafeSEH protect= ions and execute arbitrary code. Attackers can craft a malicious payload in=
    the host name or address field and trigger the vulnerability through the T= race route or System information functions to achieve code execution. 2026-= 05-23 8.4 CVE-2018-25345 [ https://www.cve.org/CVERecord?id=3DCVE-2018-2534=
    5 ] 10Web--Form Maker WordPress Form Maker Plugin 1.12.24 and below contain=
    s SQL injection vulnerabilities that allow authenticated attackers to manip= ulate database queries by injecting SQL code through the FormMakerSQLMappin=
    g and generete_csv actions. Attackers can submit POST requests with malicio=
    us SQL payloads in the name and search_labels parameters to extract, modify=
    , or escalate privileges within the WordPress database. 2026-05-23 7.1 CVE-= 2018-25346 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25346 ] acyba--Acy= Mailing An Ultimate Newsletter Plugin and Marketing Automation Solution for=
    WordPress The AcyMailing - An Ultimate Newsletter Plugin and Marketing Aut= omation Solution for WordPress plugin for WordPress is vulnerable to Missin=
    g Authorization in versions up to, and including, 10.8.2. This is due to th=
    e plugin not properly verifying that a user is authorized to perform an act= ion. This makes it possible for authenticated attackers, with subscriber-le= vel access and above, to modify privileged AcyMailing configuration, export=
    subscriber secret keys, and chain these actions into administrator account=
    takeover when a target administrator email address is known. 2026-05-20 8.=
    8 CVE-2026-5200 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5200 ] Alinto= --SOGo Webmail SOGo versions 5.12.7 and prior contains a SQL injection vuln= erability in the Access Control List management functionality that allows a= uthenticated users to extract arbitrary data from the database by injecting=
    SQL subqueries through the uid parameter of the addUserInAcls endpoint. At= tackers can inject malicious SQL code to write extracted data into the sogo= _acl table and retrieve it through the /acls API, establishing an out-of-ba=
    nd data exfiltration channel. 2026-05-18 8.1 CVE-2026-8851 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-8851 ] Audiograbber--Audiograbber Audiograbbe=
    r 1.83 contains a local buffer overflow vulnerability that allows attackers=
    to execute arbitrary code by exploiting structured exception handling mech= anisms. Attackers can craft malicious input in the Interpret or Album field=
    s that triggers a buffer overflow, overwriting SEH pointers and executing i= njected shellcode with application privileges. 2026-05-23 8.4 CVE-2018-2535=
    5 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25355 ] AWS--Amazon Braket = Python SDK Insecure deserialization in the job results processing component=
    in Amazon Braket SDK before=C2=A01.117.0 might allow a remote authenticate=
    d user with S3 write access to the job output bucket to achieve arbitrary c= ode execution on any machine that processes job results. We recommend you u= pgrade to amazon-braket-sdk version 1.117.0 or later. 2026-05-22 7.1 CVE-20= 26-9291 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9291 ] AWS--Amazon Re= dshift connector for Python Unsafe use of Python's eval() on server-receive=
    d data in the vector_in() function in amazon-redshift-python-driver before = 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrar=
    y code on the client. To remediate this issue, users should upgrade to vers= ion 2.1.14. 2026-05-18 9.8 CVE-2026-8838 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8838 ] AWS--Kiro CLI Missing input source validation in the too=
    l authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to=
    execute arbitrary tools, including shell commands, without user approval b=
    y crafting content that is piped to kiro-cli via stdin. We recommend you to=
    upgrade to kiro-cli version 1.28.0 or later. 2026-05-22 7.8 CVE-2026-9255 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-9255 ] AWS--RabbitMQ AWS Acti=
    ve debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before v= ersion 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /= api/aws/arn/validate validation endpoint might allow remote authenticated u= sers to perform arbitrary file reads on any file accessible to the RabbitMQ=
    process. To remediate this issue, customers should upgrade to version 0.2.=
    1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we=
    also recommend rotating any associated private certificate keys. 2026-05-2=
    0 7.7 CVE-2026-9133 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9133 ] ba= ptisteArno--typebot.io Typebot is a chatbot builder tool. In versions 3.15.=
    2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/p= review/startChat) allows unauthenticated users to achieve Server-Side Reque=
    st Forgery (SSRF) by supplying a custom typebot definition with server-side=
    code blocks. The fetch function exposed inside the isolated-vm sandbox cal=
    ls Node.js native fetch without the SSRF validation (validateHttpReqUrl) th=
    at protects the HTTP Request block. This bypasses all SSRF mitigations adde=
    d after GHSA-8gq9-rw7v-3jpr. Exploitation of this unauthenticated SSRF vuln= erability can lead to cloud credential theft, internal network access and d= ata exfiltration for any self-hosted Typebot deployments and hosted service=
    s. This issue has been fixed in version 3.16.0. 2026-05-22 10 CVE-2026-3371=
    2 [ https://www.cve.org/CVERecord?id=3DCVE-2026-33712 ] baptisteArno--typeb= ot.io Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the = RatingButton component in the embed package renders the user-controlled cus= tomIcon.svg field directly via Solid's innerHTML directive without any sani= tization, even though DOMPurify is already a dependency and is used elsewhe=
    re in the codebase (e.g., StreamingBubble.tsx). Because rating blocks are n=
    ot flagged as isUnsafe by the import sanitizer and the builder preview rend= ers bots inline on the builder's own origin (builder.typebot.io) under a CS=
    P permitting 'unsafe-inline', a malicious imported or collaborator-crafted = typebot can execute arbitrary HTML/JS in the builder's authenticated contex=
    t, bypassing the Web Worker sandbox that protects Script blocks during prev= iew. This allows session hijacking and privilege escalation within the buil= der application. This issue has been fixed in version 3.16.0. 2026-05-22 8.=
    7 CVE-2026-28445 [ https://www.cve.org/CVERecord?id=3DCVE-2026-28445 ] bapt= isteArno--typebot.io TypeBot is a chatbot builder tool. In versions prior t=
    o 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only = the URL string, blocked hostname literals, and literal IP formats. It does = not resolve DNS before allowing the request. As a result, a hostname such a=
    s ssrf-repro.example that resolves to 127.0.0.1, 169.254.169.254, or RFC191= 8/private space passes validation and is later fetched by the backend HTTP = client. This enables server-side request forgery to loopback, cloud metadat=
    a, and private network targets. This issue has been resolved in version 3.1= 6.0. 2026-05-22 7.6 CVE-2026-34207 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-34207 ] baptisteArno--typebot.io TypeBot is a chatbot builder tool. V= ersions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HT=
    TP Request block and Code block validate the initial request URL via valida= teHttpReqUrl() to block private IPs and cloud metadata hostnames. However, = the HTTP clients (ky and fetch) follow 302 redirects without re-validating = the redirect destination. An authenticated user can point a bot block to an=
    attacker-controlled server that responds with a redirect to an internal IP=
    , causing the Typebot server to reach internal services. An authenticated T= ypebot user can reach AWS metadata (169.254.169.254), private subnets, and = container-internal services. Exploitable to extract cloud IAM credentials o=
    r probe internal APIs inaccessible from the internet. This issue has been f= ixed in version 3.16.0. 2026-05-22 7.7 CVE-2026-39965 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-39965 ] baptisteArno--typebot.io TypeBot is a chat= bot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-= jw47 ("Credential Theft via Client-Side Script Execution and API Authorizat= ion Bypass") is incomplete. While the builder's getCredentials tRPC endpoin=
    t was patched with workspace membership checks, the bot-engine runtime stil=
    l allows any authenticated user to use credentials from any workspace via t=
    he preview chat endpoint. The bot-engine's getCredentials() utility functio=
    n uses a falsy check (if (workspaceId && ...)) for workspace ownership vali= dation. Since the preview endpoint accepts a client-controlled workspaceId = field and the Zod schema allows empty strings, an attacker can supply works= paceId: "" to bypass credential ownership verification entirely. Exploitati=
    on can result in credential exfiltration, external service abuse, financial=
    damage and a data breach. 2026-05-22 7.1 CVE-2026-39968 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-39968 ] Basamak Information Technology Consulti=
    ng and Organization Trade Ltd. Co.--DernekWeb Improper neutralization of in= put during web page generation ('cross-site scripting') vulnerability in Ba= samak Information Technology Consulting and Organization Trade Ltd. Co. Der= nekWeb allows Stored XSS. This issue affects DernekWeb: through 30122025. 2= 026-05-18 8.8 CVE-2026-7498 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7= 498 ] Behance--Smartshop Smartshop 1 contains a SQL injection vulnerability=
    that allows unauthenticated attackers to execute arbitrary SQL queries by = injecting malicious code through the id parameter. Attackers can send GET r= equests to category.php with UNION-based SQL injection payloads in the id p= arameter to extract sensitive database information including usernames and = other data. 2026-05-23 8.2 CVE-2018-25340 [ https://www.cve.org/CVERecord?i= d=3DCVE-2018-25340 ] Behance--Smartshop Smartshop 1 contains a SQL injectio=
    n vulnerability that allows unauthenticated attackers to execute arbitrary = SQL queries by injecting malicious code through the id parameter. Attackers=
    can send GET requests to product.php with union-based SQL injection payloa=
    ds in the id parameter to extract sensitive database information including = usernames and database names. 2026-05-23 8.2 CVE-2018-25341 [ https://www.c= ve.org/CVERecord?id=3DCVE-2018-25341 ] Behance--Smartshop Smartshop 1 conta= ins a time-based blind SQL injection vulnerability that allows unauthentica= ted attackers to manipulate database queries by injecting SQL code through = the 'searched' parameter in search.php. Attackers can send GET requests wit=
    h malicious SQL payloads like SLEEP commands to extract sensitive database = information including product details and system data. 2026-05-23 8.2 CVE-2= 018-25342 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25342 ] BerriAI--li= tellm LiteLLM prior to 1.83.14 allows an authenticated internal_user to cre= ate API keys with access to routes that their role does not permit. When ge= nerating a key, the allowed_routes field is stored without verifying that t=
    he specified routes fall within the user's own permissions. A key created w= ith access to admin-only routes can then be used to reach those routes succ= essfully, bypassing the role-based access controls that would otherwise blo=
    ck the request, enabling full privilege escalation from internal_user to pr= oxy_admin. 2026-05-21 8.8 CVE-2026-47101 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-47101 ] BerriAI--litellm LiteLLM prior to 1.83.10 allows a user=
    to modify their own user_role via the /user/update endpoint. While the end= point correctly restricts users to updating only their own account, it does=
    not restrict which fields may be changed. A user who can reach this endpoi=
    nt can set their role to proxy_admin, gaining full administrative access to=
    LiteLLM including all users, teams, keys, models, and prompt history. User=
    s with the org_admin role have legitimate access to this endpoint and can e= xploit this vulnerability without chaining any additional flaw. 2026-05-21 = 8.8 CVE-2026-47102 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47102 ] Be= sen--BS20 EV Charging Station A weakness has been identified in Besen BS20 =
    EV Charging Station up to 20260426. Affected by this issue is some unknown = functionality of the component OTA Update Installation Handler. This manipu= lation causes improper authorization. The attack is possible to be carried = out remotely. A high degree of complexity is needed for the attack. The exp= loitation is known to be difficult. The original disclosure mentions, that = "[t]hese vulnerabilities have been reported to Besen and we have received t= heir acknowlegement that they are reviewing this as of April 2026." 2026-05= -24 8.1 CVE-2026-9397 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9397 ] = bestpractical--rt RT is an open source, enterprise-grade issue and ticket t= racking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contai=
    n an SQL injection vulnerability. An authenticated user can craft input tha=
    t is incorporated into database queries without proper validation, potentia= lly allowing them to read or modify data in the RT database. This issue has=
    been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgra=
    de immediately, they can temporarily work around this issue by restricting =
    RT account access to trusted users. 2026-05-22 8.8 CVE-2026-41075 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-41075 ] bestpractical--rt RT is an ope=
    n source, enterprise-grade issue and ticket tracking system. Versions 5.0.9=
    and prior in addition to 6.0.0 through 6.0.2 contain an authentication byp= ass vulnerability in RT installations that use LDAP/AD for user authenticat= ion. Under certain LDAP server configurations, an attacker may be able to a= uthenticate as any LDAP-backed RT user without supplying valid credentials.=
    This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are = unable to upgrade immediately, they can temporarily work around this issue =
    by reviewing their LDAP server's authentication policy to ensure it rejects=
    unauthenticated bind attempts. Upgrading RT remains the recommended fix. 2= 026-05-22 8.1 CVE-2026-41076 [ https://www.cve.org/CVERecord?id=3DCVE-2026-= 41076 ] bestpractical--rt RT is an open source, enterprise-grade issue and = ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site R= equest Forgery (CSRF) vulnerability. An attacker who can induce a logged-in=
    RT user to visit a malicious web page can trigger arbitrary state-changing=
    actions in RT on that user's behalf. This issue has been fixed in version = 6.0.3. 2026-05-22 7.1 CVE-2026-41074 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-41074 ] Beyaz Computer Software Design Industry and Trade Ltd. Co.-= -CityPLus Improper neutralization of input during web page generation ('cro= ss-site scripting') vulnerability in Beyaz Computer Software Design Industr=
    y and Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects City= PLus: before V24.29750.1.0. 2026-05-20 7.6 CVE-2026-5783 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-5783 ] beycanpress--Account Switcher The Accoun=
    t Switcher plugin for WordPress is vulnerable to Privilege Escalation in al=
    l versions up to, and including, 1.0.2. This is due to the `rememberLogin` = REST API endpoint using a loose comparison (`!=3D` instead of `!=3D=3D`) fo=
    r secret validation at `app/RestAPI.php:111`, combined with no validation t= hat the secret is non-empty. When a target user has never used the "Remembe=
    r me" feature, their `asSecret` user meta does not exist, causing `get_user= _meta()` to return an empty string. An attacker can send an empty `secret` = parameter, which passes the comparison (`'' !=3D ''` is `false`), and the e= ndpoint then calls `wp_set_auth_cookie()` for the target user. Additionally=
    , all REST routes use `permission_callback =3D> '__return_true'` with no ca= pability checks. This makes it possible for authenticated attackers, with S= ubscriber-level access and above, to switch to any user account including A= dministrator, ultimately granting themselves full administrative privileges=
    . 2026-05-20 8.8 CVE-2026-6456 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-6456 ] Cisco--Cisco Secure Workload A vulnerability in the access va= lidation of internal REST APIs of Cisco Secure Workload could allow an unau= thenticated, remote attacker to access site resources with the privileges o=
    f the Site Admin role. This vulnerability is due to insufficient valid= ation and authentication when accessing REST API endpoints. An attacker cou=
    ld exploit this vulnerability if they are able to send a crafted API reques=
    t to an affected endpoint. A successful exploit could allow the attacker to=
    read sensitive information and make configuration changes across tenant bo= undaries with the privileges of the Site Admin user.  2026-05-20 =
    10 CVE-2026-20223 [ https://www.cve.org/CVERecord?id=3DCVE-2026-20223 ] Con= nectWise--Automate The ConnectWise Automate=C3=A2=E2=80=9E=C2=A2 Agent does=
    not fully verify the authenticity of components obtained during plugin loa= ding and self-update operations. This issue is addressed in Automate 2026.5=
    . 2026-05-21 8.8 CVE-2026-9089 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-9089 ] constantcontact--Creative Mail Easier WordPress & WooCommerce Emai=
    l Marketing The Creative Mail - Easier WordPress & WooCommerce Email Market= ing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_u= uid' parameter in all versions up to, and including, 1.6.9. This is due to = insufficient escaping on the user supplied parameter and lack of sufficient=
    preparation on the existing SQL query in the `has_checkout_consent()` meth= od. This makes it possible for unauthenticated attackers to append addition=
    al SQL queries into already existing queries that can be used to extract se= nsitive information from the database. 2026-05-20 7.5 CVE-2026-3985 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-3985 ] contest-gallery--Contest Gall= ery Upload & Vote Photos, Media, Sell with PayPal & Stripe The Contest Gall= ery plugin for WordPress is vulnerable to SQL Injection via the 'form_input=
    ' parameter in versions up to, and including, 28.1.6. This is due to insuff= icient escaping on the user supplied parameter and lack of sufficient prepa= ration on the existing SQL query inside the unauthenticated 'post_cg_galler= y_form_upload' AJAX action (specifically the 'cb' branch of the included us= ers-upload-check.php, where $f_input_id is concatenated unquoted into 'SELE=
    CT Field_Content FROM ... WHERE id =3D $f_input_id'). The endpoint is gated=
    only by a public frontend nonce ('cg1l_action' / 'cg_nonce') that is expos=
    ed in the page source of any public gallery page. This makes it possible fo=
    r unauthenticated attackers to append additional SQL queries into already e= xisting queries that can be used to extract sensitive information from the = database. 2026-05-19 7.5 CVE-2026-8912 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8912 ] cssigniterteam--AudioIgniter Music Player The AudioIgnit=
    er plugin for WordPress is vulnerable to Insecure Direct Object Reference i=
    n versions up to, and including, 2.0.2. This is due to the handle_playlist_= endpoint() function (hooked to template_redirect) accepting a user-controll=
    ed playlist ID via the audioigniter_playlist_id query var or the /audioigni= ter/playlist/{id}/ rewrite rule and returning playlist track data without p= erforming any authentication, capability, or post_status check - only the p= ost_type is validated. This makes it possible for unauthenticated attackers=
    to view track metadata (titles, artists, audio URLs, buy links, download U= RLs, and cover images) of any playlist on the site, including those in draf=
    t, private, pending, or trash status. 2026-05-22 7.5 CVE-2026-8679 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-8679 ] Ctrlpanel-gg--panel CtrlPanel =
    is open-source billing software for hosting providers. In versions 1.1.1 an=
    d prior, the web-based installer (public/installer/index.php) is vulnerable=
    to unauthenticated Remote Code Execution (RCE) because it performs the ins= tall.lock check only after including and executing form handler files, leav= ing installer endpoints reachable on already-installed instances. The handl= ers also pass unsanitized user input directly into shell commands, allowing=
    an attacker to submit crafted requests that execute arbitrary commands on = the server. The vulnerability stems from two combined weaknesses: (1) prema= ture form handler execution before the lock file gate, and (2) unsafe use o=
    f user input in shell command construction. This issue is reported to be ac= tively exploited in the wild. The issue has been fixed in version 1.2.0. 20= 26-05-19 10 CVE-2026-34234 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34= 234 ] Ctrlpanel-gg--panel CtrlPanel is open-source billing software for hos= ting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Script= ing (XSS) vulnerability in the ticket reply notification system. Unsanitize=
    d reply content ($newmessage) is stored directly in database notification p= ayloads and later rendered unescaped via Blade's {!! !!} syntax in the reci= pient's browser. The flaw exists in both App\Notifications\Ticket\Admin\Adm= inReplyNotification (triggered when a user replies, targeting admins) and A= pp\Notifications\Ticket\User\ReplyNotification (triggered when an admin rep= lies, targeting users), allowing arbitrary JavaScript execution in the vict= im's session context. A low-privileged attacker can exploit this to hijack = admin sessions, harvest credentials via fake login prompts or keyloggers, a=
    nd escalate privileges by performing administrative actions on the victim's=
    behalf. The reverse path also enables a malicious or compromised admin to = target regular users in the same manner. This issue has been fixed in versi=
    on 1.2.0. 2026-05-19 8.7 CVE-2026-34241 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-34241 ] Ctrlpanel-gg--panel CtrlPanel is open-source billing so= ftware for hosting providers. Versions 1.1.1 and prior contains a broken ac= cess control vulnerability where multiple admin controllers enforce permiss= ion checks on form display methods but omit equivalent checks on the corres= ponding write methods, allowing any authenticated user to bypass RBAC via d= irect POST/PATCH requests. Controllers missing checks on write methods stor= e() and update() include ApplicationApiController (admin.api.write), Coupon= Controller (admin.coupons.write), PartnerController (admin.partners.write),=
    ShopProductController (admin.store.write), UsefulLinkController (admin.use= ful_links.write), and VoucherController (admin.voucher.write); ProductContr= oller (admin.products.edit), ServerController (write/change_owner/change_id= entifier), and UserController (write/change_email/change_credits/change_use= rname/change_password/change_role/change_referral/change_ptero/change_serve= rlimit) are missing checks on update() only, and ActivityLogController expo= sed empty stub store()/update() methods that silently accepted any request.=
    An authenticated attacker without admin write privileges can issue API cre= dentials, generate unlimited coupons and vouchers, assign arbitrary partner=
    commission and discount rates, alter shop product pricing and limits, reas= sign server ownership or identifiers, and modify user accounts including ro= les, credits, passwords, and linked Pterodactyl IDs to achieve full privile=
    ge escalation, as well as abuse logBackIn() without the login_as permission=
    to interfere with admin impersonation sessions. This issue has been fixed =
    in version 1.2.0. 2026-05-19 8.1 CVE-2026-34358 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-34358 ] D-Link--DIR-601 D-Link DIR601 2.02NA contains a = credential disclosure vulnerability that allows unauthenticated attackers t=
    o retrieve sensitive configuration data by manipulating the table_name para= meter in POST requests. Attackers can send requests to /my_cgi.cgi with tab= le_name values like admin_user, wireless_settings, and wireless_security to=
    extract administrative credentials and wireless network keys in clear text=
    . 2026-05-23 7.5 CVE-2018-25358 [ https://www.cve.org/CVERecord?id=3DCVE-20= 18-25358 ] Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, vers= ion(s) <=3D4.6.2, contain(s) an Exposure of Information Through Directory L= isting vulnerability. An unauthenticated attacker with remote access could = potentially exploit this vulnerability, leading to Information exposure. 20= 26-05-20 7.5 CVE-2025-32750 [ https://www.cve.org/CVERecord?id=3DCVE-2025-3= 2750 ] Digital Operations Services Inc.--WifiBurada Exposure of private per= sonal information to an unauthorized actor, Insufficiently Protected Creden= tials vulnerability in Digital Operations Services Inc. WifiBurada allows A= uthentication Bypass. This issue affects WifiBurada: through 21052026.=C2= =A0NOTE: The vendor was contacted early about this disclosure but did not r= espond in any way. 2026-05-21 7.1 CVE-2025-13477 [ https://www.cve.org/CVER= ecord?id=3DCVE-2025-13477 ] Divi Engine--Divi Form Builder The Divi Form Bu= ilder plugin for WordPress is vulnerable to privilege escalation in version=
    s up to, and including, 5.1.2. This is due to the plugin accepting a user-c= ontrolled 'role' parameter from POST data during user registration without = validating it against the form's configured default_user_role setting. This=
    makes it possible for unauthenticated attackers to create administrator ac= counts by tampering with the role parameter during registration. 2026-05-21=
    9.8 CVE-2026-5118 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5118 ] Doc= ker--Docker Desktop The vllm-metal inference backend in Docker Model Runner=
    on macOS unconditionally sets trust_remote_code=3DTrue when loading model = tokenizers, and runs without sandboxing. This causes transformers.AutoToken= izer.from_pretrained() to import and execute arbitrary Python files include=
    d in any model pulled from an OCI registry, resulting in arbitrary code exe= cution on the Docker host as the Docker Desktop user when inference is trig= gered. Any container on the Docker network can trigger this by calling the = model-runner.docker.internal API to pull a malicious model and request infe= rence. 2026-05-22 8.2 CVE-2026-5817 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-5817 ] Docker--Docker Desktop The MLX inference backend in Docker Mo= del Runner on macOS uses the MLX-LM library, which unconditionally imports = and executes arbitrary Python files from model directories via the model_fi=
    le configuration field in config.json. When a model's config.json specifies=
    a model_file pointing to a Python file, MLX-LM uses importlib to load and = execute it with no trust_remote_code gate or equivalent safety check. The M=
    LX backend runs without sandboxing, resulting in arbitrary code execution o=
    n the Docker host as the Docker Desktop user. Any container on the Docker n= etwork can trigger this by calling the model-runner.docker.internal API to = pull a malicious model from an attacker-controlled OCI registry and request=
    inference. 2026-05-22 8.2 CVE-2026-5843 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-5843 ] Docker--Docker Desktop The Docker CLI --use-api-socket f= lag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desk= top. When ECI is enabled, Docker socket mounts from containers are denied u= nless explicitly allowed via the admin-settings configuration. However, the=
    --use-api-socket flag adds the Docker socket mount via the HostConfig.Moun=
    ts field rather than the HostConfig.Binds field. The ECI enforcement in the=
    Docker Desktop API proxy only inspected Binds, allowing the mount to pass = unchecked. This grants a container full access to the Docker Engine socket = and, if the host user has logged in to container registries, their authenti= cation credentials. A local attacker with the ability to run Docker CLI com= mands can exploit this to escape ECI restrictions, access the Docker Engine=
    , and potentially escalate privileges. 2026-05-22 8.8 CVE-2026-6406 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-6406 ] Dokploy--dokploy Dokploy is a=
    free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and belo=
    w have OS command injection through the appName parameter. 3 chained issues=
    cause this problem: inadequate input sanitization, lack of schema validati=
    on and direct shell interpolation. User-controlled application names are pa= ssed through inadequate sanitization (cleanAppName function only replaces s= paces and converts to lowercase) before being interpolated directly into sh= ell commands executed via execAsync() and execAsyncRemote(). An authenticat=
    ed attacker can inject shell metacharacters (e.g., ;, $(), backticks, |, &)=
    in the appName field during application creation, which are then executed = with server-level privileges when service operations (start, stop, remove, = scale) are triggered. This issue has been resolved in version 0.26.7. 2026-= 05-18 9.9 CVE-2026-27130 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2713=
    0 ] Dolibarr--Dolibarr ERP CRM Dolibarr ERP CRM 7.0.3 contains a remote cod=
    e execution vulnerability that allows unauthenticated attackers to execute = arbitrary code by injecting PHP code through the db_name parameter. Attacke=
    rs can send a POST request to install/step1.php with malicious PHP code in = the db_name parameter, then execute commands via the check.php endpoint usi=
    ng the cmd GET parameter. 2026-05-23 9.8 CVE-2018-25357 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2018-25357 ] Drupal--Drupal core Improper Neutralizat= ion of Special Elements used in an SQL Command ('SQL Injection') vulnerabil= ity in Drupal Drupal core allows SQL Injection. This issue affects Drupal c= ore: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 bef= ore 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11= .3.0 before 11.3.10. 2026-05-20 9.8 CVE-2026-9082 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-9082 ] DumbWareio--DumbAssets DumbAssets through 1.0.1=
    1 contains a path traversal vulnerability in the POST /api/delete-file endp= oint and filesToDelete array parameters that allows unauthenticated attacke=
    rs to delete arbitrary files by supplying ../ sequences that bypass directo=
    ry boundary validation. Attackers can exploit the optional and disabled-by-= default authentication control to traverse outside the intended application=
    directory and delete critical files such as server.js or package.json, cau= sing complete denial of service. 2026-05-18 9.1 CVE-2026-45230 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-45230 ] Eclipse Foundation--Eclipse Glass= fish An authenticated Remote Code Execution (RCE) vulnerability was identif= ied in GlassFish's Administration Console. A user with access to the panel = can send crafted requests that allow the execution of arbitrary operating s= ystem commands with the privileges of the application service user. 2026-05= -19 9.1 CVE-2026-2586 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2586 ] = Eclipse Foundation--Eclipse Glassfish A critical Remote Code Execution (RCE=
    ) vulnerability was identified in the server-side template rendering mechan= ism used by the Glassfish gadget handler. The application processes .xml fi= les and evaluates user-supplied values within a context where Expression La= nguage (EL) "expressions" are processed without proper sanitization or esca= ping. By injecting expressions such as #{7*7}, the server returns 49, confi= rming server-side EL evaluation. This issue allows a remote attacker to ful=
    ly compromise the underlying host, enabling capabilities as reading/modifyi=
    ng data, executing arbitrary commands, persistence, and lateral movement. 2= 026-05-19 9.6 CVE-2026-2587 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2= 587 ] Edimax--BR-6428NS A flaw has been found in Edimax BR-6428NS 1.10. Thi=
    s affects the function formL2TPSetup of the file /goform/formL2TPSetup of t=
    he component POST Request Handler. This manipulation of the argument L2TPUs= erName causes buffer overflow. It is possible to initiate the attack remote= ly. The exploit has been published and may be used. The vendor was contacte=
    d early about this disclosure but did not respond in any way. 2026-05-18 8.=
    8 CVE-2026-8775 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8775 ] Edimax= --BR-6428NS A vulnerability has been found in Edimax BR-6428NS 1.10. This v= ulnerability affects the function formPPTPSetup of the file /goform/formPPT= PSetup of the component POST Request Handler. Such manipulation of the argu= ment pptpUserName leads to buffer overflow. It is possible to launch the at= tack remotely. The exploit has been disclosed to the public and may be used=
    . The vendor was contacted early about this disclosure but did not respond =
    in any way. 2026-05-18 8.8 CVE-2026-8776 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8776 ] Edimax--BR-6428NS A vulnerability was identified in Edim=
    ax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup o=
    f the file /goform/formWanTcpipSetup of the component POST Request Handler.=
    Such manipulation of the argument pppUserName leads to buffer overflow. It=
    is possible to launch the attack remotely. The exploit is publicly availab=
    le and might be used. The vendor was contacted early about this disclosure = but did not respond in any way. 2026-05-23 8.8 CVE-2026-9294 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-9294 ] Edimax--BR-6428NS A security flaw ha=
    s been discovered in Edimax BR-6428NS 1.10. This affects the function formW= irelessTbl of the file /goform/formWirelessTbl of the component POST Reques=
    t Handler. Performing a manipulation of the argument vapurl results in buff=
    er overflow. The attack can be initiated remotely. The exploit has been rel= eased to the public and may be used for attacks. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-05-23 8.8 C= VE-2026-9295 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9295 ] Edimax--B= R-6675nD A security vulnerability has been detected in Edimax BR-6675nD 1.1=
    2. Affected is the function formL2TPSetup of the file /goform/formL2TPSetup=
    of the component POST Request Handler. Such manipulation of the argument L= 2TPUserName leads to buffer overflow. The attack can be launched remotely. = The exploit has been disclosed publicly and may be used. The vendor was con= tacted early about this disclosure but did not respond in any way. 2026-05-=
    24 8.8 CVE-2026-9380 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9380 ] E= dimax--BR-6675nD A vulnerability was detected in Edimax BR-6675nD 1.12. Aff= ected by this vulnerability is the function formPPPoESetup of the file /gof= orm/formPPPoESetup of the component POST Request Handler. Performing a mani= pulation of the argument pppUserName results in buffer overflow. The attack=
    may be initiated remotely. The exploit is now public and may be used. The = vendor was contacted early about this disclosure but did not respond in any=
    way. 2026-05-24 8.8 CVE-2026-9381 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-9381 ] Edimax--BR-6675nD A flaw has been found in Edimax BR-6675nD 1.= 12. Affected by this issue is the function formPPTPSetup of the file /gofor= m/formPPTPSetup of the component POST Request Handler. Executing a manipula= tion of the argument pptpUserName can lead to buffer overflow. The attack m=
    ay be launched remotely. The exploit has been published and may be used. Th=
    e vendor was contacted early about this disclosure but did not respond in a=
    ny way. 2026-05-24 8.8 CVE-2026-9382 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-9382 ] Edimax--BR-6675nD A vulnerability was detected in Edimax BR-= 6675nD 1.12. This vulnerability affects the function formsetPPPoE of the fi=
    le /goform/formsetPPPoE of the component POST Request Handler. Performing a=
    manipulation of the argument pppUserName results in buffer overflow. It is=
    possible to initiate the attack remotely. The exploit is now public and ma=
    y be used. The vendor was contacted early about this disclosure but did not=
    respond in any way. 2026-05-24 8.8 CVE-2026-9399 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-9399 ] Edimax--BR-6675nD A vulnerability has been foun=
    d in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of t=
    he file /goform/formWanTcpipSetup of the component POST Request Handler. Th=
    e manipulation of the argument pppUserName leads to buffer overflow. The at= tack can be initiated remotely. The exploit has been disclosed to the publi=
    c and may be used. The vendor was contacted early about this disclosure but=
    did not respond in any way. 2026-05-24 8.8 CVE-2026-9401 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-9401 ] Edimax--BR-6675nD A vulnerability was d= etermined in Edimax BR-6675nD 1.12. The impacted element is the function fo= rmWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST R= equest Handler. This manipulation of the argument selSSID causes buffer ove= rflow. The attack may be initiated remotely. The exploit has been publicly = disclosed and may be utilized. The vendor was contacted early about this di= sclosure but did not respond in any way. 2026-05-24 8.8 CVE-2026-9403 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-9403 ] Edimax--EW-7438RPn A securi=
    ty vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The imp= acted element is an unknown function of the file /goform/formWpsStart of th=
    e component webs. Such manipulation of the argument pinCode/wlan-url leads =
    to stack-based buffer overflow. The attack can be executed remotely. The ex= ploit has been disclosed publicly and may be used. The vendor was contacted=
    early about this disclosure but did not respond in any way. 2026-05-24 8.8=
    CVE-2026-9344 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9344 ] Edimax-= -EW-7438RPn A vulnerability was detected in Edimax EW-7438RPn up to 1.31. T= his affects the function formWizSurvey of the file /goform/formWizSurvey of=
    the component webs. Performing a manipulation of the argument ssid/manuals= sid/ip/mask/gateway results in buffer overflow. The attack is possible to b=
    e carried out remotely. The exploit is now public and may be used. The vend=
    or was contacted early about this disclosure but did not respond in any way=
    . 2026-05-24 8.8 CVE-2026-9345 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-9345 ] Edimax--EW-7438RPn A flaw has been found in Edimax EW-7438RPn up t=
    o 1.31. This impacts the function formWirelessTbl of the file /goform/formW= irelessTbl of the component webs. Executing a manipulation of the argument = submit-url can lead to buffer overflow. The attack may be performed from re= mote. The exploit has been published and may be used. The vendor was contac= ted early about this disclosure but did not respond in any way. 2026-05-24 = 8.8 CVE-2026-9346 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9346 ] Edim= ax--EW-7438RPn A vulnerability was found in Edimax EW-7438RPn up to 1.31. A= ffected by this vulnerability is an unknown functionality of the file /gofo= rm/mp of the component webs. The manipulation of the argument webs results =
    in stack-based buffer overflow. It is possible to launch the attack remotel=
    y. The exploit has been made public and could be used. The vendor was conta= cted early about this disclosure but did not respond in any way. 2026-05-24=
    8.8 CVE-2026-9348 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9348 ] Edi= max--EW-7438RPn A security flaw has been discovered in Edimax EW-7438RPn 1.= 28a. Affected by this issue is the function formwlencrypt24g of the file /g= oform/formwlencrypt24g of the component POST Request Handler. The manipulat= ion of the argument key1 results in buffer overflow. The attack can be laun= ched remotely. The exploit has been released to the public and may be used = for attacks. The vendor was contacted early about this disclosure but did n=
    ot respond in any way. 2026-05-24 8.8 CVE-2026-9360 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-9360 ] edmonparker--Read More & Accordion The Read M= ore & Accordion plugin for WordPress is vulnerable to Privilege Escalation =
    in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAja= x::importData' function not restricting which database tables can be writte=
    n to during import and not properly validating the imported data. This make=
    s it possible for authenticated attackers, with permission granted by the s= ite owner through the plugin's role settings, to insert arbitrary rows into=
    the 'wp_users' and 'wp_usermeta' tables, including the 'wp_capabilities' f= ield, allowing them to create a new administrator account and gain administ= rator access to the site. 2026-05-20 8.8 CVE-2026-7467 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-7467 ] F5--NGINX JavaScript NGINX JavaScript has =
    a vulnerability when the js_fetch_proxy=C2=A0directive is configured with a=
    t least one client-controlled NGINX variable (for example, $http_*, $arg_*,=
    $cookie_*) and a location invoking the ngx.fetch() operation from NGINX Ja= vaScript. An unauthenticated attacker can exploit this vulnerability by sen= ding crafted HTTP requests. This may cause a heap buffer overflow in the NG= INX worker process leading to a restart. Additionally, attackers can execut=
    e code on systems with Address Space Layout Randomization (ASLR) disabled o=
    r when the attacker can bypass ASLR. Note: Software versions which have rea= ched End of Technical Support (EoTS) are not evaluated. 2026-05-19 8.1 CVE-= 2026-8711 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8711 ] F5--NGINX Pl=
    us NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_re= write_module module. This vulnerability exists when a rewrite directive use=
    s a regex pattern with distinct, overlapping Perl-Compatible Regular Expres= sion (PCRE) captures (for example, ^/((.*))$) and a replacement string that=
    references multiple such captures (for example, $1$2) in a redirect or arg= uments context. An unauthenticated attacker along with conditions beyond th= eir control can exploit this vulnerability by sending crafted HTTP requests=
    . This may cause a heap buffer overflow in the NGINX worker process leading=
    to a restart. Additionally, attackers can execute code on systems with Add= ress Space Layout Randomization (ASLR) disabled or when the attacker can by= pass ASLR. Note: Software versions which have reached End of Technical Supp= ort (EoTS) are not evaluated. 2026-05-22 8.1 CVE-2026-9256 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-9256 ] FunnelKit--Funnel Builder for WooComme= rce Checkout Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 cont= ains a missing authorization vulnerability in the public checkout endpoint = that allows unauthenticated attackers to invoke internal methods and write = arbitrary data to the plugin's External Scripts global setting. Attackers c=
    an inject malicious JavaScript through the External Scripts setting that ex= ecutes in the browsers of all checkout page visitors. 2026-05-19 7.5 CVE-20= 26-47100 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47100 ] Gmission--We=
    b Fax Improper input validation, Unrestricted upload of file with dangerous=
    type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This = issue affects Web Fax: from 3.0 before 3.1. 2026-05-21 8.4 CVE-2026-9157 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-9157 ] GNU--GNU SASL In GNU SAS=
    L before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both cl= ients and servers, via a known token with no accompanying =3D character. Th=
    is occurs in lib/digest-md5/getsubopt.c. 2026-05-24 7.5 CVE-2026-48829 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-48829 ] goauthentik--authentik au= thentik is an open-source identity provider. Versions 2025.12.4 and prior, = and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authenticatio=
    n Bypass through SAML NameID XML Comment Injection. Due to how authentik ex= tracted the NameID value from a SAML assertion, it was possible for an atta= cker to trick authentik into only seeing a part of the NameID value, potent= ially allowing an attacker to gain access to other accounts. This issue cou=
    ld be exploited on an authentik instance with a SAML Source, where the atta= cker had an account on the SAML Source and the ability to modify their Name=
    ID value (commonly username or E-mail), and XML Signing was enabled. The at= tacker could modify the SAML assertion given to authentik by injecting a co= mment within the NameID value, which effectively truncated the NameID value=
    to the snippet before the comment, and gave the attacker access to any use=
    r account. This issue has been fixed in versions 2025.12.5 and 2026.2.3. 20= 26-05-20 8.7 CVE-2026-40165 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4= 0165 ] goauthentik--authentik authentik is an open-source identity provider=
    . In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT=
    CH /api/v3/core/users/{pk}/ API allows a caller with change_user on a targe=
    t user to assign arbitrary groups through UserSerializer, including groups = with is_superuser=3DTrue, without requiring enable_group_superuser, leading=
    to privilege escalation. This bypasses the stricter permission model enfor= ced in group-management paths and enables delegated user-management permiss= ions to escalate target users to administrator-equivalent privilege. Users = with permissions to update groups or permissions to update users are able t=
    o add themselves or other users they have permissions on to users which hav=
    e superuser permissions. This issue has been fixed in versions 22025.12.5 a=
    nd 2026.2.3. 2026-05-22 8.1 CVE-2026-40172 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-40172 ] H3C--Magic B0 A vulnerability was found in H3C Magic =
    B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /= goform/aspForm. Performing a manipulation of the argument param results in = buffer overflow. The attack may be initiated remotely. The exploit has been=
    made public and could be used. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-05-24 8.8 CVE-2026-9393 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-9393 ] harmistechnology--Ek Risht=
    a Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability = that allows unauthenticated attackers to manipulate database queries by inj= ecting SQL code through the cid parameter. Attackers can send GET requests =
    to the user_detail view with malicious cid values containing SQL commands t=
    o extract sensitive database information. 2026-05-23 8.2 CVE-2018-25348 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2018-25348 ] harmistechnology--EkRish=
    ta Joomla! Component EkRishta 2.10 contains an error-based SQL injection vu= lnerability that allows unauthenticated attackers to execute arbitrary SQL = queries by injecting malicious code into the username parameter. Attackers = can submit POST requests to the login endpoint with SQL injection payloads =
    in the username field to extract database information including user creden= tials and system details. 2026-05-23 8.2 CVE-2018-25351 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2018-25351 ] hestiacp--hestiacp HestiaCP versions 1.9=
    .0 through 1.9.4 contain a deserialization vulnerability in the web termina=
    l component caused by a session format mismatch between PHP and Node.js tha=
    t allows unauthenticated remote attackers to achieve root-level code execut= ion. Attackers can inject crafted data into HTTP headers that are processed=
    by the PHP session handler but incorrectly deserialized by the Node.js web=
    terminal component as trusted session values, resulting in arbitrary comma=
    nd execution on systems with the web terminal feature enabled. 2026-05-19 1=
    0 CVE-2026-43633 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43633 ] hest= iacp--hestiacp HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing=
    vulnerability that allows unauthenticated remote attackers to bypass authe= ntication security controls by supplying an arbitrary IP address in the CF-= Connecting-IP HTTP header without verifying the request originated from Clo= udflare's network. Attackers can exploit this to circumvent fail2ban brute-= force protection, bypass per-user IP allowlists, and poison authentication = audit logs by spoofing trusted IP addresses on each request. 2026-05-19 7.5=
    CVE-2026-43634 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43634 ] Honey= well International Inc.--Control Network Module (CNM) Honeywell Control Net= work Module (CNM)=C2=A0contains command injection vulnerability in the web = interface. An attacker could exploit this vulnerability via command delimit= ers, potentially resulting in Remote Code Execution (RCE). 2026-05-21 9.1 C= VE-2026-5433 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5433 ] iina--iin=
    a IINA before 1.4.3 contains a user-assisted command execution vulnerabilit=
    y that allows remote attackers to execute arbitrary commands by supplying m= alicious mpv_-prefixed query parameters through the iina://open custom URL = scheme handler. Attackers can deliver a crafted URL via a browser that pass=
    es unvalidated mpv_options/input-commands parameters into the mpv runtime, = causing arbitrary command execution as the current macOS user upon approval=
    of the browser protocol prompt without requiring a valid media file. 2026-= 05-21 8.8 CVE-2026-47114 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4711=
    4 ] ISC--BIND 9 BIND servers that are configured to use TKEY-based authenti= cation via GSS-API tokens are vulnerable to excessive memory consumption wh=
    en receiving and processing maliciously-constructed packets. Typically thes=
    e servers will be found in Active Directory integrated DNS deployments and/=
    or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.= 0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0=
    through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S=
    1, and 9.20.9-S1 through 9.20.22-S1. 2026-05-20 7.5 CVE-2026-3039 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-3039 ] ISC--BIND 9 A use-after-free vu= lnerability exists within the DNS-over-HTTPS implementation. This issue aff= ects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.= 20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18= .11-S1 through 9.18.48-S1 are NOT affected. 2026-05-20 7.4 CVE-2026-3593 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-3593 ] ISC--BIND 9 Multiple fla=
    ws have been identified in `named` related to the handling of DNS messages = whose CLASS is not Internet (`IN`) - for example, `CHAOS` or `HESIOD`, or D=
    NS messages that specify meta-classes (`ANY` or `NONE`) in the question sec= tion. Specially crafted requests reaching the affected code paths - recursi= on, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or pr= ocessing of `IN`-specific record types in non-`IN` data - can cause asserti=
    on failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9= .16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21= .21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.= 9-S1 through 9.20.22-S1. 2026-05-20 7.5 CVE-2026-5946 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-5946 ] ISC--BIND 9 Undefined behavior may result d=
    ue to a race condition leading to a use-after-free violation. If BIND recei= ves an incoming DNS message signed with SIG(0), it begins work to validate = that signature. If, during that validation, the "recursive-clients" limit i=
    s reached (as would occur during a query flood), and that same DNS message =
    is discarded per the limit, there is a brief window of time while the SIG(0=
    ) validation may attempt to read the now-discarded DNS message. This issue = affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and=
    9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.28 through 9.18.49 and = 9.18.28-S1 through 9.18.49-S1 are NOT affected. 2026-05-20 7.5 CVE-2026-594=
    7 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5947 ] itsourcecode--Electr= onic Judging System A vulnerability has been found in itsourcecode Electron=
    ic Judging System 1.0. This affects an unknown part of the file /intrams/ad= min/login.php. The manipulation of the argument Username leads to sql injec= tion. Remote exploitation of the attack is possible. The exploit has been d= isclosed to the public and may be used. 2026-05-24 7.3 CVE-2026-9383 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-9383 ] ItzCrazyKns--Vane A flaw has=
    been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects un= known code of the file src/app/api/providers/route.ts of the component Mode=
    l Provider API. This manipulation of the argument baseURL causes server-sid=
    e request forgery. Remote exploitation of the attack is possible. The explo=
    it has been published and may be used. The project was informed of the prob= lem early through an issue report but has not responded yet. 2026-05-24 7.3=
    CVE-2026-9372 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9372 ] ivanti-= -Secure Access Client An improper certificate validation vulnerability in I= vanti Secure Access Client before 22.8R6 allows a remote unauthenticated at= tacker to execute arbitrary code. 2026-05-22 8.8 CVE-2026-8992 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-8992 ] jarrodwatts--claude-hud Claude HUD=
    through 0.0.12, patched in commit 234d9aa, contains a command injection vu= lnerability that allows local attackers to execute arbitrary commands by ma= nipulating the COMSPEC environment variable. Attackers can set COMSPEC to a=
    n arbitrary binary path before claude-hud performs its version check, causi=
    ng execFile() to execute the attacker-supplied executable with cmd.exe argu= ments, resulting in arbitrary code execution on Windows systems. 2026-05-18=
    7.8 CVE-2026-47092 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47092 ] k= ovidgoyal--kitty Kitty is a cross-platform GPU based terminal. In versions = 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c=
    performs bounds validation on composition offsets using unsigned 32-bit ar= ithmetic that is subject to integer wrapping, potentially leading to Heap B= uffer Over-Read/Write. An attacker who can write escape sequences to a kitt=
    y terminal (e.g., via a malicious file, SSH login banner, or piped content)=
    can supply crafted x_offset/y_offset values that pass the bounds check aft=
    er wrapping but cause massive out-of-bounds heap memory access in compose_r= ectangles(). No user interaction is required. No non-default configuration =
    is required. The attacker only needs the ability to produce output in a kit=
    ty terminal window. This issue has been fixed in version 0.47.0. 2026-05-19=
    9.9 CVE-2026-33642 [ https://www.cve.org/CVERecord?id=3DCVE-2026-33642 ] k= ovidgoyal--kitty Kitty is a cross-platform GPU based terminal. Versions 0.4= 6.2 and below contain a heap buffer overflow in load_image_data() that allo=
    ws any process which can write to the terminal's stdin to crash kitty immed= iately. The vulnerability is triggered by a single APC graphics protocol co= mmand with a PNG format declaration (f=3D100) whose payload exceeds twice t=
    he initial buffer capacity. The overflow is attacker-controlled in both len= gth and content, causing DoS and potentially escalation to RCE itself. This=
    issue has been fixed in version 0.47.0. 2026-05-19 7.5 CVE-2026-33633 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-33633 ] langgenius--dify Dify ver= sion 1.14.1 and prior contains an authorization bypass vulnerability that a= llows authenticated editor users to set and enable trace configurations for=
    any application regardless of tenant ownership. Attackers can exploit miss= ing tenant ownership checks in the trace configuration endpoints to redirec=
    t all messages and responses from victim applications to attacker-controlle=
    d LLM trace providers. NOTE: Dify Cloud allows unauthenticated free self-re= gistration, making account creation trivially accessible to any attacker. 2= 026-05-18 7.4 CVE-2026-41947 [ https://www.cve.org/CVERecord?id=3DCVE-2026-= 41947 ] langgenius--dify Dify version 1.14.1 and prior contain a path trave= rsal vulnerability that allows authenticated users to manipulate requests f= orwarded to the Plugin Daemon's internal REST API by exploiting insufficien=
    t URL path sanitization. Attackers can traverse out of their authorized ten= ant path using unencoded dot sequences in task identifiers or manipulated f= ilename parameters to access internal endpoints such as debug interfaces, r= equiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allow=
    s unauthenticated free self-registration, making account creation trivially=
    accessible to any attacker. 2026-05-18 7.7 CVE-2026-41948 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-41948 ] laurent22--joplin Joplin is an open s= ource note-taking and to-do application that organises notes and lists into=
    notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability =
    in the importer which allows overwriting arbitrary files on disk. The OneNo=
    te converter does not sanitize the names of embedded files before writing t= hem to disk. As a result, it's possible for an attacker to create a malicio=
    us .one file that includes file names containing ../../, that are then inte= rpreted as part of the target path when extracting attachments from the .on=
    e file. This issue has been patched in version 3.5.7. 2026-05-18 8.2 CVE-20= 26-22810 [ https://www.cve.org/CVERecord?id=3DCVE-2026-22810 ] Linux--Linux=
    In the Linux kernel, the following vulnerability has been resolved: crypto=
    : pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can re= turn EBUSY. Handle them by checking for that value and filtering out EINPRO= GRESS notifications. 2026-05-19 9.8 CVE-2026-43493 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-43493 ] LizardByte--Sunshine Sunshine is a self-hoste=
    d game stream host for Moonlight. In versions prior to 2026.516.143833, the=
    client-certificate authentication can be bypassed because of how OpenSSL v= erification results are handled. In src/crypto.cpp, the custom verify callb= ack treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NO= T_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an = untrusted certificate to pass authentication and access protected HTTPS end= points. This issue has been fixed in version 2026.516.143833. 2026-05-22 9.=
    8 CVE-2026-32253 [ https://www.cve.org/CVERecord?id=3DCVE-2026-32253 ] Matt= ermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.x <=3D 11.5= .3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to check integration URL=
    for path traversal which allows an malicious authenticated user to call an=
    arbitrary API via system admin Mattermost auth token using via path traver= sal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640 202= 6-05-21 8 CVE-2026-4858 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4858 =
    ] Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11.x <=
    =3D 10.11.13, 11.4.x <=3D 11.4.3 fail to sanitize sensitive configuration f= ields before including them in support packet generation, which allows a Ma= ttermost System Admin or any party with access to a support packet to obtai=
    n sensitive credentials in plaintext via downloading a support packet from = the System Console.. Mattermost Advisory ID: MMSA-2026-00607 2026-05-18 8.7=
    CVE-2026-6346 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6346 ] Matterm= ost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.x <=3D 11.5.3,=
    11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to properly validate msgpac= k-encoded WebSocket frames before memory allocation which allows an unauthe= nticated remote attacker to crash the server process and cause a full servi=
    ce outage for all users via a crafted binary WebSocket message sent to the = public WebSocket endpoint.. Mattermost Advisory ID: MMSA-2026-00647 2026-05= -22 7.5 CVE-2026-5740 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5740 ] = Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11.x <=3D=
    10.11.13, 11.4.x <=3D 11.4.3 fail to sanitize sensitive configuration fiel=
    ds in the Mattermost Calls plugin which allows an attacker with access to a=
    support packet to obtain TURN server credentials via the plaintext values = present in the exported plugin configuration.. Mattermost Advisory ID: MMSA= -2026-00605 2026-05-18 7.6 CVE-2026-6347 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-6347 ] MediaArea--MediaInfoLib MediaArea MediaInfoLib Channel S= plitting heap-based buffer overflow vulnerability 2026-05-20 7.8 CVE-2026-2= 2554 [ https://www.cve.org/CVERecord?id=3DCVE-2026-22554 ] MediaArea--Media= InfoLib MediaArea MediaInfoLib LXF element parsing heap-based buffer overfl=
    ow vulnerability 2026-05-21 7.8 CVE-2026-28764 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-28764 ] memcached--memcached In memcached before 1.6.42, = username data for SASL password database authentication has a timing side c= hannel because a loop exits as soon as a valid username is found by sasl_se= rver_userdb_checkpass. 2026-05-20 8.1 CVE-2026-47783 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-47783 ] memcached--memcached In memcached before 1.= 6.42, password data for SASL password database authentication has a timing = side channel because memcmp is used by sasl_server_userdb_checkpass. 2026-0= 5-20 8.1 CVE-2026-47784 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47784=
    ] Mesalvo--Meona Client Launcher Component Improper Control of Generation =
    of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher C= omponent, Mesalvo Meona Server Component enables code execution on other us= ers' systems.=C2=A0This issue affects Meona Client Launcher Component: thro= ugh 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. = 2026-05-20 9 CVE-2026-22314 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2= 2314 ] Mesalvo--Meona Client Launcher Component Improper Access Control vul= nerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server=
    Component enables a normal user gaining access to the admin panel.=C2=A0Th=
    is issue affects Meona Client Launcher Component: through 19.06.2020 15:11:= 49; Meona Server Component: through 2025.04 5+323020. 2026-05-20 7.8 CVE-20= 26-0856 [ https://www.cve.org/CVERecord?id=3DCVE-2026-0856 ] Mesalvo--Meona=
    Client Launcher Component Incorrect Privilege Assignment vulnerability in = Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component ena= bles the export=C2=A0 of user data, including cleartext passwords, via the = SQL editor.=C2=A0This issue affects Meona Client Launcher Component: throug=
    h 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. 20= 26-05-20 7.2 CVE-2026-22315 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2= 2315 ] metaphorcreations--Ditty Responsive News Tickers, Sliders, and Lists=
    The Ditty - Responsive News Tickers, Sliders, and Lists plugin for WordPre=
    ss is vulnerable to authorization bypass in all versions up to, and includi= ng, 3.1.65. This is due to the plugin not properly verifying that a user is=
    authorized to perform an action. This makes it possible for unauthenticate=
    d attackers to retrieve the full item content of non-public Dittys - includ= ing drafts, pending, scheduled, and disabled entries - by enumerating integ=
    er post IDs against the ditty_init AJAX endpoint. Unlike the non-AJAX init(=
    ) counterpart, init_ajax() does not verify that the requested Ditty has a '= publish' post status before loading and returning its items, allowing conte=
    nt that administrators explicitly withheld from public view to be extracted=
    . 2026-05-22 7.5 CVE-2026-9011 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-9011 ] Microsoft--Azure Local Improper authentication in Azure Local Disc= onnected Operations allows an unauthorized attacker to elevate privileges o= ver a network. 2026-05-18 10 CVE-2026-42822 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-42822 ] Microsoft--Azure Orbital Spatio Unrestricted upload =
    of file with dangerous type in Azure Orbital Spatio allows an unauthorized = attacker to execute code over a network. 2026-05-22 10 CVE-2026-40412 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-40412 ] Microsoft--Azure Privilege=
    d Identity Management (PIM) Authorization bypass through user-controlled ke=
    y in Azure Privileged Identity Management (PIM) allows an authorized attack=
    er to elevate privileges over a network. 2026-05-22 8.8 CVE-2026-35430 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-35430 ] Microsoft--Azure Resource=
    Manager Improper authentication in Azure Resource Manager (ARM) allows an = unauthorized attacker to elevate privileges over a network. 2026-05-22 10 C= VE-2026-47280 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47280 ] Microso= ft--Azure Stack HCI Improper input validation in Azure Compute Gallery allo=
    ws an authorized attacker to disclose information over a network. 2026-05-2=
    2 7.7 CVE-2026-26147 [ https://www.cve.org/CVERecord?id=3DCVE-2026-26147 ] = Microsoft--Azure Virtual Network Gateway Improper input validation in Azure=
    Virtual Network Gateway allows an authorized attacker to execute code over=
    a network. 2026-05-22 9.9 CVE-2026-40411 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-40411 ] Microsoft--Microsoft 365 Copilot for iOS Improper neut= ralization of special elements used in a command ('command injection') in M= icrosoft Copilot allows an unauthorized attacker to perform tampering over =
    a network. 2026-05-22 9.3 CVE-2026-41090 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-41090 ] Microsoft--Microsoft Edge (Chromium-based) Microsoft Ed=
    ge (Chromium-based) Remote Code Execution Vulnerability 2026-05-18 8.8 CVE-= 2026-45495 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45495 ] Microsoft-= -Microsoft Entra Origin validation error in Microsoft Entra ID allows an un= authorized attacker to elevate privileges over a network. 2026-05-22 10 CVE= -2026-42901 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42901 ] Microsoft= --Microsoft Entra Authentication bypass using an alternate path or channel =
    in Microsoft Azure Active Directory B2C allows an unauthorized attacker to = elevate privileges over a network. 2026-05-22 9.1 CVE-2026-33843 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-33843 ] Microsoft--Microsoft Global Sec= ure Access (GSA) Improper privilege management in Azure Entra ID allows an = unauthorized attacker to elevate privileges over a network. 2026-05-22 7.5 = CVE-2026-23663 [ https://www.cve.org/CVERecord?id=3DCVE-2026-23663 ] Micros= oft--Microsoft Malware Protection Engine Heap-based buffer overflow in Micr= osoft Defender allows an unauthorized attacker to execute code over a netwo= rk. 2026-05-20 8.1 CVE-2026-45584 [ https://www.cve.org/CVERecord?id=3DCVE-= 2026-45584 ] Microsoft--Microsoft Malware Protection Engine Improper link r= esolution before file access ('link following') in Microsoft Defender allow=
    s an authorized attacker to elevate privileges locally. 2026-05-20 7.8 CVE-= 2026-41091 [ https://www.cve.org/CVERecord?id=3DCVE-2026-41091 ] Microsoft-= -Microsoft Planetary Computer Pro (GeoCatalog) Deserialization of untrusted=
    data in Microsoft Planetary Computer Pro allows an unauthorized attacker t=
    o disclose information over a network. 2026-05-22 10 CVE-2026-41104 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-41104 ] Microsoft--Microsoft Power P= ages Improper neutralization of special elements used in a command ('comman=
    d injection') in Microsoft Power Pages allows an unauthorized attacker to e= xecute code over a network. 2026-05-22 10 CVE-2026-23652 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-23652 ] Microsoft--Microsoft SharePoint Enterpr= ise Server 2016 Deserialization of untrusted data in Microsoft Office Share= Point allows an authorized attacker to execute code over a network. 2026-05= -22 8.8 CVE-2026-45659 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45659 =
    ] Microsoft--Windows Admin Center in Azure Portal Improper link resolution = before file access ('link following') in Azure Portal Windows Admin Center = allows an authorized attacker to elevate privileges locally. 2026-05-20 7.8=
    CVE-2026-42834 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42834 ] Motor= ola--Phones An improper authentication vulnerability was discovered in the = Motorola Factory Test=C2=A0component=C2=A0(com.motorola.motocit). The appli= cation=C2=A0contained=C2=A0a reference to a writable file descriptor in ext= ernal storage which could be used by third party apps running on the device=
    to open a TCP server, exposing sensitive permissions and data. This could = allow a local attacker to bypass permission checks and access protected dev= ice settings. 2026-05-19 8.4 CVE-2026-5804 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-5804 ] mullvad--mullvadvpn-app Mullvad VPN is a VPN client ap=
    p for desktop and mobile. When using macOS with versions 2026.1 and below, = Mullvad VPN may allow local privilege escalation during installation or upg= rade. The installer package executes binaries from /Applications/Mullvad VP= N.app without verifying if the bundle is attacker-controlled or that the pa=
    th is the legitimate Mullvad application. A user in the admin group can pre= -place a crafted application bundle at that location and may be able to ach= ieve code execution as root. Since the issue only affected the installer, t= here is no immediate need for users to update if they are already running a=
    n older version. This issue has been fixed in version 2026.2-beta1. 2026-05= -19 7.3 CVE-2026-32323 [ https://www.cve.org/CVERecord?id=3DCVE-2026-32323 =
    ] n/a--exifreader This affects versions of the package exifreader before 4.= 39.0. A crafted image containing an ICC mluc tag can set an attacker-contro= lled record count together with a zero record size. During parsing, ExifRea= der repeatedly processes the same record and appends entries to an array wi= thout sufficient bounds validation, causing excessive memory growth. In app= lications that parse attacker-supplied images, this may lead to denial of s= ervice through memory exhaustion. 2026-05-19 7.5 CVE-2026-8813 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-8813 ] n/a--lwIP A vulnerability was foun=
    d in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of=
    the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Per= forming a manipulation of the argument msgAuthenticationParameters results =
    in stack-based buffer overflow. The attack may be initiated remotely. The p= atch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to = install a patch to address this issue. 2026-05-18 9.8 CVE-2026-8836 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-8836 ] n/a--shell-quote shell-quote'=
    s `quote()` function did not validate object-token inputs against the opera= tor model used by `parse()`. The `.op` field was backslash-escaped characte=
    r by character using `/(.)/g`, which in JavaScript does not match line term= inators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore pass=
    ed through unescaped into the output; POSIX shells treat a literal newline =
    as a command separator, so any content after it would execute as a second c= ommand. The vulnerable code path is reachable in two ways: (1) direct const= ruction of `{ op: '...\n...' }` from external input, and (2) via `parse(cmd=
    , envFn)` when `envFn` returns object tokens whose `.op` is attacker-influe= nced. Both are documented API surface. Fixed by replacing the per-character=
    escape with strict shape validation: `.op` must match the parser's control= -operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forb= ids line terminators; `{ comment }` validates `comment` and forbids line te= rminators; any other object shape throws `TypeError`. 2026-05-22 8.1 CVE-20= 26-9277 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9277 ] NeoRazorX--fac= turascripts FacturaScripts is an open source accounting and invoicing softw= are. Versions 2026 and below contain a critical vulnerability in the Plugin= s::add() function. The system fails to properly validate the file paths wit= hin uploaded ZIP archives. This allows an attacker to perform a Zip Slip at= tack, leading to Arbitrary File Write and Remote Code Execution (RCE) by ov= erwriting sensitive .php files outside the designated plugins directory. Th=
    e vulnerability is located in Plugins.php. While the testZipFile function a= ttempts to validate that the ZIP contains only one root folder, it does not=
    sanitize or validate the individual file paths within that folder. An atta= cker can bypass this check by naming a file ValidPluginName/../../shell.php=
    . The explode function will see ValidPluginName as the root folder, satisfy= ing the count($folders) !=3D 1 check. However, during extraction, the ../..=
    / sequence triggers a path traversal, allowing the file to be written anywh= ere the web server has permissions the root directory. This issue is fixed =
    in version 2026.1. 2026-05-18 7.2 CVE-2026-27891 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-27891 ] Netatalk--Netatalk A heap-based buffer overflow=
    in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 all= ows a remote authenticated attacker to execute arbitrary code with escalate=
    d privileges or cause a denial of service. 2026-05-21 9.9 CVE-2026-44050 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-44050 ] Netatalk--Netatalk An S=
    QL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 thro= ugh 4.4.2 allows a remote authenticated attacker to obtain unauthorized acc= ess to data, modify data, or cause a denial of service. 2026-05-21 8.8 CVE-= 2026-44047 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44047 ] Netatalk--= Netatalk A stack-based buffer overflow via UCS-2 type confusion in convert_= charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated att= acker to execute arbitrary code or cause a denial of service. 2026-05-21 8.=
    8 CVE-2026-44048 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44048 ] Neta= talk--Netatalk An improper link resolution vulnerability in Netatalk 3.0.2 = through 4.4.2 allows a remote authenticated attacker to read arbitrary file=
    s or overwrite arbitrary files via attacker-controlled symlink creation. 20= 26-05-21 8.1 CVE-2026-44051 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4= 4051 ] Netatalk--Netatalk An out-of-bounds write due to improper null termi= nation in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote=
    authenticated attacker to execute arbitrary code or cause a denial of serv= ice via crafted character data. 2026-05-21 7.5 CVE-2026-44049 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-44049 ] Netatalk--Netatalk Netatalk 2.1.0 = through 4.4.2 inserts LDAP simple-bind passwords into log output in clearte= xt, which allows an attacker with access to the log files to obtain LDAP cr= edentials. 2026-05-21 7.5 CVE-2026-44052 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-44052 ] Netatalk--Netatalk Netatalk 1.5.0 through 4.2.2 uses a = broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote = attacker to obtain authentication credentials or impersonate a user via cry= ptanalytic attack. 2026-05-21 7.4 CVE-2026-44053 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-44053 ] Netatalk--Netatalk A logic error involving bitw= ise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authentic= ated attacker to inject OS commands and execute arbitrary code. 2026-05-21 = 7.5 CVE-2026-44055 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44055 ] Ne= tatalk--Netatalk An integer underflow in dsi_writeinit() in Netatalk 1.5.0 = through 4.4.2 allows a remote unauthenticated attacker to cause a denial of=
    service via a crafted DSI write request. 2026-05-21 7.5 CVE-2026-44060 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-44060 ] Netatalk--Netatalk A mis= sing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 t= hrough 4.4.2 allows a remote authenticated attacker to execute arbitrary co=
    de or cause a denial of service via crafted character set data. 2026-05-21 = 7.5 CVE-2026-44062 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44062 ] Ne= tatalk--Netatalk An out-of-bounds read in ASP session ID handling in Netata=
    lk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited = information or cause a denial of service via a crafted ASP request. 2026-05= -21 7.1 CVE-2026-44064 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44064 =
    ] Netatalk--Netatalk Multiple heap out-of-bounds reads in the Spotlight RPC=
    unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenti= cated attacker to obtain sensitive information or cause a minor service dis= ruption. 2026-05-21 7.1 CVE-2026-44066 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-44066 ] Netatalk--Netatalk Incomplete sanitization of extended = attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a rem= ote authenticated attacker to write to files outside the intended metadata = namespace via crafted EA names. 2026-05-21 7.6 CVE-2026-44068 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-44068 ] nimiq--core-rs-albatross nimiq-blo= ckchain provides persistent block storage for Nimiq's Rust implementation. =
    In versions 1.3.0 and below, a malicious network peer can crash any Nimiq f= ull node by publishing a crafted Kademlia DHT record. The maliciously craft=
    ed record would contain a TaggedSigned<ValidatorRecord, KeyPair> with a sig= nature field whose byte length is not exactly 64 in order to cause a crash.=
    When the victim node's DHT verifier calls TaggedSigned::verify, execution = reaches Ed25519Signature::from_bytes(sig).unwrap() in the TaggedPublicKey i= mplementation for Ed25519PublicKey. The from_bytes call fails because ed255= 19_zebra::Signature::try_from rejects slices not 64 bytes, and the unwrap()=
    panics. The BLS TaggedPublicKey implementation correctly returns false on = error; only the Ed25519 implementation panics. This issue has been fixed in=
    version 1.4.0. 2026-05-20 7.5 CVE-2026-40092 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-40092 ] NousResearch--hermes-agent A vulnerability was ide= ntified in NousResearch hermes-agent up to 2026.4.16. This affects the func= tion check_all_command_guards of the file tools/approval.py of the componen=
    t Batch Runner. Such manipulation leads to missing authorization. The attac=
    k can be launched remotely. The exploit is publicly available and might be = used. The vendor was contacted early about this disclosure but did not resp= ond in any way. 2026-05-24 7.3 CVE-2026-9350 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-9350 ] NousResearch--hermes-agent A security vulnerability = has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is=
    an unknown function of the file agent/skills_guard.py of the component Ski= lls Guard Multi-Word Prompt Handler. The manipulation of the argument THREA= T_PATTERNS leads to injection. Remote exploitation of the attack is possibl=
    e. The exploit has been disclosed publicly and may be used. The vendor was = contacted early about this disclosure but did not respond in any way. 2026-= 05-24 7.3 CVE-2026-9353 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9353 =
    ] NousResearch--hermes-agent A vulnerability was found in NousResearch herm= es-agent 2026.4.23. The impacted element is the function _scan_context_cont= ent of the file agent/prompt_builder.py. The manipulation results in inject= ion. The attack may be performed from remote. The exploit has been made pub= lic and could be used. The vendor was contacted early about this disclosure=
    but did not respond in any way. 2026-05-24 7.3 CVE-2026-9366 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-9366 ] NousResearch--hermes-agent A vulner= ability was determined in NousResearch hermes-agent up to 5157f5427f19488b3= 1c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command=
    of the file tools/approval.py of the component terminal_tool. This manipul= ation causes os command injection. It is possible to initiate the attack re= motely. The exploit has been publicly disclosed and may be utilized. The ve= ndor was contacted early about this disclosure but did not respond in any w= ay. 2026-05-24 7.3 CVE-2026-9367 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-9367 ] NousResearch--hermes-agent A vulnerability was identified in Nou= sResearch hermes-agent up to 2026.4.16. This impacts the function execute_c= ode of the file tools/code_execution_tool.py of the component Environment V= ariable Handler. Such manipulation leads to sandbox issue. It is possible t=
    o launch the attack remotely. The exploit is publicly available and might b=
    e used. The vendor was contacted early about this disclosure but did not re= spond in any way. 2026-05-24 7.3 CVE-2026-9368 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-9368 ] nukeviet--nukeviet NukeViet CMS is a multi Content=
    Management System. Versions 4.5.07 and prior contain a Stored Cross-Site S= cripting (XSS) vulnerability caused by insufficient server-side input sanit= ization in the Request class. The application relies primarily on client-si=
    de filtering to sanitize HTML tags and attributes in user-submitted content=
    , which can be bypassed by intercepting and modifying HTTP requests directl=
    y (e.g., using Burp Suite). An attacker can inject malicious payloads which=
    are stored server-side and executed in the browser of any user who views t=
    he content. Anyone viewing user-submitted content (such as administrators a=
    nd moderators reviewing contact messages or comments) is impacted, and the = vulnerability can be exploited by any anonymous visitor without authenticat= ion, with the Contact module used only as a proof of concept. Potential con= sequences include session hijacking through cookie theft, unauthorized acti= ons performed under the victim's identity, defacement or redirection to phi= shing pages, and phishing attacks via manipulated email notifications. This=
    issue has been fixed in version 4.5.08. If developers are unable to upgrad=
    e immediately, they should work around this issue by implementing server-si=
    de HTML sanitization in the Request class to strip or encode dangerous tags=
    and attributes (e.g., <iframe>, srcdoc, event handlers like onerror/onload=
    ), enforcing a Content Security Policy (CSP) to restrict inline script exec= ution, and set cookies with the HttpOnly flag to mitigate cookie theft via = XSS. 2026-05-22 8.7 CVE-2026-41147 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-41147 ] NVIDIA--BioNeMo Framework NVIDIA BioNeMo Core for Linux conta= ins a vulnerability where a user could cause a path traversal by loading a = malicious file. A successful exploit of this vulnerability might lead to co=
    de execution, denial of service, information disclosure, and data tampering=
    . 2026-05-20 8.8 CVE-2026-24217 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-24217 ] NVIDIA--BioNeMo Framework NVIDIA BioNemo for Linux contains a vu= lnerability where a user could cause a deserialization of untrusted data. A=
    successful exploit of this vulnerability might lead to code execution, den= ial of service, information disclosure, and data tampering. 2026-05-20 7.8 = CVE-2026-24216 [ https://www.cve.org/CVERecord?id=3DCVE-2026-24216 ] NVIDIA= --DGX Spark NVIDIA DGX OS contains a vulnerability in the factory provision= ing process, where the cloning of a base image causes identical SSH host ke=
    ys to be deployed across multiple systems. The sharing of cryptographic ide= ntifiers across all similarly provisioned systems enables host impersonatio=
    n or attacker-in-the-middle attacks. A successful exploit of this vulnerabi= lity might lead to code execution, data tampering, escalation of privileges=
    , information disclosure, and denial of service. 2026-05-20 8.1 CVE-2026-24= 218 [ https://www.cve.org/CVERecord?id=3DCVE-2026-24218 ] NVIDIA--TensorRT = NVIDIA TensorRT contains a vulnerability where an attacker could cause an o= ut-of-bounds write. A successful exploit of this vulnerability might lead t=
    o data tampering. 2026-05-20 8.2 CVE-2026-24188 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-24188 ] NVIDIA--TensorRT-LLM NVIDIA TRT-LLM for any plat= form contains a vulnerability in MPI server, where an attacker could cause =
    an unsafe deserialization. A successful exploit of this vulnerability might=
    lead to code execution, denial of service, data tampering, and information=
    disclosure. 2026-05-20 7.5 CVE-2025-33255 [ https://www.cve.org/CVERecord?= id=3DCVE-2025-33255 ] NVIDIA--TensorRT-LLM NVIDIA TRT-LLM for any platform = contains a vulnerability in RPC testing, where an attacker could cause an u= nsafe deserialization. A successful exploit of this vulnerability might lea=
    d to code execution, denial of service, data tampering, and information dis= closure. 2026-05-20 7.5 CVE-2026-24163 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-24163 ] NVIDIA--Triton Inference Server NVIDIA Triton Inference=
    Server contains a vulnerability where an attacker could cause an authentic= ation bypass. A successful exploit of this vulnerability might lead to code=
    execution, escalation of privileges, data tampering, denial of service, or=
    information disclosure. 2026-05-20 9.8 CVE-2026-24207 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-24207 ] NVIDIA--Triton Inference Server NVIDIA Tr= iton Inference Server contains a vulnerability in the DALI backend where an=
    attacker could cause an out-of-bounds read. A successful exploit of this v= ulnerability might lead to code execution, data tampering, denial of servic=
    e, or information disclosure. 2026-05-20 8 CVE-2026-24213 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-24213 ] NVIDIA--Triton Inference Server NVIDIA=
    Triton Inference Server contains a vulnerability in the DALI backend where=
    an attacker could cause an integer overflow. A successful exploit of this = vulnerability might lead to code execution, data tampering, or denial of se= rvice. 2026-05-20 8 CVE-2026-24214 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-24214 ] NVIDIA--Triton Inference Server NVIDIA Triton Inference Serve=
    r contains a vulnerability where an attacker could cause an authentication = bypass. A successful exploit of this vulnerability might lead to escalation=
    of privileges, denial of service, or information disclosure. 2026-05-20 7.=
    3 CVE-2026-24206 [ https://www.cve.org/CVERecord?id=3DCVE-2026-24206 ] NVID= IA--Triton Inference Server NVIDIA Triton Inference Server contains a vulne= rability where an attacker could cause a path traversal issue. A successful=
    exploit of this vulnerability might lead to denial of service. 2026-05-20 = 7.5 CVE-2026-24209 [ https://www.cve.org/CVERecord?id=3DCVE-2026-24209 ] NV= IDIA--Triton Inference Server NVIDIA Triton Inference Server contains a vul= nerability where an attacker could cause an integer overflow. A successful = exploit of this vulnerability might lead to denial of service. 2026-05-20 7=
    .5 CVE-2026-24210 [ https://www.cve.org/CVERecord?id=3DCVE-2026-24210 ] Ope=
    n ISES--Tickets Open ISES Tickets before 3.44.2 contains a SQL injection vu= lnerability in incs/remotes.inc.php where latitude, longitude, callsign, mp=
    h, altitude, and timestamp values parsed from external GPS tracking service=
    XML/JSON responses (InstaMapper and Google Latitude integration) are conca= tenated into UPDATE and INSERT statements without sanitization. An attacker=
    able to compromise or impersonate the remote GPS tracker endpoint can inje=
    ct SQL to manipulate the responder location, tracks, and assignment tables.=
    2026-05-21 8.2 CVE-2026-48235 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-48235 ] Open ISES--Tickets Open ISES Tickets before 3.44.2 contains hardc= oded MySQL database credentials in loader.php (a public-facing database uti= lity) that are committed to the source repository. Any actor with access to=
    the public source tree (or an unauthenticated attacker with read access to=
    the file on a deployed installation) can read the username, password, and = database name and use them to connect to the database if it is reachable fr=
    om their network. 2026-05-21 8.1 CVE-2026-48241 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-48241 ] Open ISES--Tickets Open ISES Tickets before 3.44=
    .2 contains hardcoded MySQL database connection credentials (host, username=
    , password, database name) in import_mdb.php. The credentials are embedded =
    in source code committed to the public repository, allowing any reader of t=
    he source to obtain valid configuration values that may match deployed inst= allations. 2026-05-21 8.1 CVE-2026-48242 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-48242 ] Open ISES--Tickets Open ISES Tickets before 3.44.2 cont= ains a SQL injection vulnerability in tables.php where the multiple POST pa= rameters (tablename, indexname, sortby) are concatenated into table/column = identifiers in dynamically constructed SELECT/UPDATE/DELETE statements with= out sanitization. Authenticated attackers can craft requests that alter que=
    ry semantics to read, modify, or destroy database contents. 2026-05-21 7.1 = CVE-2026-48231 [ https://www.cve.org/CVERecord?id=3DCVE-2026-48231 ] Open I= SES--Tickets Open ISES Tickets before 3.44.2 contains a SQL injection vulne= rability in ajax/fullsit_incidents.php where the offset GET parameter is co= ncatenated into the LIMIT clause of a SELECT statement without sanitization=
    . Authenticated attackers can craft requests that alter query semantics to = read, modify, or destroy database contents. 2026-05-21 7.1 CVE-2026-48232 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-48232 ] Open ISES--Tickets Ope=
    n ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax= /sit_incidents.php where the offset GET parameter is concatenated into the = LIMIT clause of a SELECT statement without sanitization. Authenticated atta= ckers can craft requests that alter query semantics to read, modify, or des= troy database contents. 2026-05-21 7.1 CVE-2026-48233 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-48233 ] Open ISES--Tickets Open ISES Tickets befor=
    e 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_request= s.php where the sort and dir GET parameters are concatenated into the ORDER=
    BY clause of a SELECT statement without sanitization. Authenticated attack= ers can craft requests that alter query semantics to read, modify, or destr=
    oy database contents. 2026-05-21 7.1 CVE-2026-48234 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-48234 ] Open ISES--Tickets Open ISES Tickets before = 3.44.2 contains a SQL injection vulnerability in db_loader.php where the mu= ltiple POST parameters (ticketsdb, ticketshost, ticketsuser, ticketspasswor=
    d) are concatenated into mysqli connection arguments and dynamic SQL operat= ing against an attacker-controlled database without sanitization. Authentic= ated attackers can craft requests that alter query semantics to read, modif=
    y, or destroy database contents. 2026-05-21 7.1 CVE-2026-48236 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-48236 ] Open ISES--Tickets Open ISES Tick= ets before 3.44.2 contains a SQL injection vulnerability in message.php whe=
    re the frm_ticket_id and frm_resp_id POST parameters are concatenated into = WHERE clauses of SELECT/UPDATE statements without sanitization. Authenticat=
    ed attackers can craft requests that alter query semantics to read, modify,=
    or destroy database contents. 2026-05-21 7.1 CVE-2026-48237 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-48237 ] Open ISES--Tickets Open ISES Ticket=
    s before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.= php where the id GET parameter is concatenated into the WHERE clause of a S= ELECT statement used as a ticket-existence sanity check without sanitizatio=
    n. Authenticated attackers can craft requests that alter query semantics to=
    read, modify, or destroy database contents. 2026-05-21 7.1 CVE-2026-48238 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-48238 ] Open ISES--Tickets Op=
    en ISES Tickets before 3.44.2 contains a SQL injection vulnerability in aja= x/reports.php where the tick_id POST parameter is concatenated into the WHE=
    RE clause of SELECT statements in the incidents summary report without sani= tization. Authenticated attackers can craft requests that alter query seman= tics to read, modify, or destroy database contents. 2026-05-21 7.1 CVE-2026= -48239 [ https://www.cve.org/CVERecord?id=3DCVE-2026-48239 ] Open ISES--Tic= kets Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability=
    in ajax/statistics.php where the tick_id and f_tick_id POST parameters are=
    concatenated into WHERE clauses of SELECT statements in the statistics rol= lup queries without sanitization. Authenticated attackers can craft request=
    s that alter query semantics to read, modify, or destroy database contents.=
    2026-05-21 7.1 CVE-2026-48240 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-48240 ] OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions a= llow a remote attacker arbitrary code execution in pre-installed apps. 2026= -05-19 8.1 CVE-2026-24792 [ https://www.cve.org/CVERecord?id=3DCVE-2026-247=
    92 ] OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allow =
    a local attacker cause DOS and it cannot be recovered. 2026-05-19 8.4 CVE-2= 026-25781 [ https://www.cve.org/CVERecord?id=3DCVE-2026-25781 ] OpenHarmony= --OpenHarmony in OpenHarmony v6.0 and prior versions allow a remote attacke=
    r arbitrary code execution in pre-installed apps. 2026-05-19 8.8 CVE-2026-2= 7648 [ https://www.cve.org/CVERecord?id=3DCVE-2026-27648 ] OPPO--O+ Connect=
    A local privilege escalation vulnerability exists in O+ Connect because it=
    fails to validate the identity of the caller on the pipe interface. 2026-0= 5-19 7.3 CVE-2026-22069 [ https://www.cve.org/CVERecord?id=3DCVE-2026-22069=
    ] Piotnet--Piotnet Addons For Elementor Pro The Piotnet Addons for Element=
    or Pro plugin for WordPress is vulnerable to arbitrary file upload due to m= issing file type validation in the 'pafe_ajax_form_builder' function in all=
    versions up to, and including, 7.1.70. The plugin uses an incomplete exten= sion blacklist that only blocks php, phpt, php5, php7, and exe extensions, = while allowing dangerous extensions such as .phar or .phtml to be uploaded.=
    This makes it possible for unauthenticated attackers to upload arbitrary f= iles on the affected site's server which may make remote code execution pos= sible. Note: The exploit can only be exploited if a file field is added to = the form. 2026-05-19 9.8 CVE-2026-4885 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-4885 ] Piotnet--Piotnet Forms The Piotnet Forms plugin for Word= Press is vulnerable to arbitrary file upload due to missing file type valid= ation in the 'piotnetforms_ajax_form_builder' function in all versions up t=
    o, and including, 2.1.40. The plugin uses an incomplete extension blacklist=
    that only blocks php, phpt, php5, php7, and exe extensions, while allowing=
    dangerous extensions such as .phar or .phtml to be uploaded. This makes it=
    possible for unauthenticated attackers to upload arbitrary files on the af= fected site's server which may make remote code execution possible. Note: T=
    he exploit can only be exploited if a file field is added to the form. 2026= -05-19 9.8 CVE-2026-4883 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4883=
    ] PixelYourSite--Boost The Boost plugin for WordPress is vulnerable to PHP=
    Object Injection in versions up to, and including, 2.0.3 via deserializati=
    on of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes=
    it possible for unauthenticated attackers to inject a PHP Object. No known=
    POP chain is present in the vulnerable software, which means this vulnerab= ility has no impact unless another plugin or theme containing a POP chain i=
    s installed on the site. If a POP chain is present via an additional plugin=
    or theme installed on the target system, it may allow the attacker to perf= orm actions like delete arbitrary files, retrieve sensitive data, or execut=
    e code depending on the POP chain present. 2026-05-20 9.8 CVE-2026-7637 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-7637 ] PixelYourSite--Boost The = Boost plugin for WordPress is vulnerable to time-based SQL Injection via th=
    e 'current_url' and 'user_name' parameters in versions up to, and including=
    , 2.0.3 due to insufficient escaping on the user supplied parameters and la=
    ck of sufficient preparation on the existing SQL queries. This makes it pos= sible for unauthenticated attackers to append additional SQL queries into a= lready existing queries that can be used to extract sensitive information f= rom the database. 2026-05-20 7.5 CVE-2026-9010 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-9010 ] pixelyoursite--Cost of Goods by PixelYourSite The = Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored=
    Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter i=
    n versions up to, and including, 1.2.12 due to insufficient input sanitizat= ion and output escaping. This makes it possible for unauthenticated attacke=
    rs to inject arbitrary web scripts in pages that will execute whenever a us=
    er accesses an injected page. 2026-05-20 7.2 CVE-2026-7613 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-7613 ] PosCube Hardware Software and Consulti=
    ng Ltd.--QR Menu Authorization bypass through User-Controlled key vulnerabi= lity in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploi= tation of Trusted Identifiers. This issue affects QR Menu: through 21052026= .=C2=A0NOTE: The vendor was contacted early about this disclosure but did n=
    ot respond in any way. 2026-05-21 7.5 CVE-2025-13479 [ https://www.cve.org/= CVERecord?id=3DCVE-2025-13479 ] PowerDNS--Authoritative Insufficient Valida= tion of Autoprimary SOA Queries 2026-05-21 7.5 CVE-2026-42001 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-42001 ] projectworlds--hospital-management= -system-in-php A flaw has been found in projectworlds hospital-management-s= ystem-in-php 1.0. Affected by this vulnerability is the function getAllPati= entDetail of the file update_info.php of the component GET Parameter Handle=
    r. Executing a manipulation of the argument appointment_no can lead to sql = injection. The attack may be performed from remote. The exploit has been pu= blished and may be used. The project was informed of the problem early thro= ugh an issue report but has not responded yet. 2026-05-18 7.3 CVE-2026-8785=
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-8785 ] projectworlds--Online=
    Art Gallery Shop A flaw has been found in projectworlds Online Art Gallery=
    Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php=
    . Executing a manipulation of the argument social_linked can lead to sql in= jection. The attack can be executed remotely. The exploit has been publishe=
    d and may be used. 2026-05-24 7.3 CVE-2026-9364 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-9364 ] prosolution--ProSolution WP Client The ProSolutio=
    n WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in = versions up to, and including, 2.0.0. This is due to an array validation mi= smatch where only the first file in the upload array undergoes extension an=
    d MIME type validation, while all files are processed and uploaded to a web= -accessible directory. This makes it possible for unauthenticated attackers=
    to upload malicious PHP files and achieve remote code execution by sending=
    a valid first file followed by a malicious file. 2026-05-20 9.8 CVE-2026-6= 555 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6555 ] Red Hat--Red Hat b= uild of Keycloak 26.2 A flaw was found in Keycloak's URL validation logic d= uring redirect operations. By crafting a malicious request, an attacker cou=
    ld bypass validation to redirect users to unauthorized URLs, potentially le= ading to the exposure of sensitive information within the domain or facilit= ating further attacks. This vulnerability specifically affects Keycloak cli= ents configured with a wildcard (*) in the "Valid Redirect URIs" field and = requires user interaction to be successfully exploited. The issue stems fro=
    m a discrepancy in how Keycloak and the underlying Java URI implementation = handle the user-info component of a URL. If a malicious redirect URL is con= structed using multiple @ characters in the user-info section, Java's URI p= arser fails to extract the user-info, leaving only the raw authority field.=
    Consequently, Keycloak's validation check fails to detect the malformed us= er-info, falls back to a wildcard comparison, and incorrectly permits the m= alicious redirect. 2026-05-19 8.1 CVE-2026-7504 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-7504 ] Red Hat--Red Hat build of Keycloak 26.2 A flaw wa=
    s found in Keycloak. A remote, unauthenticated attacker can send a speciall=
    y crafted XML input to the Security Assertion Markup Language (SAML) endpoi= nt. This malicious input can cause high CPU usage and worker thread starvat= ion, leading to a Denial of Service (DoS) where the server becomes unavaila= ble. 2026-05-19 7.5 CVE-2026-7307 [ https://www.cve.org/CVERecord?id=3DCVE-= 2026-7307 ] Red Hat--Red Hat build of Keycloak 26.2 A session fixation vuln= erability was found in Keycloak's login-actions endpoints. An unauthenticat=
    ed attacker could exploit this flaw by pre-creating an authentication sessi=
    on and tricking a victim into visiting a maliciously crafted link. By lever= aging the /login-actions/restart endpoint-which processes session handles w= ithout adequate CSRF protection or cookie ownership validation-an attacker = can reset the authentication flow state. This causes Single Sign-On (SSO) t=
    o authenticate the victim transparently upon clicking the link, allowing th=
    e attacker to hijack the required-action form without needing the victim's = credentials. A successful exploit could lead to complete account takeover, = including highly privileged administrative accounts. 2026-05-19 7.5 CVE-202= 6-7507 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7507 ] Red Hat--Red Ha=
    t build of Keycloak 26.4 A flaw was found in Keycloak. A low-privilege user=
    , with knowledge of user credentials and client ID, can bypass a security c= ontrol intended to disable the implicit flow in OpenID Connect (OIDC) clien= ts. By manipulating client data during a session restart, an attacker can o= btain an access token that should not be available. This vulnerability can = also lead to the exposure of these access tokens in server logs, proxy logs=
    , and HTTP Referrer headers, resulting in sensitive information disclosure.=
    2026-05-19 7.1 CVE-2026-7571 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -7571 ] Red Hat--Red Hat Directory Server 11 A flaw was found in 389-ds-bas=
    e. The get_ldapmessage_controls_ext() function in the LDAP server does not = enforce an upper bound on the number of controls per LDAP message. A remote=
    , unauthenticated attacker can send a specially crafted LDAP request contai= ning hundreds of thousands of minimal controls within the default maximum B=
    ER message size (2 MB), causing excessive CPU consumption and heap allocati=
    on on the server. Under concurrent exploitation, this leads to significant = latency degradation, worker thread starvation, or out-of-memory termination=
    , resulting in a denial of service. 2026-05-20 7.5 CVE-2026-9064 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-9064 ] Red Hat--Red Hat Hardened Images=
    A flaw was found in gnutls. A remote attacker could exploit an issue in th=
    e Datagram Transport Layer Security (DTLS) packet reordering logic. The com= parator function, responsible for ordering DTLS packets by sequence numbers=
    , did not correctly handle packets with duplicate sequence numbers. This co= uld lead to unstable packet ordering or undefined behavior, resulting in a = denial of service. 2026-05-18 7.5 CVE-2026-42009 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-42009 ] Redaxo--Redaxo CMS Mediapool Redaxo CMS Mediapo=
    ol Addon 5.5.1 and older contains an arbitrary file upload vulnerability th=
    at allows authenticated users to bypass file extension blacklist restrictio= ns. Attackers with editor accounts can upload executable files by using obf= uscated extensions like php71 or php53 to evade the blacklist filter and ex= ecute arbitrary code. 2026-05-23 8.8 CVE-2018-25353 [ https://www.cve.org/C= VERecord?id=3DCVE-2018-25353 ] Repute Infosystems--BookingPress Appointment=
    Booking Pro The BookingPress Pro plugin for WordPress is vulnerable to arb= itrary file uploads due to missing file type validation in the 'bookingpres= s_validate_submitted_booking_form_func' function in all versions up to, and=
    including, 5.6. This makes it possible for unauthenticated attackers to up= load arbitrary files on the affected site's server which may make remote co=
    de execution possible. Note: The vulnerability can only be exploited if a s= ignature custom field is added to the booking form. 2026-05-21 9.8 CVE-2026= -6960 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6960 ] RsyncProject--rs= ync Rsync version=C2=A03.4.2 and prior contain an integer overflow vulnerab= ility in the compressed-token decoder where a 32-bit signed counter is not = checked for overflow, allowing a malicious sender to trigger an overflow th=
    at causes the receiver process to read and return data from outside the int= ended buffer bounds. Attackers can exploit this vulnerability to disclose p= rocess memory contents including environment variables, passwords, heap and=
    stack data, and library memory pointers, significantly reducing ASLR effec= tiveness and facilitating further exploitation. 2026-05-20 8.1 CVE-2026-436=
    18 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43618 ] RsyncProject--rsyn=
    c Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTO=
    U) race condition in daemon file handling that allows attackers to redirect=
    file writes outside intended directories by replacing parent directory com= ponents with symbolic links. Attackers with write access to a module path c=
    an exploit this race condition to create or overwrite arbitrary files, pote= ntially modifying sensitive system files and achieving privilege escalation=
    when the daemon runs with elevated privileges. This vulnerability can only=
    be triggered if the chroot setting is false. 2026-05-20 7 CVE-2026-29518 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-29518 ] ruby-lang--Ruby An iss=
    ue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use= -after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinf=
    o in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS res= ponses near the user-specified timeout to crash a Ruby process that calls A= ddrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Mem= ory-corruption-based exploitation is theoretically possible. The attack cou= ld, for example, be carried out through a crafted authoritative DNS server =
    or recursive resolver. 2026-05-22 8.1 CVE-2026-46727 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-46727 ] Samsung Open Source--Escargot Use after fre=
    e vulnerability in Samsung Open Source Escargot allows Pointer Manipulation=
    . This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. 20= 26-05-19 7.8 CVE-2026-47310 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4= 7310 ] Samsung Open Source--Escargot Heap-based buffer overflow vulnerabili=
    ty in Samsung Open Source Escargot allows Overflow Buffers. This issue affe= cts Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. 2026-05-19 7.8 CVE-= 2026-47311 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47311 ] Samsung Op=
    en Source--Escargot Out-of-bounds write vulnerability in Samsung Open Sourc=
    e Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc62= 58317c5da850d846ce6baaf2afc2d3. 2026-05-19 7.8 CVE-2026-47314 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-47314 ] SigmaPlugin--Advanced Database Cle= aner Premium The Advanced Database Cleaner - Premium plugin for WordPress i=
    s vulnerable to Local File Inclusion in versions up to, and including, 4.1.=
    0 via the 'template' parameter. This makes it possible for authenticated at= tackers, with Subscriber-level access and above, to include and execute arb= itrary .php files on the server, allowing the execution of any PHP code in = those files. This can be used to bypass access controls, obtain sensitive d= ata, or achieve code execution in cases where .php file types can be upload=
    ed and included. 2026-05-20 8.8 CVE-2026-7522 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-7522 ] Significant-Gravitas--AutoGPT AutoGPT is a workflow=
    automation platform for creating, deploying, and managing continuous artif= icial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to=
    Authenticated Session Hijacking via IDOR. If an authenticated attacker can=
    determine the session_id of another user's session, they can take it over,=
    reading any messages in it and locking the legitimate user out. The PATCH = /sessions/{session_id}/assign-user endpoint authenticates the caller but ne= ver verifies session ownership: the service layer invokes the session looku=
    p with user_id=3DNone, which the data access layer interprets as a privileg= ed/system call that bypasses the ownership filter, allowing any authenticat=
    ed user to reassign an arbitrary session to themselves. This issue has been=
    patched in version 0.6.51. 2026-05-18 7.1 CVE-2026-30950 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-30950 ] Significant-Gravitas--AutoGPT AutoGPT =
    is a workflow automation platform for creating, deploying, and managing con= tinuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are v= ulnerable to an unauthenticated Denial of Service (DoS) through the server = due to uncontrolled disk space consumption. The download_agent_file endpoin=
    t creates persistent temporary files for every request but fails to delete = them after they are served. An unauthenticated attacker can repeatedly call=
    this endpoint to exhaust the server's disk space, causing the database or = other system services to fail due to "No space left on device" errors, rend= ering the entire AutoGPT Platform backend unavailable to all users. This is= sue has been patched in version 0.6.52. 2026-05-19 7.5 CVE-2026-33232 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-33232 ] Significant-Gravitas--Auto= GPT AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. In versions 0.6.34 thro= ugh 0.6.51, the backend deserializes Redis cache bytes using pickle.loads w= ithout integrity/authenticity checks. The write path serializes values with=
    pickle.dumps(...) into Redis and the read path blindly invokes pickle.load= s(...) on bytes with no HMAC/signature or strict schema validation gating d= eserialization. If an attacker can poison a shared-cache key in Redis, arbi= trary command execution is possible in the backend container context, affec= ting confidentiality, integrity, and availability. This issue has been fixe=
    d in version 0.6.52. 2026-05-19 7.6 CVE-2026-33233 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-33233 ] Sipp--SIPp SIPp 3.6 and earlier contains a lo= cal buffer overflow vulnerability in command-line argument handling that al= lows local attackers to crash the application or execute arbitrary code. At= tackers can trigger the vulnerability by supplying oversized input to the -= 3pcc, -i, or -log_file parameters, causing strcpy to write beyond buffer bo= undaries in sipp.cpp. 2026-05-23 8.4 CVE-2018-25356 [ https://www.cve.org/C= VERecord?id=3DCVE-2018-25356 ] Sitemio Information Technologies Trade Ltd. = Co.--WISECP Cross-Site request forgery (CSRF) vulnerability in Sitemio Info= rmation Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forger=
    y. This issue affects WISECP: through 20022026.=C2=A0NOTE: The vendor was c= ontacted early about this disclosure but did not respond in any way. 2026-0= 5-20 8 CVE-2025-11954 [ https://www.cve.org/CVERecord?id=3DCVE-2025-11954 ]=
    SourceCodester--Hospitals Patient Records Management System A flaw has bee=
    n found in SourceCodester Hospitals Patient Records Management System 1.0. = The impacted element is an unknown function of the file /classes/Master.php= ?f=3Dsave_patient_history. This manipulation of the argument ID causes sql = injection. The attack is possible to be carried out remotely. The exploit h=
    as been published and may be used. 2026-05-24 7.3 CVE-2026-9355 [ https://w= ww.cve.org/CVERecord?id=3DCVE-2026-9355 ] SourceCodester--Hospitals Patient=
    Records Management System A vulnerability has been found in SourceCodester=
    Hospitals Patient Records Management System 1.0. This affects an unknown f= unction of the file /admin/patients/manage_history.php. Such manipulation o=
    f the argument ID leads to sql injection. The attack may be performed from = remote. The exploit has been disclosed to the public and may be used. 2026-= 05-24 7.3 CVE-2026-9356 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9356 =
    ] Splunk--Splunk Enterprise In Splunk Enterprise versions below 10.2.2 and = 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11,=
    10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the = `_internal` index could view session cookies and response bodies that conta=
    in sensitive data. 2026-05-20 7.5 CVE-2026-20239 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-20239 ] Splunk--Splunk Enterprise In Splunk Enterprise = versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platfor=
    m versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0= .2503.13, and 9.3.2411.129, a low-privileged user that does not hold the 'a= dmin' or 'power' Splunk roles could cause a Denial of Service by exploiting=
    the `coldToFrozen.sh` script in the `splunk_archiver` app to rename critic=
    al Splunk directories, making the instance non-functional.<br><br>The Denia=
    l of Service is possible because of missing input validation in the `coldTo= Frozen.sh` script, which accepts arbitrary file paths and renames them with= out restricting operations to safe directories. 2026-05-20 7.1 CVE-2026-202=
    40 [ https://www.cve.org/CVERecord?id=3DCVE-2026-20240 ] steipete--summariz=
    e Summarize prior to 0.15.1 contains a path traversal vulnerability in the = /v1/summarize daemon endpoint that allows authenticated callers to write fi= les to arbitrary directories by supplying an absolute path or directory tra= versal sequence in the slidesDir request parameter. Attackers can exploit t= his to write slide_*.png and slides.json files to any writable directory an=
    d subsequently delete matching files at the specified location through repe=
    at extraction. 2026-05-18 7.1 CVE-2026-45242 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-45242 ] steipete--summarize Summarize prior to 0.15.1 conta= ins a vulnerability in the hover summary feature that allows malicious page=
    s to dispatch synthetic mouseover events over attacker-controlled links, ca= using the extension to make authenticated daemon requests using stored toke=
    ns without verifying event trustworthiness. Attackers can place local or pr= ivate-network URLs behind hoverable links to route authenticated requests t= hrough the daemon, potentially accessing sensitive internal endpoints when = users interact with attacker-controlled content. 2026-05-18 7.4 CVE-2026-45= 245 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45245 ] strukturag--libhe=
    if libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.2= 1.2 and prior contain a heap-buffer-overflow (write) vulnerability in the g= rid tile compositing, allowing an attacker to write 64 bytes of fully attac= ker-controlled data past the end of a chroma plane heap allocation by craft= ing a HEIF/AVIF file with a 1=C3=83=E2=80=944 grid of odd-height tiles. The=
    overflow is triggered during normal image decoding with default build conf= iguration. The written bytes are chroma (Cb/Cr) pixel values from the attac= king tile, giving the attacker full control over the overflow content. This=
    issue has been fixed in version 1.22.0. 2026-05-19 8.8 CVE-2026-32740 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-32740 ] strukturag--libheif libhe=
    if is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and = below contain a heap buffer overflow in MaskImageCodec::decode_mask_image()=
    . When decoding a HEIF file containing a mask image (mski), the function co= pies the full iloc extent data into a pixel buffer using memcpy(dst, data.d= ata(), data.size()). The copy length data.size() is determined by the iloc = extent in the file (attacker-controlled), while the destination buffer is s= ized based on the declared image dimensions. Because no upper-bound check e= xists on the data length, a crafted file whose iloc extent exceeds the pixe=
    l buffer allocation overflows the heap. The vulnerable single-memcpy branch=
    is reached when the mskC property specifies bits_per_pixel =3D 8 and the i= spe property declares an even width =C3=A2=E2=80=B0=C2=A5 64 (so that strid=
    e =3D=3D width), with no changes to default security limits or external cod=
    ec plugins required. This issue has been fixed in version 1.22.0. 2026-05-1=
    9 7.1 CVE-2026-32741 [ https://www.cve.org/CVERecord?id=3DCVE-2026-32741 ] = strukturag--libheif libheif is a HEIF and AVIF file format decoder and enco= der. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixel= Image::overlay() in libheif/pixelimage.cc. When compositing an overlay imag=
    e (iovl) whose child image has a different bit depth for the alpha channel = than for the color channels, the function indexes into the alpha plane usin=
    g the color channel stride (in_stride) instead of the previously retrieved = alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 b= ytes for a 100=C3=83=E2=80=9450 image with 10-bit color and 8-bit alpha). A=
    crafted HEIF file can exploit this to cause a denial of service (crash) or=
    potentially disclose adjacent heap memory through leaked bytes embedded in=
    the decoded output pixels. This issue has been fixed in versionThis issue = has been fixed in version 1.22.0. 2026-05-19 7.1 CVE-2026-32882 [ https://w= ww.cve.org/CVERecord?id=3DCVE-2026-32882 ] SUSE--Container suse/sle-micro-r= ancher/5.3:latest In `src/havegecmd.c`, the `socket_handler` function perfo= rms a credential check on the abstract UNIX socket (` /sys/entropy/haveged`=
    ). However, while it detects if the connecting user is not root (`cred.uid = !=3D 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails =
    to stop execution**. The code proceeds to the `switch` statement, allowing = any local unprivileged user to execute privileged commands such as `MAGIC_C= HROOT`. 2026-05-20 7.8 CVE-2026-41054 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-41054 ] SUSE--SUSE Linux Enterprise `PluginScript` attempts to `ch= root` the plugin to the `repoManagerRoot`, this root is frequently `/` (the=
    system root) in standard configurations or when using `--root`. If the chr= oot target is `/`, it is a no-op, allowing the traversed path to execute ho=
    st binaries (like `/bin/bash`) with root privileges. 2026-05-20 7.8 CVE-202= 6-44933 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44933 ] syslink softw= are AG--Avantra Insufficient session expiration vulnerability in syslink so= ftware AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session=
    Replay). This issue affects Avantra: before 25.3.1. 2026-05-22 9.6 CVE-202= 6-8670 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8670 ] syslink softwar=
    e AG--Avantra Insertion of sensitive information into log file vulnerabilit=
    y in syslink software AG Avantra on Linux, Windows allows Resource Leak Exp= osure. This issue affects Avantra: before 25.3.0. 2026-05-22 7.5 CVE-2026-8= 671 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8671 ] Taiko Network Comm= unications Pte Ltd.--AG1000-01A SMS Alert Gateway Taiko AG1000-01A SMS Aler=
    t Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability =
    in the embedded web configuration interface where authentication is impleme= nted entirely in client-side JavaScript in login.zhtml, exposing static pla= intext credentials in the page source. Unauthenticated attackers with netwo=
    rk access can recover administrative credentials directly from the client-s= ide validate() function to obtain full administrative access to the device.=
    2026-05-20 9.8 CVE-2026-9139 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -9139 ] Taiko Network Communications Pte Ltd.--AG1000-01A SMS Alert Gateway=
    Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentic= ation bypass vulnerability in the embedded web configuration interface that=
    allows unauthenticated attackers to access internal application pages with= out any session management or server-side authentication checks. Attackers = with network access can directly request internal resources such as index.z= html, point.zhtml, and log.shtml to gain full administrative read and write=
    access, enabling unauthorized modification of alarm routing, device config= uration, and disruption of monitoring and control functions. 2026-05-20 9.8=
    CVE-2026-9141 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9141 ] Taiko N= etwork Communications Pte Ltd.--AG1000-01A SMS Alert Gateway Taiko AG1000-0=
    1A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripti=
    ng vulnerability in the embedded web configuration interface that allows au= thenticated attackers to execute persistent JavaScript by fragmenting malic= ious payloads across multiple administrative form fields. Attackers can byp= ass front-end length restrictions using JavaScript comments and template li= terals to concatenate executable script fragments that are rendered in admi= nistrative dashboard views such as index.zhtml, resulting in persistent scr= ipt execution within administrative sessions. 2026-05-20 7.6 CVE-2026-9144 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-9144 ] Talend--Talend Adminis= tration Center A broken access control issue has been identified in the Tal= end Administration Center, that allows a user with "View" permission to mod= ify the Talend Studio update URL. This issue was resolved in a patch, which=
    is already available. 2026-05-20 8.2 CVE-2026-9057 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-9057 ] tenable--Terrascan Terrascan v1.18.3 and prio=
    r are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url = parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/lo= cal/file/scan) when running in server mode. An unauthenticated remote attac= ker can supply an arbitrary URL as the webhook_url multipart form parameter=
    . After scanning the uploaded file, Terrascan sends an HTTP POST request to=
    the attacker-controlled URL containing the full scan results as a JSON bod=
    y, with the attacker-supplied webhook_token forwarded as a Bearer token in = the Authorization header. The retryable HTTP client retries up to 10 times =
    on failure. This affects deployments running terrascan in server mode (terr= ascan server), which binds to 0.0.0.0 with no authentication. Note: Terrasc=
    an was archived in August 2023 and no patch will be released. 2026-05-19 7.=
    5 CVE-2026-47356 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47356 ] tena= ble--Terrascan Terrascan v1.18.3 and prior are vulnerable to Server-Side Re= quest Forgery (SSRF) via the remote_url parameter in the remote directory s= can endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when run= ning in server mode. An unauthenticated remote attacker can supply an attac= ker-controlled HTTP URL as remote_url with remote_type set to "http". The U=
    RL is passed directly to hashicorp/go-getter (v1.7.5) without validation. G= o-getter's HttpGetter supports the X-Terraform-Get response header, allowin=
    g the attacker's server to redirect the download to a file:// URL, enabling=
    local file read. Additionally, HttpGetter has Netrc set to true, causing i=
    t to read ~/.netrc and send stored credentials to attacker-controlled hostn= ames. This affects deployments running terrascan in server mode (terrascan = server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was=
    archived in August 2023 and no patch will be released. 2026-05-19 7.5 CVE-= 2026-47357 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47357 ] tenable--T= errascan Terrascan v1.18.3 and prior are vulnerable to Server-Side Request = Forgery (SSRF) via external URL resolution in uploaded IaC templates when r= unning in server mode. When Terrascan parses uploaded ARM templates or Clou= dFormation templates, it resolves external URLs referenced within those tem= plates via hashicorp/go-getter with all default detectors enabled, includin=
    g FileDetector. An unauthenticated remote attacker can upload an ARM templa=
    te containing a templateLink.uri or parametersLink.uri field, or a CloudFor= mation template containing an AWS::CloudFormation::Stack TemplateURL field,=
    pointing to an attacker-controlled URL. Terrascan will fetch the attacker-= controlled URL server-side. Unlike SSRF via the remote scan endpoint, file:=
    // URLs are directly usable without requiring an X-Terraform-Get redirect, = enabling local file read. This affects deployments running terrascan in ser= ver mode (terrascan server), which binds to 0.0.0.0 with no authentication.=
    Note: Terrascan was archived in August 2023 and no patch will be released.=
    2026-05-19 7.5 CVE-2026-47358 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-47358 ] Tenda--F456 A security vulnerability has been detected in Tenda F= 456 1.0.0.5. This affects the function frmL7ImForm of the file /goform/L7Im=
    . The manipulation of the argument page leads to buffer overflow. The attac=
    k can be initiated remotely. The exploit has been disclosed publicly and ma=
    y be used. 2026-05-24 8.8 CVE-2026-9389 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-9389 ] themefusion--Avada (Fusion) Builder The Avada Builder (f= usion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote=
    Code Execution via PHP Function Injection in versions up to and including = 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Co= nditional_Render_Helper::get_value()` passing attacker-controlled values fr=
    om a base64-decoded JSON blob directly to `call_user_func()` without any al= lowlist validation. This is exploitable by unauthenticated attackers throug=
    h the `fusion_get_widget_markup` AJAX endpoint, which is registered for non= -privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_m= arkup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), bu=
    t this nonce is generated for user ID 0 and is deterministically exposed in=
    the JavaScript output of any public-facing page containing a Post Cards (`= [fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) e= lement. This makes it possible for unauthenticated attackers to execute arb= itrary code on affected sites. 2026-05-21 9.8 CVE-2026-6279 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-6279 ] themeum--Kirki Freeform Page Builder,=
    Website Builder & Customizer The Kirki - Freeform Page Builder, Website Bu= ilder & Customizer plugin for WordPress is vulnerable to arbitrary file del= etion due to insufficient file path validation and missing capability check=
    in the 'downloadZIP' function in all versions up to, and including, 6.0.6.=
    This makes it possible for unauthenticated attackers to read and delete ar= bitrary files limited in the WordPress uploads base directory. 2026-05-19 7=
    .5 CVE-2026-8073 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8073 ] theme= want--Easy Elements for Elementor Addons & Website Templates The Easy Eleme= nts for Elementor - Addons & Website Templates plugin for WordPress is vuln= erable to privilege escalation via user registration in all versions up to,=
    and including, 1.4.4. This is due to the 'easyel_handle_register' function=
    not restricting what user roles a user can register with. This makes it po= ssible for unauthenticated attackers to supply the 'administrator' role dur= ing registration and gain administrator access to the site. 2026-05-20 9.8 = CVE-2026-7284 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7284 ] themewan= t--Easy Elements for Elementor Addons & Website Templates The Easy Elements=
    for Elementor - Addons & Website Templates plugin for WordPress is vulnera= ble to Privilege Escalation in all versions up to, and including, 1.4.5 via=
    the `easyel_handle_register()` function. This is due to the `wp_ajax_nopri= v_eel_register` AJAX handler iterating the attacker-controlled `custom_meta=
    ` POST array and writing every supplied key-value pair to the newly created=
    user's meta via `update_user_meta()` without any key whitelist or blocklis=
    t, allowing the `wp_capabilities` user meta key to be overwritten after `wp= _insert_user()` has already assigned a safe role. This makes it possible fo=
    r unauthenticated attackers to register a new account with full administrat= or-level privileges by supplying `custom_meta[wp_capabilities][administrato= r]=3D1`. Exploitation requires that user registration is enabled on the sit=
    e and that at least one page exposes the Login/Register widget, which publi= shes the required `easy_elements_nonce` into the page DOM where it can be r= etrieved by any unauthenticated visitor via a simple GET request. 2026-05-2=
    2 8.8 CVE-2026-9018 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9018 ] TO= NNET--TPR7308 E-LAN Hybrid Recording System developed by TONNET has a SQL I= njection vulnerability, allowing unauthenticated remote attackers to inject=
    arbitrary SQL commands to read database contents. 2026-05-20 7.5 CVE-2026-= 9003 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9003 ] Totolink--A8000RU=
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vu= lnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstec= gi.cgi of the component Web Management Interface. The manipulation of the a= rgument ip results in os command injection. The attack can be executed remo= tely. The exploit has been made public and could be used. 2026-05-24 9.8 CV= E-2026-9384 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9384 ] Totolink--= A8000RU A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200= 521. This issue affects the function setTracerouteCfg of the file /cgi-bin/= cstecgi.cgi of the component Web Management Interface. This manipulation of=
    the argument command causes os command injection. The attack is possible t=
    o be carried out remotely. The exploit has been publicly disclosed and may =
    be utilized. 2026-05-24 9.8 CVE-2026-9385 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-9385 ] Totolink--A8000RU A vulnerability was identified in Tot= olink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg =
    of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface.=
    Such manipulation of the argument lang leads to os command injection. The = attack may be performed from remote. The exploit is publicly available and = might be used. 2026-05-24 9.8 CVE-2026-9386 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-9386 ] Totolink--A8000RU A security flaw has been discovered=
    in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the funct= ion setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Mana= gement Interface. Performing a manipulation of the argument resetFlags resu= lts in os command injection. It is possible to initiate the attack remotely=
    . The exploit has been released to the public and may be used for attacks. = 2026-05-24 9.8 CVE-2026-9387 [ https://www.cve.org/CVERecord?id=3DCVE-2026-= 9387 ] Totolink--A8000RU A weakness has been identified in Totolink A8000RU=
    7.1cu.643_b20200521. The impacted element is the function setScheduleCfg o=
    f the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. = Executing a manipulation of the argument mode can lead to os command inject= ion. It is possible to launch the attack remotely. The exploit has been mad=
    e available to the public and could be used for attacks. 2026-05-24 9.8 CVE= -2026-9388 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9388 ] Totolink--A= 8000RU A vulnerability was identified in Totolink A8000RU 7.1cu.643_b202005= 21. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi o=
    f the component Web Management Interface. Such manipulation of the argument=
    provider leads to os command injection. The attack may be launched remotel=
    y. The exploit is publicly available and might be used. 2026-05-24 9.8 CVE-= 2026-9404 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9404 ] Totolink--A8= 000RU A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20= 200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cste= cgi.cgi of the component Web Management Interface. Performing a manipulatio=
    n of the argument enable results in os command injection. Remote exploitati=
    on of the attack is possible. The exploit has been released to the public a=
    nd may be used for attacks. 2026-05-24 9.8 CVE-2026-9405 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-9405 ] Totolink--A8000RU A weakness has been id= entified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function = setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Manageme=
    nt Interface. Executing a manipulation of the argument enable can lead to o=
    s command injection. The attack can be executed remotely. The exploit has b= een made available to the public and could be used for attacks. 2026-05-24 = 9.8 CVE-2026-9406 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9406 ] Toto= link--A8000RU A security vulnerability has been detected in Totolink A8000R=
    U 7.1cu.643_b20200521. Affected by this vulnerability is the function setFi= rewallType of the file /cgi-bin/cstecgi.cgi of the component Web Management=
    Interface. The manipulation of the argument firewallType leads to os comma=
    nd injection. The attack is possible to be carried out remotely. The exploi=
    t has been disclosed publicly and may be used. 2026-05-24 9.8 CVE-2026-9407=
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-9407 ] Trend Micro, Inc.--Tr= endAI Apex One A vulnerability in the Trend Micro Apex One management conso=
    le could allow a remote attacker to upload malicious code and execute comma= nds on affected installations. Please note: although this vulnerability car= ries a technical critical CVSS rating, this was reported via responsible di= sclosure via a researcher through the Zero Day Initiative. The SaaS version=
    s of the product have already been mitigated and no customer action require=
    d. For this particular vulnerability, an attacker must have access to the T= rend Micro Apex One Management Console, so customers that have their consol= e=C3=AF=C2=BF=C2=BDs IP address exposed externally should consider mitigati=
    ng factors such as source restrictions if not already applied. 2026-05-21 9=
    .8 CVE-2025-71210 [ https://www.cve.org/CVERecord?id=3DCVE-2025-71210 ] Tre=
    nd Micro, Inc.--TrendAI Apex One A vulnerability in the Trend Micro Apex On=
    e management console could allow a remote attacker to upload malicious code=
    and execute commands on affected installations. This vulnerability is simi= lar in scope to CVE-2025-71210 but affects a different executable. Please n= ote: although this vulnerability carries a technical critical CVSS rating, = this was reported via responsible disclosure via a researcher through the Z= ero Day Initiative. The SaaS versions of the product have already been miti= gated and no customer action required. For this particular vulnerability, a=
    n attacker must have access to the Trend Micro Apex One Management Console,=
    so customers that have their console=C3=AF=C2=BF=C2=BDs IP address exposed=
    externally should consider mitigating factors such as source restrictions =
    if not already applied. 2026-05-21 9.8 CVE-2025-71211 [ https://www.cve.org= /CVERecord?id=3DCVE-2025-71211 ] Trend Micro, Inc.--TrendAI Apex One A link=
    following vulnerability in the Trend Micro Apex One scan engine could allo=
    w a local attacker to escalate privileges on affected installations. Please=
    note: an attacker must first obtain the ability to execute low-privileged = code on the target system in order to exploit this vulnerability. 2026-05-2=
    1 7.8 CVE-2025-71212 [ https://www.cve.org/CVERecord?id=3DCVE-2025-71212 ] = Trend Micro, Inc.--TrendAI Apex One An origin validation error vulnerabilit=
    y in Trend Micro Apex One could allow a local attacker to escalate privileg=
    es on affected installations. Please note: an attacker must first obtain th=
    e ability to execute low-privileged code on the target system in order to e= xploit this vulnerability. 2026-05-21 7.8 CVE-2025-71213 [ https://www.cve.= org/CVERecord?id=3DCVE-2025-71213 ] Trend Micro, Inc.--TrendAI Apex One An = origin validation vulnerability in the Apex One/SEP agent could allow a loc=
    al attacker to escalate privileges on affected installations. Please note: =
    an attacker must first obtain the ability to execute low-privileged code on=
    the target system in order to exploit this vulnerability. 2026-05-21 7.8 C= VE-2026-34927 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34927 ] Trend M= icro, Inc.--TrendAI Apex One An origin validation vulnerability in the Apex=
    One/SEP agent could allow a local attacker to escalate privileges on affec= ted installations. This is similar to CVE-2026-34927 but exists in a differ= ent named pipe communication mechanism. Please note: an attacker must first=
    obtain the ability to execute low-privileged code on the target system in = order to exploit this vulnerability. 2026-05-21 7.8 CVE-2026-34928 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-34928 ] Trend Micro, Inc.--TrendAI Ap=
    ex One An origin validation vulnerability in the Apex One/SEP agent could a= llow a local attacker to escalate privileges on affected installations. Thi=
    s is similar to CVE-2026-34927 but exists in a different inter-process comm= unication mechanism. Please note: an attacker must first obtain the ability=
    to execute low-privileged code on the target system in order to exploit th=
    is vulnerability. 2026-05-21 7.8 CVE-2026-34929 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-34929 ] Trend Micro, Inc.--TrendAI Apex One An origin va= lidation vulnerability in the Apex One/SEP agent could allow a local attack=
    er to escalate privileges on affected installations. This is similar to CVE= -2026-34927 but exists in a different process protection mechanism. Please = note: an attacker must first obtain the ability to execute low-privileged c= ode on the target system in order to exploit this vulnerability. 2026-05-21=
    7.8 CVE-2026-34930 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34930 ] T= rend Micro, Inc.--TrendAI Apex One An origin validation vulnerability in th=
    e Apex One/SEP agent could allow a local attacker to escalate privileges on=
    affected installations. This is similar to CVE-2026-45207 but exists in a = different process protection communication mechanism. Please note: an attac= ker must first obtain the ability to execute low-privileged code on the tar= get system in order to exploit this vulnerability. 2026-05-21 7.8 CVE-2026-= 45206 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45206 ] Trend Micro, In= c.--TrendAI Apex One An origin validation vulnerability in the Apex One/SEP=
    agent could allow a local attacker to escalate privileges on affected inst= allations. This is similar to CVE-2026-45206 but exists in a different proc= ess protection communication mechanism. Please note: an attacker must first=
    obtain the ability to execute low-privileged code on the target system in = order to exploit this vulnerability. 2026-05-21 7.8 CVE-2026-45207 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-45207 ] Trend Micro, Inc.--TrendAI Ap=
    ex One A time-of-check time-of-use vulnerability in the Apex One/SEP agent = could allow a local attacker to escalate privileges on affected installatio= ns. Please note: an attacker must first obtain the ability to execute low-p= rivileged code on the target system in order to exploit this vulnerability.=
    2026-05-21 7.8 CVE-2026-45208 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-45208 ] TriliumNext--Trilium Trilium Notes is a cross-platform, hierarchi= cal note taking application focused on building large personal knowledge ba= ses. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.= 101.3) allows full authentication bypass when running in an Electron enviro= nment. When Trilium detects an Electron environment, it explicitly disables=
    authentication middleware for the Clipper API, exposing endpoints such as = /api/clipper/notes to the network with no password, API token, or CSRF prot= ection. An attacker on a shared network (for example, a corporate LAN or pu= blic Wi-Fi) can scan for open high-range ports using a tool like nmap, sinc=
    e Trilium often binds to ports such as 37840. Once a candidate port is foun=
    d, an unauthenticated request to the Clipper handshake endpoint, which also=
    bypasses authentication, confirms a Trilium instance by returning the appl= ication name and protocol version. This facilitates unauthorized data acces=
    s, phishing, and local system compromise. The issue has been fixed in versi=
    on 0.102.2. 2026-05-20 8.6 CVE-2026-39310 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-39310 ] twigphp--Twig Twig versions 2.16.x and 3.9.0 through 3= .25.x contain a sandbox bypass vulnerability when using a SourcePolicyInter= face that allows attackers with template rendering capabilities to pass arb= itrary PHP callables to sort, filter, map, and reduce filters. Attackers ca=
    n exploit the runtime check that fails to use the current template source t=
    o bypass sandbox restrictions and execute arbitrary code when the sandbox i=
    s enabled through a source policy rather than globally. 2026-05-20 8.8 CVE-= 2026-24425 [ https://www.cve.org/CVERecord?id=3DCVE-2026-24425 ] Tyler Tech= nologies--TID-L Tyler Identity Local (TID-L) uses documented, default admin= istrative credentials. Users are not required to change the credentials bef= ore deployment. TID-L has not been distributed since December 2020, and has=
    not been supported since 2021. 2026-05-19 9.8 CVE-2026-44159 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-44159 ] Ubiquiti Inc--UniFi OS Server A ma= licious actor with access to the network could exploit an Improper Access C= ontrol vulnerability found in UniFi OS devices to make unauthorized changes=
    to the system. 2026-05-22 10 CVE-2026-34908 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-34908 ] Ubiquiti Inc--UniFi OS Server A malicious actor wit=
    h access to the network could exploit a Path Traversal vulnerability found =
    in UniFi OS devices to access files on the underlying system that could be = manipulated to access an underlying account. 2026-05-22 10 CVE-2026-34909 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-34909 ] Ubiquiti Inc--UniFi OS=
    Server A malicious actor with access to the network could exploit an Impro= per Input Validation vulnerability found in UniFi OS devices to execute a C= ommand Injection. 2026-05-22 10 CVE-2026-34910 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-34910 ] Ubiquiti Inc--UniFi OS Server A malicious actor w= ith access to the network and high privileges could exploit an Improper Inp=
    ut Validation vulnerability found in UniFi OS devices to execute a Command = Injection. 2026-05-22 9.1 CVE-2026-33000 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-33000 ] Ubiquiti Inc--UniFi OS Server A malicious actor with ac= cess to the network and low privileges could exploit a Path Traversal vulne= rability found in UniFi OS devices to access files on the underlying system=
    that could be manipulated to obtain sensitive information. 2026-05-22 7.7 = CVE-2026-34911 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34911 ] ultima= te-form-builder-lite--Ultimate Form Builder Lite WordPress Ultimate Form Bu= ilder Lite plugin version 1.3.7 and below contains an SQL injection vulnera= bility that allows authenticated attackers to manipulate database queries b=
    y injecting SQL code through the entry_id POST parameter. Attackers can sen=
    d POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_deta= il_action action to extract, modify, or escalate privileges within the Word= Press database. 2026-05-23 7.1 CVE-2018-25352 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2018-25352 ] UserSpice--userSpice userSpice 4.3.24 contains a u= sername enumeration vulnerability that allows unauthenticated attackers to = discover valid usernames by sending POST requests to the existingUsernameCh= eck.php endpoint. Attackers can submit usernames and analyze response text = for the 'taken' string to identify existing accounts in the system. 2026-05= -23 9.8 CVE-2018-25350 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25350 =
    ] web-dorado--Contact Form Maker WordPress Contact Form Maker Plugin 1.12.2=
    0 contains SQL injection vulnerabilities that allow authenticated attackers=
    to manipulate database queries through the FormMakerSQLMapping and generet= e_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'na= me' and 'search_labels' parameters to extract sensitive database informatio=
    n or escalate privileges. 2026-05-23 7.1 CVE-2018-25347 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2018-25347 ] webdriverio--webdriverio WebdriverIO is =
    a test automation framework for unit, e2e and component testing using WebDr= iver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command in= jection vulnerability leading to remote code execution (RCE) in test orches= tration. Git permits branch names containing shell metacharacters, and getG= itMetadataForAISelection() interpolates these names directly into execSync(=
    ) calls without sanitization. An attacker can exploit this by supplying a m= alicious repository (via testOrchestrationOptions.runSmartSelection.source,=
    or the current directory if unset) whose branch name carries a payload, ca= using the shell to execute arbitrary code. This enables remote code executi=
    on on CI/CD servers and developer machines, leading to credential and secre=
    t disclosure, source code and SSH key exfiltration, system compromise, and = supply chain attacks via tampered build artifacts. The issue has been fixed=
    in version 9.24.0. 2026-05-18 9.8 CVE-2026-25244 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-25244 ] weDevs--WP ERP Pro The WP ERP Pro plugin for W= ordPress is vulnerable to SQL Injection via the 'search_key' parameter in a=
    ll versions up to, and including, 1.5.1. This is due to insufficient escapi=
    ng on the user supplied parameter and lack of sufficient preparation on the=
    existing SQL query. This makes it possible for unauthenticated attackers t=
    o append additional SQL queries into already existing queries that can be u= sed to extract sensitive information from the database. 2026-05-22 7.5 CVE-= 2026-4834 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4834 ] windmill-lab= s--windmill Windmill prior to 1.703.2 contains an incorrect default permiss= ions vulnerability in nsjail sandbox configuration files where /etc is bind= -mounted without read-write restrictions, allowing authenticated users to w= rite arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/= ca-certificates.crt from within script execution sandboxes. Attackers can e= xploit persistent poisoned entries across all subsequent script executions =
    on the same worker pod to redirect hostnames, intercept DNS queries, perfor=
    m transparent HTTPS man-in-the-middle attacks, and intercept WM_TOKEN JWTs =
    to gain workspace-admin access to other users' workspaces. 2026-05-19 8.1 C= VE-2026-47107 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47107 ] Wishlis=
    t Member--Wishlist Member The WishList Member plugin for WordPress is vulne= rable to Privilege Escalation via Missing Authorization in versions up to a=
    nd including 3.30.1. This is due to the missing capability and nonce check =
    in the ajax_get_screen() function. This makes it possible for authenticated=
    attackers, with Subscriber-level access and above, to supply an arbitrary = admin screen identifier via the data[url] parameter, causing the plugin to = load and execute the administrative API configuration template without auth= orization. The rendered HTML, which contains the plugin's plaintext REST AP=
    I Secret Key, is returned directly to the attacker in the AJAX JSON respons=
    e. An attacker who obtains this key can authenticate to the WishList Member=
    API, create a new membership level assigned the administrator WordPress ro= le, and register an arbitrary administrator-level user account, resulting i=
    n complete site takeover. 2026-05-23 8.8 CVE-2026-6419 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-6419 ] Wishlist Member--Wishlist Member The WishL= ist Member plugin for WordPress is vulnerable to Missing Authorization lead= ing to Sensitive Information Disclosure and Privilege Escalation in version=
    s up to and including 3.30.1. This is due to the missing capability checks =
    in the 'export_settings' function. This function returns the REST API Secre=
    t Key to the attacker in the AJAX JSON response. An attacker who obtains th=
    is key can authenticate to the WishList Member API, create a new membership=
    level assigned the administrator WordPress role, and register an arbitrary=
    administrator-level user account, resulting in complete site takeover. 202= 6-05-23 8.8 CVE-2026-6895 [ https://www.cve.org/CVERecord?id=3DCVE-2026-689=
    5 ] Wishlist Member--Wishlist Member The Wishlist Member plugin for WordPre=
    ss is vulnerable to unauthorized modification of data due to a missing capa= bility check on the 'WishListMember\Features\Team_Accounts::save_settings' = function in all versions up to, and including, 3.30.1. This makes it possib=
    le for authenticated attackers, with Subscriber-level access and above, to = update arbitrary plugin options, includes the REST API Secret Key, which ca=
    n be used to create a new membership level assigned the administrator WordP= ress role, and register an arbitrary administrator-level user account, resu= lting in complete site takeover. 2026-05-23 8.8 CVE-2026-6897 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-6897 ] Wishlist Member--Wishlist Member Th=
    e Wishlist Member plugin for WordPress is vulnerable to unauthorized modifi= cation of data due to a missing capability check on the 'WishListMember3_Ho= oks::generate_api_key' function in all versions up to, and including, 3.30.=
    1. This makes it possible for authenticated attackers, with Subscriber-leve=
    l access and above, to update the REST API Secret Key, which can be used to=
    create a new membership level assigned the administrator WordPress role, a=
    nd register an arbitrary administrator-level user account, resulting in com= plete site takeover. 2026-05-23 8.8 CVE-2026-6898 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-6898 ] woocommerce--WooCommerce PayPal Payments The Wo= oCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorize=
    d order manipulation and information disclosure due to missing authorizatio=
    n checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in=
    all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint = accepts an arbitrary WooCommerce order ID in the `pay-now` context without = validating order ownership, allowing attackers to create PayPal orders for = any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint = returns full PayPal order details for any PayPal order ID without binding t=
    o the requester's session. This makes it possible for unauthenticated attac= kers to chain these endpoints to manipulate other customers' order payment = flows and exfiltrate sensitive order details (payer information, shipping d= ata) by creating a PayPal order for a victim's WC order and then retrieving=
    the PayPal order data. 2026-05-23 8.2 CVE-2026-9284 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-9284 ] Wp Directory Kit--WP Directory Kit Improper = Neutralization of Special Elements used in an SQL Command ('SQL Injection')=
    vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Inject= ion. This issue affects WP Directory Kit: from n/a through 1.5.0. 2026-05-2=
    1 9.3 CVE-2026-39531 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39531 ] =
    WP Swings--Gift Cards For WooCommerce Pro Unrestricted Upload of File with = Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro al= lows Using Malicious Files. This issue affects Gift Cards For WooCommerce P= ro: from n/a through 4.2.6. 2026-05-20 10 CVE-2026-45444 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-45444 ] yiisoft--yii2 Yii 2 is a PHP applicatio=
    n framework. Versions 2.0.54 and prior contain flawed logic in the core vie=
    w rendering method View::renderPhpFile() that leads to Local File Inclusion=
    . The function calls extract($_params_, EXTR_OVERWRITE) before the require = statement that loads the view file. As a result, a caller-controlled _file_=
    key in the $params array overwrites the internal local variable specifying=
    which file to include, potentially enabling RCE if an attacker can write P=
    HP files through a separate primitive, as well as information disclosure. T= his issue has been fixed in version 2.0.55. 2026-05-20 7.4 CVE-2026-39850 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-39850 ] YITH--YITH WooCommerce=
    Product Add-Ons Improper Neutralization of Special Elements used in an SQL=
    Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product A= dd-Ons allows Blind SQL Injection. This issue affects YITH WooCommerce Prod= uct Add-Ons: from n/a through 4.29.0. 2026-05-20 7.6 CVE-2026-42383 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-42383 ] ZKTeco--SSC335-GC2063-Face-0= b77 Solution Camera An undocumented configuration export port is accessible=
    on some models of ZKTeco CCTV cameras. This port does not require authenti= cation and exposes critical information about the camera such as open servi= ces and camera account credentials. 2026-05-20 9.1 CVE-2026-8598 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-8598 ] Zohocorp--ManageEngine ADSelfSer= vice Plus Zohocorp ManageEngine ADSelfService Plus version before 6525, Dat= aSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnera= ble to Authenticated Remote code execution in the agent machines due to the=
    bug in the 3rd party dependency. 2026-05-21 8.4 CVE-2026-2740 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-2740 ]=20

    Back to top [ #top ]

    Medium Vulnerabilities

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info 5= 46669204--vps-inventory-monitoring A vulnerability was determined in 546669= 204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9=
    . This issue affects the function eval of the file app/index/command/VpsTes= t.php of the component VpsTest Console. Executing a manipulation of the arg= ument vf can lead to code injection. The attack may be performed from remot=
    e. The exploit has been publicly disclosed and may be utilized. This produc=
    t utilizes a rolling release system for continuous delivery, and as such, v= ersion information for affected or updated releases is not disclosed. The p= roject was informed of the problem early through an issue report but has no=
    t responded yet. 2026-05-23 6.3 CVE-2026-9302 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-9302 ] VDB-365249 | 546669204 vps-inventory-monitoring Vps= Test Console VpsTest.php eval code injection [ https://vuldb.com/vuln/36524=
    9 ]
    VDB-365249 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65249/cti ]
    Submit #811843 | 546669204 vps-inventory-monitoring <=3D98c00b3 Code Inject= ion / Eval Injection [ https://vuldb.com/submit/811843 ] https://github.com/546669204/vps-inventory-monitoring/issues/36 https://github.com/dntyfate/cve/issues/2 https://github.com/546669204/vps-inventory-monitoring/
    =C2=A0 ADD-ONS.ORG--PDF for Elementor Forms + Drag And Drop Template Builde=
    r Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Form=
    s + Drag And Drop Template Builder allows Exploiting Incorrectly Configured=
    Access Control Security Levels. This issue affects PDF for Elementor Forms=
    + Drag And Drop Template Builder: from n/a through 5.5.1. 2026-05-20 5 CVE= -2026-45443 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45443 ] https://p= atchstack.com/database/wordpress/plugin/pdf-for-elementor-forms/vulnerabili= ty/wordpress-pdf-for-elementor-forms-drag-and-drop-template-builder-plugin-= 5-5-1-broken-access-control-vulnerability?_s_id=3Dcve
    =C2=A0 askywhale--Games Catalog The Games Catalog plugin for WordPress is v= ulnerable to Cross-Site Request Forgery in versions up to, and including, 1= .2.0. This is due to missing or incorrect nonce validation on the gc_crud()=
    function which handles the delete action (action=3Ddelete) via a GET reque=
    st without any wp_verify_nonce() / check_admin_referer() call. This makes i=
    t possible for unauthenticated attackers to delete arbitrary game catalog e= ntries (including the associated WordPress post created for the game) via a=
    forged request, granted they can trick a site administrator into performin=
    g an action such as clicking on a link. 2026-05-20 4.3 CVE-2026-8418 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-8418 ] https://www.wordfence.com/th= reat-intel/vulnerabilities/id/0888cda8-63ca-44f6-a3eb-765c14a7e6c7?source= =3Dcve https://plugins.trac.wordpress.org/browser/game-catalog/trunk/admin-crud.ph= p#L94 https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2.0/admin-cr= ud.php#L94 https://plugins.trac.wordpress.org/browser/game-catalog/trunk/admin-crud.ph= p#L31 https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2.0/admin-cr= ud.php#L31 https://plugins.trac.wordpress.org/browser/game-catalog/trunk/games-catalog= .php#L96 https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2.0/games-ca= talog.php#L96
    =C2=A0 baptisteArno--typebot.io Typebot is a chatbot builder tool. In versi= ons 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller = against the provided typebotId but fetches logs solely by resultId without = verifying that the result belongs to the authorized typebot, leading to IDO=
    R. An authenticated attacker can supply their own typebotId alongside any v= ictim's resultId to read execution logs from other workspaces, leaking sens= itive data including HTTP response bodies, AI model outputs, and webhook pa= yloads. Every other result-scoped endpoint in the same router properly vali= dates that the resultId belongs to the authorized typebotId. This confirms = the missing check is an oversight, not a design choice. This issue has been=
    fixed in version 3.15.2. 2026-05-22 6.5 CVE-2026-28444 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-28444 ] https://github.com/baptisteArno/typebot.= io/security/advisories/GHSA-c63p-mqx5-75r7 https://github.com/baptisteArno/typebot.io/commit/d82b2d47c86ae614a08d4073c= 669ca64442faff2
    https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0
    =C2=A0 baptisteArno--typebot.io TypeBot is a chatbot builder tool. In versi= ons 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions=
    to any authenticated user who references a target bot ID in a Typebot Link=
    block, regardless of workspace ownership, leading to IDOR. The authorizati=
    on check uses Array.filter() with an async callback - since filter() is syn= chronous, the callback always returns a truthy Promise, so the access contr=
    ol predicate is never actually evaluated. Any authenticated Typebot user ca=
    n read the full definition of any other workspace's private bots, including=
    : all conversation blocks and logic flow, variable values embedded in the b=
    ot (credentials, API keys, PII), webhook URLs and integration configuration=
    s. This issue has been fixed in version 3.16.0. 2026-05-22 6.5 CVE-2026-399=
    66 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39966 ] https://github.com= /baptisteArno/typebot.io/security/advisories/GHSA-3fr5-999r-84qj https://github.com/baptisteArno/typebot.io/commit/b9530a089b43bfa6e79e3ff9c= bfab921ce832f45
    https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0
    =C2=A0 baptisteArno--typebot.io TypeBot is a chatbot builder tool. In versi= ons 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/wor= kspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the=
    x-hub-signature-256 HMAC signature included by Meta in every webhook deliv= ery. The webhook URL exposes both workspaceId and credentialsId as path par= ameters, which are logged in web server access logs, visible in Meta's webh= ook configuration dashboard, and potentially shared when configuring integr= ations. This allows any unauthenticated attacker to send spoofed webhook me= ssages to trigger bot flows, consume API resources, and interact with exter= nal services using the workspace owner's credentials. The issue has been fi= xed in version 3.17.0. 2026-05-22 6.5 CVE-2026-39969 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-39969 ] https://github.com/baptisteArno/typebot.io/= security/advisories/GHSA-8vqp-r5w7-v47f https://github.com/baptisteArno/typebot.io/releases/tag/v3.17.0
    =C2=A0 baptisteArno--typebot.io TypeBot is a chatbot builder tool. In versi= ons prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor=
    tags from rich text bubble content without filtering the javascript: URI s= cheme. A bot author can set a link URL to javascript:PAYLOAD, which execute=
    s in the visitor's browser context when clicked. Since the viewer is typica= lly embedded in a third-party site, the attacker's JavaScript runs in the h= ost page's origin and can exfiltrate cookies and session tokens. This can r= esult in any authenticated Typebot user (including those on the free tier) = being able to create a bot with this payload. Shared bots are publicly acce= ssible - no victim authentication is required. This issue has been resolved=
    in version 3.16.0. 2026-05-22 5.4 CVE-2026-39964 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-39964 ] https://github.com/baptisteArno/typebot.io/sec= urity/advisories/GHSA-hqmv-v56g-4m47 https://github.com/baptisteArno/typebot.io/commit/2c3fc7267a5e1529ba4b1a2ab= 4f1edb3e3b8990b
    https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0
    =C2=A0 Behance--Smartshop Smartshop 1 contains a cross-site request forgery=
    vulnerability that allows attackers to modify user profiles by tricking au= thenticated users into submitting malicious requests. Attackers can craft H= TML forms targeting editprofile.php with hidden fields for email and passwo=
    rd parameters that execute automatically when visited by an authenticated a= dmin user. 2026-05-23 4.3 CVE-2018-25343 [ https://www.cve.org/CVERecord?id= =3DCVE-2018-25343 ] ExploitDB-44824 [ https://www.exploit-db.com/exploits/4= 4824 ]
    Official Product Homepage [ https://www.behance.net/gallery/49080415/Smarts= hop-Free-e-commerce-website ]
    Product Reference [ https://github.com/smakosh/Smartshop/archive/master.zip=
    ]
    VulnCheck Advisory: Smartshop 1 Cross-Site Request Forgery via editprofile.= php [ https://www.vulncheck.com/advisories/smartshop-1-cross-site-request-f= orgery-via-editprofile-php ]
    =C2=A0 bentoml--BentoML BentoML is a Python library for building online ser= ving systems optimized for AI apps and model inference. In versions 1.4.38 = and prior, the build packaging workflow follows attacker-controlled symlink=
    s inside the build context and copies the referenced file contents into the=
    generated Bento artifact. If a victim builds an untrusted repository or ot= her attacker-supplied build context, the attacker can place a symlink such =
    as loot.txt -> /tmp/outside-marker.txt or a link to a more sensitive local = file. When bentoml build runs, BentoML dereferences the symlink and package=
    s the target file contents into the Bento. The leaked file can then propaga=
    te further through export, push, or containerization workflows. An attacker=
    can exfiltrate local files from the build host into the Bento artifact, ex= posing secrets such as cloud credentials, SSH keys, API tokens, environment=
    files, or other sensitive local configurations. Because Bento artifacts ar=
    e commonly exported, uploaded, stored, or containerized after build, the le= aked file contents can spread beyond the original build machine. This issue=
    has been fixed in version 1.4.39. 2026-05-22 5.5 CVE-2026-40610 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-40610 ] https://github.com/bentoml/Bent= oML/security/advisories/GHSA-mcfx-4vc6-qgxv https://github.com/bentoml/BentoML/commit/5fb7cd41f92e2a56b45391284cf15b9ac= 9963a1f
    https://github.com/bentoml/BentoML/releases/tag/v1.4.39
    =C2=A0 bestpractical--rt RT is an open source, enterprise-grade issue and t= icket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 con= tain a spreadsheet (CSV/formula) injection vulnerability. User-controlled d= ata in spreadsheet exports is not sanitized before being written to the out= put file, which can cause spreadsheet applications to interpret crafted val= ues as formulas or macros when the file is opened. This issue has been fixe=
    d in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immedia= tely, they can temporarily work around this issue by avoiding opening expor= ted RT spreadsheet files directly in spreadsheet applications when the data=
    may contain untrusted user input. 2026-05-22 4.6 CVE-2026-41073 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-41073 ] https://github.com/bestpractica= l/rt/security/advisories/GHSA-6x92-7v65-7m3r https://github.com/bestpractical/rt/releases/tag/rt-5.0.10 https://github.com/bestpractical/rt/releases/tag/rt-6.0.3
    =C2=A0 bigbluebutton--bigbluebutton BigBlueButton is an open-source virtual=
    classroom. In versions prior to 3.0.19, the recording playback (presentati=
    on format) was not sanitizing user's input in public chat. This allowed for=
    a malicious actor to craft and carry out a targeted XSS attack, activated =
    on anyone replaying the recording. This issue has been fixed 3.0.19. 2026-0= 5-18 6.5 CVE-2026-27737 [ https://www.cve.org/CVERecord?id=3DCVE-2026-27737=
    ] https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-= 8vv7-vj94-q2pv https://github.com/bigbluebutton/bbb-playback/commit/09e89bfe4ff8488b68c3ff= 040d3081e419dc89b1 https://github.com/bigbluebutton/bigbluebutton/commit/69f45aa1b963dc7d80179= d0155acc670aec5c4fc https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.19 https://github.com/blindsidenetworks/scalelite/releases/tag/v1.7.0
    =C2=A0 Brainstorm Force--Presto Player Missing Authorization vulnerability =
    in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured = Access Control Security Levels. This issue affects Presto Player: from n/a = through 4.1.3. 2026-05-19 4.3 CVE-2026-45442 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-45442 ] https://patchstack.com/database/wordpress/plugin/pr= esto-player/vulnerability/wordpress-presto-player-plugin-4-1-3-broken-acces= s-control-vulnerability?_s_id=3Dcve
    =C2=A0 broadstreetads--Broadstreet The Broadstreet plugin for WordPress is = vulnerable to Insecure Direct Object Reference in all versions up to, and i= ncluding, 1.52.2 via the get_sponsored_meta AJAX action due to missing vali= dation on a user controlled key. This makes it possible for authenticated a= ttackers, with Subscriber-level access and above, to disclose any private p= ost metadata. 2026-05-21 4.3 CVE-2026-1881 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-1881 ] https://www.wordfence.com/threat-intel/vulnerabilities= /id/328ccf8f-797b-4b1a-b0f1-afd8e44f41e6?source=3Dcve https://plugins.trac.wordpress.org/changeset?old_path=3D%2Fbroadstreet/tags= /1.52.2&new_path=3D%2Fbroadstreet/tags/1.53.2
    =C2=A0 burlingtonbytes--WP Blockade Visual Page Builder The WP Blockade plu= gin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '= shortcode' parameter in all versions up to and including 0.9.14. This is du=
    e to insufficient input sanitization and output escaping in the render_shor= tcode_preview() function. The function receives user input from $_GET['shor= tcode'], passes it through stripslashes() without any sanitization, and the=
    n outputs it directly via echo do_shortcode($shortcode) on line 393. When t=
    he input is not a valid WordPress shortcode (e.g., an HTML tag with JavaScr= ipt event handlers), do_shortcode() returns it unchanged, and it is reflect=
    ed into the page without escaping. The endpoint is registered via admin_pos=
    t_ (not admin_post_nopriv_), meaning it requires the user to be logged in w= ith at minimum a Subscriber-level account. There is no nonce verification o=
    r additional capability check. This makes it possible for authenticated att= ackers, with Subscriber-level access and above, to inject arbitrary web scr= ipts in pages that will execute if they can successfully trick a user into = performing an action such as clicking a link. 2026-05-22 6.1 CVE-2026-3481 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-3481 ] https://www.wordfence.= com/threat-intel/vulnerabilities/id/66950509-ce2a-42fe-a8b2-2a92a1b573c3?so= urce=3Dcve https://plugins.trac.wordpress.org/browser/wp-blockade/trunk/wp-blockade.ph= p#L393 https://plugins.trac.wordpress.org/browser/wp-blockade/tags/0.9.14/wp-block= ade.php#L393 https://plugins.trac.wordpress.org/browser/wp-blockade/trunk/wp-blockade.ph= p#L360 https://plugins.trac.wordpress.org/browser/wp-blockade/tags/0.9.14/wp-block= ade.php#L360
    =C2=A0 calcom--cal.diy A security flaw has been discovered in calcom cal.di=
    y up to 4.9.4. The affected element is the function validateUrlForSSRF of t=
    he file apps/web/app/api/logo/route.ts of the component Logo API. The manip= ulation results in server-side request forgery. It is possible to launch th=
    e attack remotely. Attacks of this nature are highly complex. The exploitab= ility is described as difficult. The exploit has been released to the publi=
    c and may be used for attacks. The vendor was contacted early about this di= sclosure but did not respond in any way. 2026-05-23 5 CVE-2026-9304 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-9304 ] VDB-365251 | calcom cal.diy L= ogo API route.ts validateUrlForSSRF server-side request forgery [ https://v= uldb.com/vuln/365251 ]
    VDB-365251 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365251= /cti ]
    Submit #812176 | cal.com <=3D v4.9.4 Server-Side Request Forgery (CWE-918) =
    [ https://vuldb.com/submit/812176 ] https://gist.github.com/YLChen-007/b3d0b85767b7e346a291933d602fbb3b
    =C2=A0 calcom--cal.diy A vulnerability was determined in calcom cal.diy up =
    to 4.9.4. Affected by this issue is the function getServerSideProps of the = file apps/web/modules/bookings/views/bookings-single-view.getServerSideProp= s.tsx of the component Generic React API. This manipulation of the argument=
    cancelledBy/rescheduledBy causes information disclosure. The attack can be=
    initiated remotely. The exploit has been publicly disclosed and may be uti= lized. The vendor was contacted early about this disclosure but did not res= pond in any way. 2026-05-24 5.3 CVE-2026-9349 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-9349 ] VDB-365312 | calcom cal.diy Generic React API booki= ngs-single-view.getServerSideProps.tsx getServerSideProps information discl= osure [ https://vuldb.com/vuln/365312 ]
    VDB-365312 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65312/cti ]
    Submit #812177 | cal.com <=3D v4.9.4 Exposure of Sensitive Information (CWE= -200) [ https://vuldb.com/submit/812177 ] https://gist.github.com/YLChen-007/b59c44d1550c4b0f373ca4eb1c150994
    =C2=A0 calcom--cal.diy A vulnerability was identified in calcom cal.diy up =
    to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-= site request forgery. It is possible to initiate the attack remotely. The e= xploit is publicly available and might be used. The vendor was contacted ea= rly about this disclosure but did not respond in any way. 2026-05-23 4.3 CV= E-2026-9303 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9303 ] VDB-365250=
    | calcom cal.diy cross-site request forgery [ https://vuldb.com/vuln/36525=
    0 ]
    VDB-365250 | CTI Indicators (IOB, IOC) [ https://vuldb.com/vuln/365250/cti ] Submit #812173 | cal.com <=3D v4.9.4 Cross-Site Request Forgery (CWE-352) [=
    https://vuldb.com/submit/812173 ]
    Submit #812175 | cal.com <=3D v4.9.4 Cross-Site Request Forgery (CWE-352) (= Duplicate) [ https://vuldb.com/submit/812175 ] https://gist.github.com/YLChen-007/26663d9558e15994176dc420d2e11d48 https://gist.github.com/YLChen-007/dafada36e356bc895b09829d8ec57e49
    =C2=A0 Cisco--Cisco NX-OS Software A vulnerability in the Border Gateway Pr= otocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nexus 3000 Series = Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode coul=
    d allow an unauthenticated, remote attacker to trigger BGP peer flaps, resu= lting in a denial of service (DoS) condition. This vulnerability is due to = incorrect parsing of a transitive BGP attribute. An attacker could exploit = this vulnerability by sending a crafted BGP update through an established B=
    GP peer session. If the update propagates to an affected device, it could c= ause the device to drop the BGP session and flap with the BGP peer that is = forwarding this update, resulting in a DoS condition. 2026-05-20 6.8 CVE-20= 26-20171 [ https://www.cve.org/CVERecord?id=3DCVE-2026-20171 ] cisco-sa-bgp= -iefab-3hb2pwtx [ https://sec.cloudapps.cisco.com/security/center/content/C= iscoSecurityAdvisory/cisco-sa-bgp-iefab-3hb2pwtx ]
    =C2=A0 Cisco--Cisco ThousandEyes Enterprise Agent A vulnerability in the Br= owserBot component of Cisco ThousandEyes Enterprise Agent could have allowe=
    d an authenticated, remote attacker to execute arbitrary commands on Agents=
    on behalf of the BrowserBot synthetics orchestration process. Cisco has ad= dressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and =
    no customer action is needed. This vulnerability was due to insufficient in= put validation of command arguments that are supplied by the user. Prior to=
    this vulnerability being addressed, an attacker could have exploited this = vulnerability by authenticating to the ThousandEyes SaaS and submitting cra= fted input into the affected parameter. A successful exploit could have all= owed the attacker to execute arbitrary commands within the BrowserBot conta= iner as the node user. To exploit this vulnerability, the attacker must hav=
    e valid user credentials for the ThousandEyes SaaS and the ability to manag=
    e transaction tests. 2026-05-20 6.3 CVE-2026-20206 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-20206 ] cisco-sa-tebbot-cmdinj-wN3yQ5gn [ https://sec= .cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa= -tebbot-cmdinj-wN3yQ5gn ]
    =C2=A0 Cisco--Cisco ThousandEyes Enterprise Agent A vulnerability in the SS=
    L certificate handling of Cisco ThousandEyes Virtual Appliance could allow =
    an authenticated, remote attacker to execute commands on the underlying ope= rating system as the root user. This vulnerability is due to insufficient v= alidation of user-supplied input. An authenticated attacker could exploit t= his vulnerability by uploading a crafted certificate to an affected device.=
    A successful exploit could allow the attacker to execute arbitrary code as=
    the root user on the underlying operating system. To exploit this vulnerab= ility, the attacker must have valid administrative credentials. 2026-05-20 = 4.7 CVE-2026-20199 [ https://www.cve.org/CVERecord?id=3DCVE-2026-20199 ] ci= sco-sa-tevacert-rce-RMJVEym5 [ https://sec.cloudapps.cisco.com/security/cen= ter/content/CiscoSecurityAdvisory/cisco-sa-tevacert-rce-RMJVEym5 ]
    =C2=A0 conoha--TypeSquare Webfonts for ConoHa The TypeSquare Webfonts for C= onoHa plugin for WordPress is vulnerable to authorization bypass in all ver= sions up to, and including, 2.0.4. This is due to the plugin not properly v= erifying that a user is authorized to perform an action. This makes it poss= ible for authenticated attackers, with subscriber-level access and above, t=
    o modify the plugin's site-wide font settings, including the typesquare_aut=
    h option (fontThemeUseType), show_post_form, and typesquare_fonttheme, by s= ubmitting a POST request to any wp-admin page. For fontThemeUseType values =
    1 and 3, no nonce verification is performed either, meaning those branches = are additionally exploitable via cross-site request forgery. 2026-05-20 4.3=
    CVE-2026-8610 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8610 ] https:/= /www.wordfence.com/threat-intel/vulnerabilities/id/88002a25-6890-4f8b-8a11-= 239b59d56672?source=3Dcve https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.= 4/typesquare-admin.php#L93 https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.= 4/inc/class/class.auth.php#L51 https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.= 4/typesquare-admin.php#L25
    =C2=A0 cryptpad--cryptpad CryptPad is an end-to-end encrypted collaborative=
    office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmar= ked.js can be bypassed due to incomplete attribute filtering on restricted = tags. The sanitizer validates only the src attribute of <iframe>, <video>, = and <audio> elements, leaving all other attributes unchecked. As a result, =
    an attacker can inject arbitrary HTML through srcdoc, completely defeating = CryptPad's intended bounce sandboxing and enabling link injection or other = interactive content within user-controlled documents. The root cause lies i=
    n how the sanitizer classifies and enforces tag restrictions: although it d= efines both forbidden and restricted tag lists, <iframe> is treated as "res= tricted" rather than "forbidden." Enforcement then inspects only the src at= tribute, so pairing a benign blob: src with a malicious srcdoc results in u= nrestricted rendering. This issue has been fixed in version 2026.2.0. 2026-= 05-20 6.1 CVE-2026-26028 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2602=
    8 ] https://github.com/cryptpad/cryptpad/security/advisories/GHSA-g2g4-47gv= -p72v
    https://github.com/cryptpad/cryptpad/releases/tag/2026.2.0
    =C2=A0 Ctrlpanel-gg--panel CtrlPanel is open-source billing software for ho= sting providers. In versions 1.1.1 and prior, the admin settings update end= point accepted a fully qualified class name directly from user-supplied req= uest input and used it for dynamic static method calls and object instantia= tion without any allowlist validation, allowing for authenticated Remote Co=
    de Execution. An authenticated admin-level user could supply an arbitrary c= lass name available in the Composer autoloader, potentially triggering unin= tended constructor or magic method execution. The update() method reads set= tings_class directly from the HTTP request and passed it to new $settings_c= lass() and $settings_class::getValidations() without verifying that the pro= vided value corresponds to a legitimate settings class: Because PHP resolve=
    s class names against the Composer autoloader at runtime, any autoloadable = class in the application or its dependencies could be instantiated. Dependi=
    ng on the classes available in the dependency tree, this can trigger uninte= nded side effects through constructors or magic methods (__construct, __toS= tring, __wakeup), following a PHP object injection / gadget chain pattern. = This issue has been fixed in version 1.2.0. 2026-05-19 6.6 CVE-2026-34216 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-34216 ] https://github.com/Ctr= lpanel-gg/panel/security/advisories/GHSA-vcg3-fjrx-rg5q https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0
    =C2=A0 Ctrlpanel-gg--panel CtrlPanel is open-source billing software for ho= sting providers. In versions 1.1.1 and prior, multiple admin controllers ex= pose DataTable endpoints without authorization checks, allowing any authent= icated user to access sensitive administrative data that should be restrict=
    ed to administrators only. The affected admin controllers define datatable(=
    ) methods that are reachable via GET requests but lack any permission or ro=
    le verification. Because the routes fall under the /admin/ prefix, operator=
    s may assume they are protected - however, the middleware applied to this r= oute group does not enforce admin-level authorization on these specific end= points. As a result, any authenticated user (regardless of role) can query = these endpoints and receive paginated JSON responses containing sensitive r= ecords. Exploitation can result in enumeration of user PII, payment and tra= nsaction records, active voucher and coupon codes, role and permission stru= cture, server ownership mappings and support ticket contents. This issue ha=
    s been fixed in version 1.2.0. 2026-05-19 6.5 CVE-2026-34233 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-34233 ] https://github.com/Ctrlpanel-gg/pan= el/security/advisories/GHSA-mj5g-j7fq-7hc4 https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0
    =C2=A0 Ctrlpanel-gg--panel CtrlPanel is open-source billing software for ho= sting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scrip= ting (XSS) vulnerability exists in the admin role management interface. In = app/Http/Controllers/Admin/RoleController.php, the datatable() method inter= polates $role->name and $role->color directly into a <span> element's HTML = and style attribute without sanitization, and the chained .rawColumns(['act= ions', 'name']) call instructs DataTables to render the name column as raw = HTML, bypassing automatic output escaping. An admin with role creation or e= dit permissions can inject a payload such as <img src=3Dx onerror=3D"alert(= 'XSS_POC')"> into the name or color fields, which is persisted to the datab= ase and executes in the browser of every admin who loads the /admin/roles p= age. This enables session hijacking via cookie theft, credential harvesting=
    through fake login prompts or keyloggers, lateral privilege escalation by = performing admin actions on behalf of victims, and a persistent backdoor th=
    at re-executes on every page load until the malicious role record is remove=
    d. This issue has been resolved in version 1.2.0. 2026-05-19 4.8 CVE-2026-3= 4246 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34246 ] https://github.c= om/Ctrlpanel-gg/panel/security/advisories/GHSA-wpqj-xwhq-2mmh https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0
    =C2=A0 cvmh--Sticky The Sticky plugin for WordPress is vulnerable to Stored=
    Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attrib= ute in versions up to and including 2.5.6. This is due to insufficient inpu=
    t sanitization and output escaping in the `cvmh_sticky_front_render()` func= tion - the `readmoretext` attribute value is passed through `apply_filters(=
    )` and directly concatenated into the HTML output without any escaping func= tion such as `esc_html()`. This makes it possible for authenticated attacke=
    rs with Contributor-level access and above to inject arbitrary web scripts =
    in pages that will execute whenever a user accesses a page containing the i= njected shortcode. 2026-05-20 6.4 CVE-2026-6397 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-6397 ] https://www.wordfence.com/threat-intel/vulnerabil= ities/id/135783c5-8175-4775-a013-f1e2bef04479?source=3Dcve https://plugins.trac.wordpress.org/browser/sticky/trunk/includes/functions.= php#L118 https://plugins.trac.wordpress.org/browser/sticky/tags/2.5.6/includes/funct= ions.php#L118 https://plugins.trac.wordpress.org/browser/sticky/trunk/includes/shortcode.= php#L7 https://plugins.trac.wordpress.org/browser/sticky/tags/2.5.6/includes/short= code.php#L7
    =C2=A0 dartiss--Draft List The Draft List plugin for WordPress is vulnerabl=
    e to Stored Cross-Site Scripting via Draft Post Title in all versions up to=
    , and including, 2.6.3 due to insufficient input sanitization and output es= caping. This makes it possible for authenticated attackers, with author-lev=
    el access and above, to inject arbitrary web scripts in pages that will exe= cute whenever a user accesses an injected page. The unescaped injection pat=
    h is triggered specifically when the viewing user lacks edit capabilities, = meaning payloads embedded in draft post titles via attribute-breakout techn= iques execute for unauthenticated users and subscribers. 2026-05-22 6.4 CVE= -2026-9104 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9104 ] https://www= .wordfence.com/threat-intel/vulnerabilities/id/07361278-7abb-4d22-a8df-218d= 3f982483?source=3Dcve https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.3/inc= /create-lists.php#L396 https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.3/inc= /create-lists.php#L305 https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.3/inc= /create-lists.php#L66 https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.4/inc= /create-lists.php#L389 https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.4/inc= /create-lists.php#L391 https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.4/inc= /create-lists.php#L394
    =C2=A0 Dell--ECS Dell ECS, versions 3.5 and 3.6, contain an Improper Access=
    Control in the Identity and Access Management (IAM) module. A remote unaut= henticated attacker may potentially exploit this vulnerability, leading to = gaining read access to unauthorized data. 2026-05-22 5.9 CVE-2022-31231 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2022-31231 ] https://dellservices.lig= htning.force.com/lightning/r/Lightning_Knowledge__kav/ka06P0000004RFTQA2/vi=
    ew
    =C2=A0 Dell--Live Optics Dell Live Optics Windows and Personal Edition coll= ectors contain an improper certificate validation vulnerability. A remote u= nauthenticated attacker could potentially exploit this vulnerability leadin=
    g to loss of confidentiality and integrity. 2026-05-18 6.8 CVE-2026-41119 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-41119 ] https://www.dell.com/s= upport/kbdoc/en-us/000464862/dsa-2026-221-security-update-for-dell-live-opt= ics-collector-ssl-vulnerability
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, versions=
    4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticat=
    ed attacker could potentially exploit this vulnerability, leading to a targ= eted application user being redirected to arbitrary web URLs. The vulnerabi= lity could be leveraged by attackers to conduct phishing attacks that cause=
    users to divulge sensitive information. 2026-05-22 6.1 CVE-2025-26483 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2025-26483 ] https://www.dell.com/supp= ort/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-r= ack-multiple-third-party-component-vulnerabilities https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, version(=
    s) <=3D4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A=
    low privileged attacker with local access could potentially exploit this v= ulnerability, leading to Elevation of privileges. 2026-05-22 5.3 CVE-2025-3= 2747 [ https://www.cve.org/CVERecord?id=3DCVE-2025-32747 ] https://www.dell= .com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-po= werflex-rack-multiple-third-party-component-vulnerabilities https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, version(=
    s) <=3D4.6.2, contain(s) an Exposure of Information Through Directory Listi=
    ng vulnerability. An unauthenticated attacker with remote access could pote= ntially exploit this vulnerability, leading to Information exposure. 2026-0= 5-22 5.3 CVE-2025-32749 [ https://www.cve.org/CVERecord?id=3DCVE-2025-32749=
    ] https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security= -update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilit= ies https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, version(=
    s) <=3D4.6.2, contain(s) an Insecure Storage of Sensitive Information vulne= rability. A low privileged attacker with local access could potentially exp= loit this vulnerability, leading to unauthorized access to sensitive inform= ation. 2026-05-22 5.5 CVE-2025-32751 [ https://www.cve.org/CVERecord?id=3DC= VE-2025-32751 ] https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025= -435-security-update-for-dell-powerflex-rack-multiple-third-party-component= -vulnerabilities https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, version(=
    s) <=3D4.6.2, contain(s) an Improper Certificate Validation vulnerability. =
    An unauthenticated attacker with adjacent network access could potentially = exploit this vulnerability, leading to Information tampering. 2026-05-22 4.=
    2 CVE-2025-32745 [ https://www.cve.org/CVERecord?id=3DCVE-2025-32745 ] http= s://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update= -for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, version(=
    s) <=3D4.6.2, contain(s) an Insecure Storage of Sensitive Information vulne= rability. An unauthenticated attacker with local access could potentially e= xploit this vulnerability, leading to unauthorized access to sensitive info= rmation. 2026-05-22 4 CVE-2025-32746 [ https://www.cve.org/CVERecord?id=3DC= VE-2025-32746 ] https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025= -435-security-update-for-dell-powerflex-rack-multiple-third-party-component= -vulnerabilities https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 Dell--SmartFabric Storage Software Dell SmartFabric Storage Software=
    , versions prior to 1.4.5, contains an Improper Neutralization of Special E= lements used in a Command ('Command Injection') vulnerability. A high privi= leged attacker with local access could potentially exploit this vulnerabili= ty, leading to Filesystem access for attacker. 2026-05-20 6.4 CVE-2026-3507=
    0 [ https://www.cve.org/CVERecord?id=3DCVE-2026-35070 ] https://www.dell.co= m/support/kbdoc/en-us/000466942/dsa-2026-235-security-update-for-dell-netwo= rking-smartfabric-storage-software-vulnerabilities
    =C2=A0 Dell--Unisphere for PowerMax Dell Unisphere for PowerMax vApp versio=
    n prior to 10.0.0.2, contains an authorization bypass vulnerability in the= =C2=A0 Unisphere for VMAX application running in=C2=A0vApp 2026-05-22 6.5 C= VE-2022-34363 [ https://www.cve.org/CVERecord?id=3DCVE-2022-34363 ] https:/= /dellservices.lightning.force.com/lightning/r/Lightning_Knowledge__kav/ka06= P000000xAiKQAU/view
    =C2=A0 Dell--VxRail Dell VxRail versions before 7.0.200 contain a Plain-tex=
    t Password Storage Vulnerability in VxRail Manager. A sys-admin user may ex= ploit this vulnerability, leading to the disclosure of certain user credent= ials. The attacker may be able to use the exposed credentials to access the=
    vulnerable application with privileges of the compromised account. 2026-05= -22 6.7 CVE-2021-21508 [ https://www.cve.org/CVERecord?id=3DCVE-2021-21508 =
    ] https://dellservices.lightning.force.com/lightning/r/Lightning_Knowledge_= _kav/ka0Do000000m7VwIAI/view
    =C2=A0 discourse--discourse Discourse is an open-source discussion platform=
    . In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, = outdated cached AI summaries can leak removed content to anonymous and unpr= ivileged users who cannot regenerate summaries. This issue has been fixed i=
    n versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1. To work arou=
    nd this issue, restrict summary generation by tightening the allowed groups=
    on the summarization Personas. 2026-05-19 5.3 CVE-2026-32244 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-32244 ] https://github.com/discourse/disco= urse/security/advisories/GHSA-hjmg-2mww-vfvx
    =C2=A0 DumbWareio--DumbAssets DumbAssets through 1.0.11 contains a stored c= ross-site scripting vulnerability in asset fields including name, descripti= on, modelNumber, serialNumber, and tags that are stored without server-side=
    sanitization and rendered using innerHTML without client-side escaping. At= tackers can create or update assets with HTML or JavaScript payloads via th=
    e asset API endpoints to execute arbitrary scripts in the browsers of users=
    viewing the asset list, and with Content-Security-Policy disabled, the inj= ected scripts can make unrestricted connections to internal network service=
    s. 2026-05-18 6.1 CVE-2026-45231 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-45231 ] https://github.com/DumbWareio/DumbAssets/pull/135 https://www.vulncheck.com/advisories/dumbassets-stored-cross-site-scripting= -via-asset-fields
    =C2=A0 eazyserver--Sentence To SEO (keywords, description and tags) The Sen= tence To SEO (keywords, description and tags) plugin for WordPress is vulne= rable to Cross-Site Request Forgery in all versions up to, and including, 1= .0. This is due to missing or incorrect nonce validation on the create_admi= n_page() function. This makes it possible for unauthenticated attackers to = inject malicious web scripts and update plugin settings via a forged reques=
    t granted they can trick a site administrator into performing an action suc=
    h as clicking on a link. 2026-05-20 6.1 CVE-2026-6391 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-6391 ] https://www.wordfence.com/threat-intel/vuln= erabilities/id/add32c06-90d0-466f-b176-aaae55cf03fb?source=3Dcve https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php#= L75 https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.p= hp#L75 https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php#= L81 https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.p= hp#L81 https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php#= L87 https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.p= hp#L87 https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php#= L50 https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.p= hp#L50
    =C2=A0 Edimax--BR-6228NC A vulnerability was detected in Edimax BR-6228NC 1= .22. Affected by this issue is the function mp of the file /goform/mp of th=
    e component POST Request Handler. The manipulation of the argument command = results in command injection. The attack may be performed from remote. The = exploit is now public and may be used. The vendor was contacted early about=
    this disclosure but did not respond in any way. 2026-05-18 6.3 CVE-2026-87=
    74 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8774 ] VDB-364399 | Edimax=
    BR-6228NC POST Request mp command injection [ https://vuldb.com/vuln/36439=
    9 ]
    VDB-364399 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 64399/cti ]
    Submit #811529 | EDIMAX BR6228NC BR-6228NCv2 (Version : v1.22) Command Inje= ction [ https://vuldb.com/submit/811529 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6228NC-mp-34b53a41781f80d= b8aaed24e43ea24b9?source=3Dcopy_link
    =C2=A0 Edimax--BR-6428NS A vulnerability was found in Edimax BR-6428NS 1.10=
    . This issue affects the function formStaDrvSetup of the file /goform/formS= taDrvSetup of the component POST Request Handler. Performing a manipulation=
    of the argument stadrv_ssid results in command injection. The attack can b=
    e initiated remotely. The exploit has been made public and could be used. T=
    he vendor was contacted early about this disclosure but did not respond in = any way. 2026-05-18 6.3 CVE-2026-8777 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-8777 ] VDB-364402 | Edimax BR-6428NS POST Request formStaDrvSetup = command injection [ https://vuldb.com/vuln/364402 ]
    VDB-364402 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 64402/cti ]
    Submit #811532 | EDIMAX BR-6428NS BR-6428NS_v4_1.10 Command Injection [ htt= ps://vuldb.com/submit/811532 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-formStaDrvSetup-3= 4b53a41781f80ca940cc467cd15dfc2?source=3Dcopy_link
    =C2=A0 Edimax--BR-6428NS A weakness has been identified in Edimax BR-6428NS=
    1.10. This impacts the function system of the file /goform/formWlanM of th=
    e component POST Request Handler. Executing a manipulation of the argument = ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2= /e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e= 2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power= 7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2= pTxPwDeltaG/e2pTxPwDeltaMix/e2pTxPwDeltaN/readE2P can lead to command injec= tion. The attack can be launched remotely. The exploit has been made availa= ble to the public and could be used for attacks. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-05-23 6.3 C= VE-2026-9296 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9296 ] VDB-36524=
    3 | Edimax BR-6428NS POST Request formWlanM system command injection [ http= s://vuldb.com/vuln/365243 ]
    VDB-365243 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65243/cti ]
    Submit #811535 | EDIMAX BR-6428NS BR-6428NS_v4_1.10 Command Injection [ htt= ps://vuldb.com/submit/811535 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-formWlanMP-34b53a= 41781f808fb207ce3f297db80b?source=3Dcopy_link
    =C2=A0 Edimax--BR-6428NS A security vulnerability has been detected in Edim=
    ax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform= /formWlbasic of the component POST Request Handler. The manipulation of the=
    argument repeaterSSID leads to command injection. The attack may be initia= ted remotely. The exploit has been disclosed publicly and may be used. The = vendor was contacted early about this disclosure but did not respond in any=
    way. 2026-05-23 6.3 CVE-2026-9297 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-9297 ] VDB-365244 | Edimax BR-6428NS POST Request formWlbasic command=
    injection [ https://vuldb.com/vuln/365244 ]
    VDB-365244 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65244/cti ]
    Submit #811536 | EDIMAX BR-6428NS BR-6428NS_v4_1.10 Command Injection [ htt= ps://vuldb.com/submit/811536 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-formWlbasic-34b53= a41781f807fb398dbab03bdbb38?source=3Dcopy_link
    =C2=A0 Edimax--BR-6675nD A security flaw has been discovered in Edimax BR-6= 675nD 1.12. This affects the function formHwSet of the file /goform/formHwS=
    et of the component POST Request Handler. The manipulation of the argument = regDomain/ABandregDomain/nic0Addr/nic1Addr/wlanAddr/inicAddr results in com= mand injection. It is possible to launch the attack remotely. The exploit h=
    as been released to the public and may be used for attacks. The vendor was = contacted early about this disclosure but did not respond in any way. 2026-= 05-24 6.3 CVE-2026-9378 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9378 =
    ] VDB-365341 | Edimax BR-6675nD POST Request formHwSet command injection [ = https://vuldb.com/vuln/365341 ]
    VDB-365341 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65341/cti ]
    Submit #811555 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811555 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formHwSet-34b53a4= 1781f8077b588f6e7cbbed36b?source=3Dcopy_link
    =C2=A0 Edimax--BR-6675nD A weakness has been identified in Edimax BR-6675nD=
    1.12. This impacts the function formWpsStart of the file /goform/formWpsSt= art of the component POST Request Handler. This manipulation of the argumen=
    t pinCode causes command injection. The attack can be initiated remotely. T=
    he exploit has been made available to the public and could be used for atta= cks. The vendor was contacted early about this disclosure but did not respo=
    nd in any way. 2026-05-24 6.3 CVE-2026-9379 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-9379 ] VDB-365342 | Edimax BR-6675nD POST Request formWpsSta=
    rt command injection [ https://vuldb.com/vuln/365342 ]
    VDB-365342 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65342/cti ]
    Submit #811556 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811556 ]
    Submit #811567 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection (Duplic= ate) [ https://vuldb.com/submit/811567 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formWpsStart-34b5= 3a41781f8011b77ac5ebb77dfddd?source=3Dcopy_link
    =C2=A0 Edimax--BR-6675nD A flaw has been found in Edimax BR-6675nD 1.12. Th=
    is issue affects the function formUSBStorage of the file /goform/formUSBSto= rage of the component POST Request Handler. Executing a manipulation of the=
    argument sub_dir can lead to command injection. It is possible to launch t=
    he attack remotely. The exploit has been published and may be used. The ven= dor was contacted early about this disclosure but did not respond in any wa=
    y. 2026-05-24 6.3 CVE-2026-9400 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-9400 ] VDB-365381 | Edimax BR-6675nD POST Request formUSBStorage command=
    injection [ https://vuldb.com/vuln/365381 ]
    VDB-365381 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65381/cti ]
    Submit #811562 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811562 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formUSBStorage-34= b53a41781f80809fc9e6ab3c51328b?source=3Dcopy_link
    =C2=A0 Edimax--BR-6675nD A vulnerability was found in Edimax BR-6675nD 1.12=
    . The affected element is the function formWlanMP of the file /goform/formW= lanMP of the component POST Request Handler. The manipulation of the argume=
    nt ateFunc/ateGain/ateRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2p= Tx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/e2pTxPower1/e= 2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/ateT= xFreqOffset/ateMode/ateMacID/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB= /e2pTxPwDeltaG/e2pTxPwDeltaMix/readE2P/e2pTxPwDeltaN results in command inj= ection. The attack can be launched remotely. The exploit has been made publ=
    ic and could be used. The vendor was contacted early about this disclosure = but did not respond in any way. 2026-05-24 6.3 CVE-2026-9402 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-9402 ] VDB-365383 | Edimax BR-6675nD POST R= equest formWlanMP command injection [ https://vuldb.com/vuln/365383 ] VDB-365383 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65383/cti ]
    Submit #811565 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811565 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formWlanMP-34b53a= 41781f8041aa2ecb4fa1927f59?source=3Dcopy_link
    =C2=A0 Edimax--EW-7438RPn A weakness has been identified in Edimax EW-7438R=
    Pn up to 1.31. The affected element is the function formWpsStart of the fil=
    e /goform/formWpsStart of the component webs. This manipulation of the argu= ment pinCode causes os command injection. Remote exploitation of the attack=
    is possible. The exploit has been made available to the public and could b=
    e used for attacks. The vendor was contacted early about this disclosure bu=
    t did not respond in any way. 2026-05-23 6.3 CVE-2026-9343 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-9343 ] VDB-365306 | Edimax EW-7438RPn webs fo= rmWpsStart os command injection [ https://vuldb.com/vuln/365306 ]
    VDB-365306 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65306/cti ]
    Submit #813884 | Edimax EW-7438RPn 1.31 Command Injection [ https://vuldb.c= om/submit/813884 ]
    Submit #811551 | EDIMAX EW-7438RPn Mini EW-7438RPn Mini Firmware 1.28a (Ver= sion : 1.28a) Command Injection (Duplicate) [ https://vuldb.com/submit/8115=
    51 ]
    https://github.com/wudipjq/my_vuln/blob/main/Edimax/vuln_1/1.md
    =C2=A0 Edimax--EW-7438RPn A vulnerability has been found in Edimax EW-7438R=
    Pn up to 1.31. Affected is the function formWizSurvey of the file /goform/f= ormWizSurvey of the component webs. The manipulation of the argument ip/mas= k/gateway leads to os command injection. It is possible to initiate the att= ack remotely. The exploit has been disclosed to the public and may be used.=
    The vendor was contacted early about this disclosure but did not respond i=
    n any way. 2026-05-24 6.3 CVE-2026-9347 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-9347 ] VDB-365310 | Edimax EW-7438RPn webs formWizSurvey os com= mand injection [ https://vuldb.com/vuln/365310 ]
    VDB-365310 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65310/cti ]
    Submit #813889 | Edimax EW-7438RPn 1.31 Command Injection [ https://vuldb.c= om/submit/813889 ]
    Submit #811543 | EDIMAX EW-7438RPn Mini EW-7438RPn Mini Firmware 1.28a (Ver= sion : 1.28a) Command Injection (Duplicate) [ https://vuldb.com/submit/8115=
    43 ]
    https://github.com/wudipjq/my_vuln/blob/main/Edimax/vuln_5/5.md
    =C2=A0 Edimax--EW-7438RPn A vulnerability was identified in Edimax EW-7438R=
    Pn 1.28a. Affected by this vulnerability is the function formHwSet of the f= ile /goform/formHwSet of the component POST Request Handler. The manipulati=
    on of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr= /wlanSSID/wlanChan/comd/initgain/txcck/txofdm leads to command injection. T=
    he attack can be initiated remotely. The exploit is publicly available and = might be used. The vendor was contacted early about this disclosure but did=
    not respond in any way. 2026-05-24 6.3 CVE-2026-9359 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-9359 ] VDB-365322 | Edimax EW-7438RPn POST Request=
    formHwSet command injection [ https://vuldb.com/vuln/365322 ]
    VDB-365322 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65322/cti ]
    Submit #811540 | EDIMAX EW-7438RPn Mini EW-7438RPn Mini Firmware 1.28a (Ver= sion : 1.28a) Command Injection [ https://vuldb.com/submit/811540 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-EW-7438RPn-Mini-formHwSet-3= 4b53a41781f80b98d10f0da699f2236?source=3Dcopy_link
    =C2=A0 Edimax--EW-7438RPn A weakness has been identified in Edimax EW-7438R=
    Pn 1.12. This affects the function formAccept of the file /goform/formAccep=
    of the component POST Request Handler. This manipulation of the argument s= ubmit-url causes command injection. The attack may be initiated remotely. T=
    he exploit has been made available to the public and could be used for atta= cks. The vendor was contacted early about this disclosure but did not respo=
    nd in any way. 2026-05-24 6.3 CVE-2026-9361 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-9361 ] VDB-365324 | Edimax EW-7438RPn POST Request formAccep=
    formAccept command injection [ https://vuldb.com/vuln/365324 ]
    VDB-365324 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65324/cti ]
    Submit #811552 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811552 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formAccept-34b53a= 41781f807fb8f3d96c5e5ef215?source=3Dcopy_link
    =C2=A0 Edimax--EW-7438RPn A security vulnerability has been detected in Edi= max EW-7438RPn 1.12. This vulnerability affects the function formConnection= Setting of the file /goform/formConnectionSetting of the component Setting = Handler. Such manipulation of the argument max_Conn/timeOut leads to comman=
    d injection. The attack may be launched remotely. The exploit has been disc= losed publicly and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-05-24 6.3 CVE-2026-9362 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-9362 ] VDB-365325 | Edimax EW-743= 8RPn Setting formConnectionSetting command injection [ https://vuldb.com/vu= ln/365325 ]
    VDB-365325 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65325/cti ]
    Submit #811553 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811553 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formConnectionSet= ting-34b53a41781f807a9c88e746d24540cd?source=3Dcopy_link
    =C2=A0 Edimax--EW-7438RPn A vulnerability was detected in Edimax EW-7438RPn=
    1.12. This issue affects the function formEZCHNwlanSetup of the file /gofo= rm/formEZCHNwlanSetu of the component POST Request Handler. Performing a ma= nipulation of the argument method results in command injection. Remote expl= oitation of the attack is possible. The exploit is now public and may be us= ed. The vendor was contacted early about this disclosure but did not respon=
    d in any way. 2026-05-24 6.3 CVE-2026-9363 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-9363 ] VDB-365326 | Edimax EW-7438RPn POST Request formEZCHNw= lanSetu formEZCHNwlanSetup command injection [ https://vuldb.com/vuln/36532=
    6 ]
    VDB-365326 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65326/cti ]
    Submit #811554 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection [ https= ://vuldb.com/submit/811554 ] https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formEZCHNwlanSetu= p-34b53a41781f803a8c60ca409394df5b?source=3Dcopy_link
    =C2=A0 edmonparker--Read More & Accordion The Read More & Accordion plugin = for WordPress is vulnerable to time-based blind SQL Injection via the 'orde= rby' parameter in all versions up to, and including, 3.5.7. This is due to = the use of esc_sql() without surrounding the value in quotes in an ORDER BY=
    clause inside the getAllDataByLimit() and getAccordionAllDataByLimit() fun= ctions in ReadMoreData.php. The user-supplied $_GET['orderby'] value is onl=
    y processed through esc_attr() (an HTML-escaping function) before being pas= sed to these database functions, where esc_sql() is applied but the value i=
    s directly concatenated-unquoted-into the ORDER BY fragment of the SQL quer=
    y before $wpdb->prepare() is called. Because esc_sql() only escapes quote c= haracters and backslashes (which are irrelevant in an unquoted ORDER BY con= text), an attacker can inject arbitrary SQL expressions such as (SELECT SLE= EP(5)) or conditional subqueries to perform time-based blind data extractio=
    n. This makes it possible for authenticated attackers with administrator-le= vel access or above (or any role explicitly permitted access to the plugin'=
    s admin pages via the yrm-user-roles setting) to extract sensitive data fro=
    m the database, including administrator credential hashes. 2026-05-20 4.9 C= VE-2026-7472 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7472 ] https://w= ww.wordfence.com/threat-intel/vulnerabilities/id/cc7c7e21-fbd7-4451-bc7d-3d= 11db01a443?source=3Dcve https://plugins.trac.wordpress.org/browser/expand-maker/trunk/classes/ReadM= oreData.php#L1522 https://plugins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/classes/= ReadMoreData.php#L1522 https://plugins.trac.wordpress.org/browser/expand-maker/trunk/views/readMor= ePagesView.php#L29 https://plugins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/views/re= adMorePagesView.php#L29 https://plugins.trac.wordpress.org/browser/expand-maker/trunk/classes/ReadM= oreData.php#L1537 https://plugins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/classes/= ReadMoreData.php#L1537 https://plugins.trac.wordpress.org/browser/expand-maker/trunk/views/accordi= onBuilder/list.php#L29 https://plugins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/views/ac= cordionBuilder/list.php#L29
    =C2=A0 espocrm--espocrm EspoCRM is an open source customer relationship man= agement application. Versions 9.3.3 and below allow authenticated users to = upload SVG attachments through normal attachment-capable fields and later s= erve those SVG files as top-level inline documents through both the attachm= ent and image entry points, resulting in stored cross-user XSS reachable th= rough a normal attachment workflow. Although inline SVG script is blocked b=
    y the response CSP, the same CSP still allows same-origin external script. =
    As a result, an attacker can upload a malicious SVG together with a second = attacker-controlled JavaScript attachment, then trick another user into ope= ning the SVG to execute JavaScript in the victim's EspoCRM origin. This iss=
    ue has been fixed in version 9.3.4. 2026-05-19 6.8 CVE-2026-33741 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-33741 ] https://github.com/espocrm/esp= ocrm/security/advisories/GHSA-5wh5-ccv2-m3pv
    =C2=A0 Esri--ArcGIS Server ArcGIS Server contains an improper authenticatio=
    n vulnerability in an undocumented administrative endpoint. An unauthentica= ted attacker could exploit this issue by sending a crafted request to the e= ndpoint. Successful exploitation may result in disruption of the web-based = browsing interface. This issue affects ArcGIS Server 12.0 and earlier. 2026= -05-20 5.3 CVE-2026-2812 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2812=
    ] https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/ap= ril2026_security_bulletin
    =C2=A0 Esri--ArcGIS Server ArcGIS Server contains an input validation weakn= ess in the login redirection workflow. An Authenticated attacker could expl= oit this issue by sending a specially crafted request, Successful exploitat= ion may result in the application redirecting the browser to an unintended,=
    untrusted site, resulting in a limited confidentiality impact under specif=
    ic user interaction conditions. The vulnerability affects only the client s= ide navigation logic during authentication and remains confined to the same=
    security boundary. No server side compromise or cross component impact is = possible.=C2=A0=C2=A0This issue affects ArcGIS Server 11.5. 2026-05-20 4.7 = CVE-2026-2813 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2813 ] https://= www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_sec= urity_bulletin
    =C2=A0 etspring--LJ comments import: reloaded The LJ comments import: reloa= ded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi=
    a PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to in= sufficient input sanitization and output escaping. This makes it possible f=
    or unauthenticated attackers to inject arbitrary web scripts in pages that = execute if they can successfully trick a user into performing an action suc=
    h as clicking on a link. The vulnerability arises specifically because PHP_= SELF includes attacker-controllable PATH_INFO appended to the script name, = and there are two distinct unsanitized echo points for this value in the sa=
    me function. 2026-05-20 6.1 CVE-2026-8624 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-8624 ] https://www.wordfence.com/threat-intel/vulnerabilities/= id/0f09cb59-dbbb-48a3-aeac-377f6ec87b88?source=3Dcve https://plugins.trac.wordpress.org/browser/lj-comments-import-reloaded/trun= k/lj_comments_import.php#L129 https://plugins.trac.wordpress.org/browser/lj-comments-import-reloaded/trun= k/lj_comments_import.php#L161
    =C2=A0 goback2--Logo Manager For Enamad The Logo Manager For Enamad plugin = for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' = attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_cust= om` shortcodes in all versions up to, and including, 0.7.4 due to insuffici= ent input sanitization and output escaping on user supplied attributes. Thi=
    s makes it possible for authenticated attackers, with contributor-level acc= ess and above, to inject arbitrary web scripts in pages that will execute w= henever a user accesses an injected page. 2026-05-20 6.4 CVE-2026-6549 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-6549 ] https://www.wordfence.com/= threat-intel/vulnerabilities/id/ed6d1167-c89d-4c97-9446-b968df945e6c?source= =3Dcve
    https://wordpress.org/plugins/logo-manager-for-enamad https://plugins.trac.wordpress.org/browser/logo-manager-for-enamad/tags/0.7= .4/widgets.php#L295 https://plugins.trac.wordpress.org/browser/logo-manager-for-enamad/trunk/wi= dgets.php#L295
    =C2=A0 HCL--BigFix Service Management (SM) HCL BigFix Service Management (S=
    M) is susceptible to a Configuration - 'Insecure Use of Base Image Version'=
    . Using outdated or insecure base images may introduce known vulnerabilitie=
    s, potentially increasing the risk of exploitation in the application envir= onment. 2026-05-20 4 CVE-2025-31973 [ https://www.cve.org/CVERecord?id=3DCV= E-2025-31973 ] https://support.hcl-software.com/csm?id=3Dkb_article&sysparm= _article=3DKB0128144
    =C2=A0 HCLSoftware--Connections HCL Connections contains a broken access co= ntrol vulnerability that may allow unauthorized user to update data in cert= ain scenarios. 2026-05-18 4.6 CVE-2026-21789 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-21789 ] https://support.hcl-software.com/csm?id=3Dkb_articl= e&sysparm_article=3DKB0129719
    =C2=A0 HCLSoftware--DominoIQ The HCL DominoIQ RAG feature is=C2=A0affected = by=C2=A0a Broken Access Control vulnerability. =C2=A0Under certain circumst= ances, document level access restrictions will be ignored when determining = what data to return from an AI query. =C2=A0This could enable an authentica= ted attacker to view sensitive data. 2026-05-20 6.5 CVE-2026-21836 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-21836 ] https://support.hcl-software.= com/csm?id=3Dkb_article&sysparm_article=3DKB0130932
    =C2=A0 heartcombo--devise Devise is an authentication solution for Rails ba= sed on Warden. In versions 5.0.3 and below, when the Timeoutable module is = enabled in Devise, the FailureApp#redirect_url method returns request.refer= rer - the HTTP Referer header, which is attacker-controllable - without val= idation for any non-GET request that results in a session timeout. An attac= ker who hosts a page with an auto-submitting cross-origin form can cause a = victim with an expired Devise session to be redirected to an arbitrary exte= rnal URL. This contrasts with the GET timeout path (which uses server-side = attempted_path) and Devise's own store_location_for mechanism (which strips=
    external hosts via extract_path_from_location), both of which are protecte=
    d; only the non-GET timeout redirect path is unprotected. Expired-session u= sers can be silently redirected from the trusted app domain to attacker-con= trolled URLs, enabling phishing and malware delivery while bypassing browse=
    r warnings. Note: Rails' built-in open-redirect protection does not mitigat=
    e this issue. Devise::FailureApp is an ActionController::Metal app with its=
    own isolated copy of the relevant redirect configuration, so config.action= _controller.action_on_open_redirect =3D :raise (and the older raise_on_open= _redirects setting) do not reach it. This issue has been fixed in version 5= .0.4. 2026-05-22 6.1 CVE-2026-40295 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-40295 ] https://github.com/heartcombo/devise/security/advisories/GHS= A-jp94-3292-c3xv https://github.com/heartcombo/devise/commit/025fe2124f9928766fc46520e999633= b598d0360
    =C2=A0 helgatheviking--KIA Subtitle The KIA Subtitle plugin for WordPress i=
    s vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle`=
    shortcode `before` and `after` attributes in all versions up to, and inclu= ding, 4.0.1. This is due to insufficient input sanitization and output esca= ping on user supplied attributes. This makes it possible for authenticated = attackers, with Contributor-level access and above, to inject arbitrary web=
    scripts in pages that will execute whenever a user accesses an injected pa= ge. 2026-05-22 6.4 CVE-2026-7509 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-7509 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/a9a520= 97-0d85-4036-9b74-f35fea549607?source=3Dcve https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subt= itle.php#L359 https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subt= itle.php#L329 https://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.= php#L359 https://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.= php#L329 https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subt= itle.php#L369 https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subt= itle.php#L370
    =C2=A0 helpstring--Child Height Predictor by Ostheimer The Child Height Pre= dictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Reques=
    t Forgery in all versions up to and including 1.3. This is due to missing n= once verification in the options() function, which handles plugin settings = updates. The form template does not include a wp_nonce_field() call, and th=
    e handler never calls check_admin_referer() or wp_verify_nonce(). This make=
    s it possible for unauthenticated attackers to trick a site administrator i= nto clicking a link or visiting a malicious page that submits a forged POST=
    request, causing unauthorized changes to the plugin settings such as unit = preferences to be persisted to the database via update_option(). 2026-05-20=
    4.3 CVE-2026-6400 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6400 ] htt= ps://www.wordfence.com/threat-intel/vulnerabilities/id/dc1681a8-5f2e-45f1-9= 6d9-797b13644607?source=3Dcve https://plugins.trac.wordpress.org/browser/child-height-predictor/trunk/chi= ldheight.php#L149 https://plugins.trac.wordpress.org/browser/child-height-predictor/tags/1.3/= childheight.php#L149 https://plugins.trac.wordpress.org/browser/child-height-predictor/trunk/chi= ldheight.php#L135 https://plugins.trac.wordpress.org/browser/child-height-predictor/tags/1.3/= childheight.php#L135
    =C2=A0 Honeywell International Inc.--Control Network Module (CNM) Honeywell=
    Control Network Module (CNM)=C2=A0contains insertion of sensitive informat= ion into an unintended directory. An attacker could exploit this vulnerabil= ity through probing system files, potentially resulting in unintended acces=
    s to protected data. 2026-05-21 5.9 CVE-2026-5434 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-5434 ] https://process.honeywell.com/
    =C2=A0 infility--Infility Global The Infility Global plugin for WordPress i=
    s vulnerable to SQL Injection via the 'orderby' and 'order' parameters in a=
    ll versions up to, and including, 2.15.16. This is due to insufficient esca= ping on user supplied parameters and lack of sufficient preparation on the = existing SQL query within the show_control_data::post_list() function, whic=
    h is registered as an admin menu page with only the 'read' capability. This=
    makes it possible for authenticated attackers, with Subscriber-level acces=
    s and above, to append additional SQL queries into already existing queries=
    that can be used to extract sensitive information from the database. 2026-= 05-20 6.5 CVE-2026-8685 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8685 =
    ] https://www.wordfence.com/threat-intel/vulnerabilities/id/1caeb5e0-9e4e-4= c9e-a6e4-881fb81dc5f2?source=3Dcve https://plugins.trac.wordpress.org/browser/infility-global/trunk/widgets/sh= ow-control-data/show-control-data.php#L34 https://plugins.trac.wordpress.org/browser/infility-global/trunk/widgets/sh= ow-control-data/show-control-data.php#L74 https://plugins.trac.wordpress.org/browser/infility-global/trunk/widgets/sh= ow-control-data/show-control-data.php#L78 https://plugins.trac.wordpress.org/browser/infility-global/trunk/widgets/sh= ow-control-data/show-control-data.php#L84
    =C2=A0 Intelbras -- VIP-1230-D-G4 An issue in Intelbras VIP-1230-D-G4 Versi=
    on V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive informat= ion via password reset functionality under /OutsideCmd 2026-05-18 5.3 CVE-2= 026-36438 [ https://www.cve.org/CVERecord?id=3DCVE-2026-36438 ] https://bac= kend.intelbras.com/sites/default/files/2023-03/Datasheet%20UNIFICADO%20-%20= VIP%201230%20B.D.G4-v2.pdf https://www.intelbras.com/pt-br/camera-dome-wi-fi-vip-1230-d-w-g4 https://github.com/kensh1k/CVE-2026-36438/tree/main
    =C2=A0 ISC--BIND 9 BIND resolvers are vulnerable to an amplified resource c= onsumption/exhaustion attack. If a victim resolver makes a query to a speci= ally crafted zone, the resolver will consume disproportionate resources. Th=
    is issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.1= 8.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.1= 6.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1. 2= 026-05-20 5.3 CVE-2026-3592 [ https://www.cve.org/CVERecord?id=3DCVE-2026-3= 592 ] CVE-2026-3592 [ https://kb.isc.org/docs/cve-2026-3592 ] https://downloads.isc.org/isc/bind9/9.18.49 https://downloads.isc.org/isc/bind9/9.20.23 https://downloads.isc.org/isc/bind9/9.21.22
    =C2=A0 ISC--BIND 9 An unbounded resend loop vulnerability exists in the BIN=
    D 9 resolver state machine during bad-server handling, enabling a remote un= authenticated attacker to cause severe resource exhaustion by sending queri=
    es that trigger specific retry conditions. This issue affects BIND 9 versio=
    ns 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21,=
    9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1. 2026-05-2=
    0 5.3 CVE-2026-5950 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5950 ] CV= E-2026-5950 [ https://kb.isc.org/docs/cve-2026-5950 ] https://downloads.isc.org/isc/bind9/9.18.49 https://downloads.isc.org/isc/bind9/9.20.23 https://downloads.isc.org/isc/bind9/9.21.22
    =C2=A0 ItzCrazyKns--Vane A security vulnerability has been detected in ItzC= razyKns Vane up to 1.12.1. Affected by this issue is some unknown functiona= lity of the file route.ts of the component API. The manipulation leads to m= issing authentication. The attack may be initiated remotely. The attack's c= omplexity is rated as high. The exploitation is known to be difficult. The = exploit has been disclosed publicly and may be used. It appears that basic = authentication is planned. 2026-05-24 5.6 CVE-2026-9371 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-9371 ] VDB-365334 | ItzCrazyKns Vane API route.t=
    s missing authentication [ https://vuldb.com/vuln/365334 ]
    VDB-365334 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365334= /cti ]
    Submit #813209 | ItzCrazyKns Vane 1.12.1 API Key Exposure [ https://vuldb.c= om/submit/813209 ]
    Submit #813210 | ItzCrazyKns Vane 1.12.1 Missing Authentication for Critica=
    l Function (Duplicate) [ https://vuldb.com/submit/813210 ] https://github.com/ItzCrazyKns/Vane/issues/1122 https://github.com/ItzCrazyKns/Vane/issues/1123 https://github.com/ItzCrazyKns/Vane/
    =C2=A0 jarrodwatts--claude-hud Claude HUD through 0.0.12, patched in commit=
    234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cw=
    d and branchUrl values without stripping control characters or encoding emb= edded values, allowing attackers to inject arbitrary ANSI codes into termin=
    al sessions. Attackers can embed ESC+backslash sequences in the current wor= king directory or branch URL to execute malicious ANSI codes including text=
    color changes, forged prompts, and OSC 52 clipboard writes, or trigger out= bound HTTP requests to attacker-controlled remotes when hyperlinks are clic= ked. 2026-05-18 4.6 CVE-2026-47090 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-47090 ] https://github.com/jarrodwatts/claude-hud/issues/485 https://github.com/jarrodwatts/claude-hud/pull/487 https://github.com/jarrodwatts/claude-hud/commit/234d9aad919b51326a43bcf90b= 45ae35c23afc30 https://www.vulncheck.com/advisories/claude-hud-terminal-injection-via-osc-= 8-hyperlinks
    =C2=A0 javibola--JaviBola Custom Theme Test The JaviBola Custom Theme Test = plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver= sions up to, and including, 2.0.5. This is due to missing or incorrect nonc=
    e validation on the options page. This makes it possible for unauthenticate=
    d attackers to change the site's active theme by modifying the jbct_theme o= ption via a forged request granted they can trick a site administrator into=
    performing an action such as clicking on a link. 2026-05-20 4.3 CVE-2026-8= 423 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8423 ] https://www.wordfe= nce.com/threat-intel/vulnerabilities/id/68a8a277-2ea6-4d75-b8cd-4d20eb17b3a= a?source=3Dcve https://plugins.trac.wordpress.org/browser/javibola-custom-theme/trunk/javi= bola-custom-theme.php#L41 https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5= /javibola-custom-theme.php#L41 https://plugins.trac.wordpress.org/browser/javibola-custom-theme/trunk/javi= bola-custom-theme.php#L40 https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5= /javibola-custom-theme.php#L40 https://plugins.trac.wordpress.org/browser/javibola-custom-theme/trunk/javi= bola-custom-theme.php#L54 https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5= /javibola-custom-theme.php#L54
    =C2=A0 jay_patel--Remove Yellow BGBOX The Remove Yellow BGBOX plugin for Wo= rdPress is vulnerable to Cross-Site Request Forgery in all versions up to, = and including, 1.0. This is due to missing or incorrect nonce validation on=
    the 'rybb_api_settings' page. This makes it possible for unauthenticated a= ttackers to reset the plugin's stored settings by overwriting its configura= tion via a forged request granted they can trick a site administrator into = performing an action such as clicking on a link. 2026-05-20 4.3 CVE-2026-84=
    24 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8424 ] https://www.wordfen= ce.com/threat-intel/vulnerabilities/id/c5b30d27-a3f8-4535-a47f-675c939ec648= ?source=3Dcve https://plugins.trac.wordpress.org/browser/remove-yellow-bgbox/trunk/admin/= rybb_api_settings.php#L5 https://plugins.trac.wordpress.org/browser/remove-yellow-bgbox/tags/1.0/adm= in/rybb_api_settings.php#L5 https://plugins.trac.wordpress.org/browser/remove-yellow-bgbox/trunk/includ= es/functions.php#L16 https://plugins.trac.wordpress.org/browser/remove-yellow-bgbox/tags/1.0/inc= ludes/functions.php#L16
    =C2=A0 jetmonsters--MotoPress Hotel Booking The MotoPress Hotel Booking plu= gin for WordPress is vulnerable to authorization bypass in all versions up = to, and including, 6.0.1. This is due to the plugin not properly verifying = that a user is authorized to perform an action. This makes it possible for = unauthenticated attackers to overwrite or delete the internal notes (_mphb_= booking_internal_notes) of any booking by supplying an arbitrary booking ID=
    . The nonce for this action is output in the HTML source of every public pa=
    ge through wp_localize_script (MPHB._data.nonces), so any unauthenticated v= isitor can obtain a valid nonce and perform the action without any account =
    or prior interaction. 2026-05-22 5.3 CVE-2026-8684 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-8684 ] https://www.wordfence.com/threat-intel/vulnera= bilities/id/6567e63c-3129-47b2-a734-733eb599821a?source=3Dcve https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/6.0.1/includes/ajax-api/ajax-actions/update-booking-notes.php#L83 https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/6.0.1/includes/ajax-api/ajax-actions/abstract-ajax-api-action.php#L34 https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/6.0.1/includes/ajax-api/ajax-api-handler.php#L43 https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/5.4.1/includes/ajax-api/ajax-actions/update-booking-notes.php#L83 https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/5.4.1/includes/ajax-api/ajax-actions/abstract-ajax-api-action.php#L34 https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/5.4.1/includes/ajax-api/ajax-api-handler.php#L43 https://plugins.trac.wordpress.org/changeset/3537354/motopress-hotel-bookin= g-lite/trunk/includes/ajax-api/ajax-actions/update-booking-notes.php
    =C2=A0 Jomres--Jomres Joomla Component jomres 9.11.2 contains a cross-site = request forgery vulnerability that allows attackers to modify user account = information by tricking authenticated users into visiting malicious pages. = Attackers can craft HTML forms targeting the account/index endpoint with hi= dden fields to change passwords, email addresses, and profile details witho=
    ut user consent. 2026-05-23 4.3 CVE-2018-25354 [ https://www.cve.org/CVERec= ord?id=3DCVE-2018-25354 ] ExploitDB-44901 [ https://www.exploit-db.com/expl= oits/44901 ]
    Official Product Homepage [ https://www.jomres.net/ ]
    Product Reference [ https://extensions.joomla.org/extension/jomres/ ]
    VulnCheck Advisory: Joomla Component jomres 9.11.2 Cross-Site Request Forge=
    ry [ https://www.vulncheck.com/advisories/joomla-component-jomres-cross-sit= e-request-forgery ]
    =C2=A0 jupyterhub--jupyterhub JupyterHub is software that allows users to c= reate a multi-user server for Jupyter notebooks. In versions 4.1.0 through = 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests = with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks=
    . The JSON API is not affected, only HTTP form endpoints, such as /hub/spaw=
    n and /hub/accept-share, meaning attackers could trigger server spawn (but = not access the server) and if the attacker is a JupyterHub user permitted t=
    o share access to their server, cause a user to accept a share and have acc= ess to the attacker's server. This issue has been fixed in version 5.4.5. I=
    f developers are unable to immediately upgrade, they can temporarily mitiga=
    te this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-co=
    rs if they are using a reverse proxy. 2026-05-22 5.4 CVE-2026-40864 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-40864 ] https://github.com/jupyterhu= b/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9 https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117= efa77bd941127
    =C2=A0 kasparsd--Widget Context The Widget Context plugin for WordPress is = vulnerable to Cross-Site Request Forgery in all versions up to, and includi= ng, 1.3.3. This is due to missing or incorrect nonce validation on the save= _widget_context_settings function. This makes it possible for unauthenticat=
    ed attackers to modify widget visibility context settings stored in the Wor= dPress options table via a forged POST request to /wp-admin/widgets.php via=
    a forged request granted they can trick a site administrator into performi=
    ng an action such as clicking on a link. 2026-05-22 4.3 CVE-2026-7615 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-7615 ] https://www.wordfence.com/t= hreat-intel/vulnerabilities/id/3c434637-4bf9-46ee-9a6d-35eab7ef11a1?source= =3Dcve https://plugins.trac.wordpress.org/browser/widget-context/trunk/src/WidgetC= ontext.php#L311 https://plugins.trac.wordpress.org/browser/widget-context/tags/1.3.3/src/Wi= dgetContext.php#L311 https://plugins.trac.wordpress.org/browser/widget-context/trunk/src/WidgetC= ontext.php#L282 https://plugins.trac.wordpress.org/browser/widget-context/tags/1.3.3/src/Wi= dgetContext.php#L282 https://plugins.trac.wordpress.org/browser/widget-context/trunk/src/WidgetC= ontext.php#L91 https://plugins.trac.wordpress.org/browser/widget-context/tags/1.3.3/src/Wi= dgetContext.php#L91
    https://github.com/kasparsd/widget-context-wporg/pull/73
    =C2=A0 Kieback & Peter--DDC4002 The affected=C2=A0Kieback & Peter DDC build= ing controllers=C2=A0are vulnerable to cross-site scripting, enabling JavaS= cript to be executed by the victim's browser, which allows the attacker to = control the browser. 2026-05-20 5.3 CVE-2026-4293 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-4293 ] https://www.cisa.gov/news-events/ics-advisories= /icsa-26-139-05 https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-= 26-139-05.json
    =C2=A0 ktulhu--Bigfishgames Syndicate The Bigfishgames Syndicate plugin for=
    WordPress is vulnerable to Cross-Site Request Forgery in all versions up t=
    o, and including, 1.2. This is due to missing or incorrect nonce validation=
    on the bigfishgames_syndicate_submenu() function. This makes it possible f=
    or unauthenticated attackers to reset plugin settings and update them via a=
    forged request granted they can trick a site administrator into performing=
    an action such as clicking on a link. 2026-05-20 4.3 CVE-2026-6452 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-6452 ] https://www.wordfence.com/thr= eat-intel/vulnerabilities/id/67877a2e-a45d-4674-b749-05d9217ef6bf?source=3D= cve https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/trunk/big= fishgames-syndicate.php#L238 https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/tags/1.2/= bigfishgames-syndicate.php#L238 https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/trunk/big= fishgames-syndicate.php#L169 https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/tags/1.2/= bigfishgames-syndicate.php#L169
    =C2=A0 langgenius--dify Dify version 1.14.1 and prior contain an authorizat= ion bypass vulnerability in the file preview endpoint that allows any authe= nticated user to read up to 3,000 characters of any uploaded document acros=
    s all tenants and workspaces using only the file's UUID. Attackers can acce=
    ss the /console/api/files/{file_id}/preview endpoint with an intercepted fi=
    le UUID to extract sensitive content from documents without ownership or wo= rkspace permission verification. NOTE: Dify Cloud allows unauthenticated fr=
    ee self-registration, making account creation trivially accessible to any a= ttacker. 2026-05-18 5.9 CVE-2026-41949 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-41949 ] https://huntr.com/bounties/d50a0240-7951-4939-b989-9bde= d66c7682
    https://github.com/langgenius/dify/pull/35797 https://www.vulncheck.com/advisories/dify-authorization-bypass-via-file-pre= view-endpoint
    =C2=A0 laurent22--joplin Joplin is an open source note-taking and to-do app= lication that organises notes and lists into notebooks. Versions 3.6.14 and=
    prior contain a Denial of Service (DoS) vulnerability in the title input f= unctionality due to a lack of proper length validation. This flaw allows an=
    attacker to cause an Out Of Memory (OOM) error and subsequent program term= ination by inserting an excessively long string into a note's title. This c=
    an be triggered either through direct user interface (UI) input or programm= atically via the local web service API after compromising an authentication=
    token. There are 2 primary methods of exploitation: via User Interface (UI=
    ) Input, and the Local Web Service API. A local user can directly type or p= aste an extremely long string into the title field when creating or editing=
    a note Joplin runs a local web service (typically on port 41184) that allo=
    ws programmatic interaction, such as creating or editing notes via HTTP API=
    calls. If an attacker manages to exfiltrate or compromise the user's authe= ntication token (e.g., through malware on the local system, or other local = vulnerabilities), they can then send a crafted HTTP POST request to this lo= cal API. By including an excessively long string in the title parameter of = this request, the application will attempt to allocate an unbounded amount =
    of memory. This issue has been patched in version 3.7.1. 2026-05-19 5.5 CVE= -2025-57798 [ https://www.cve.org/CVERecord?id=3DCVE-2025-57798 ] https://g= ithub.com/laurent22/joplin/security/advisories/GHSA-6jm8-gr87-q69x https://github.com/laurent22/joplin/commit/5b8795da446a5a40c9e212c98b35e368= ffce628e
    =C2=A0 laurent22--joplin Joplin is an open source note-taking and to-do app= lication that organises notes and lists into notebooks. Versions 3.5.2 and = prior contain a logic error in the delta API that allows share recipients t=
    o download notes that are no longer shared with them, related to but not fu= lly fixed by the prior patch in #14289. In ChangeModel.delta, when DELTA_IN= CLUDES_ITEMS is enabled (the default), the latest state of items is attache=
    d to delta output without verifying that those items are still shared with = the requesting user, and the existing removal logic only filters items dele= ted for all users. Additionally, the change compression logic incorrectly r= educes create - delete to NOOP, which is unsafe because compression is appl= ied per page and an item can have multiple create events; if an earlier cre= ate falls on a separate page from a later create -> delete pair, the deleti=
    on is dropped and the sequence collapses to a create. As a result, the delt=
    a API returns a create event for a deleted item with the full latest conten=
    t attached, exposing notes the user no longer has access to. This issue has=
    been fixed in version 3.5.3. 2026-05-19 5.7 CVE-2026-34600 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-34600 ] https://github.com/laurent22/joplin/= security/advisories/GHSA-88x4-77rc-jw94 https://github.com/laurent22/joplin/issues/14110 https://github.com/laurent22/joplin/pull/14289
    =C2=A0 Ledger--Ledger Bitcoin app Ledger Bitcoin app versions 2.1.0 and 2.1=
    .1 contain an address derivation vulnerability that allows attackers to cau=
    se incorrect Bitcoin addresses to be displayed by exploiting improper handl= ing of miniscript policies containing the a: fragment. Attackers can craft = malicious miniscript policies that cause the device to derive and display i= ncorrect receiving addresses, potentially leading to funds being sent to un= intended addresses. 2026-05-20 4 CVE-2023-7346 [ https://www.cve.org/CVERec= ord?id=3DCVE-2023-7346 ] Ledger Security Bulletin 019 [ https://donjon.ledg= er.com/lsb/019/ ] https://www.vulncheck.com/advisories/ledger-bitcoin-app-address-derivation-= error-via-miniscript
    =C2=A0 Ledger--Ledger Nano X Ledger Nano X, Flex, and Stax devices contain =
    a denial of service vulnerability in the MCU firmware update process due to=
    missing validation of the reset_handler parameter during firmware flashing=
    . An attacker can provide a crafted reset_handler address pointing to inval=
    id memory or attacker-controlled code to cause the device to enter an unrec= overable fault state during boot, resulting in permanent loss of operabilit=
    y. 2026-05-19 4.6 CVE-2025-15645 [ https://www.cve.org/CVERecord?id=3DCVE-2= 025-15645 ] Ledger Security Bulletin 021 [ https://donjon.ledger.com/lsb/02=
    1/ ] https://www.vulncheck.com/advisories/ledger-nano-x-flex-stax-mcu-firmware-u= pdate-denial-of-service
    =C2=A0 Ledger--ledgerhq/hw-app-eth Ledger Live with vulnerable versions of = ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerabili=
    ty that allows attackers to manipulate EIP-712 typed data messages by explo= iting incorrect hexadecimal field parsing when values contain an odd number=
    of characters. Attackers can obtain signatures on truncated or misinterpre= ted message values to authorize unintended blockchain transactions, such as=
    asset transfers at incorrect amounts. 2026-05-19 6.5 CVE-2023-7345 [ https= ://www.cve.org/CVERecord?id=3DCVE-2023-7345 ] Ledger Security Bulletin 020 =
    [ https://donjon.ledger.com/lsb/020/ ] https://www.vulncheck.com/advisories/ledger-live-hw-app-eth-eip-712-message= -parsing-integer-truncation
    =C2=A0 linlinjava--litemall A security vulnerability has been detected in l= inlinjava litemall up to 1.8.0. Affected by this vulnerability is the funct= ion backup/load of the file litemall-db/src/main/java/org/linlinjava/litema= ll/db/util/DbUtil.java of the component Database Setting Handler. The manip= ulation of the argument db/password leads to argument injection. The attack=
    is possible to be carried out remotely. The exploit has been disclosed pub= licly and may be used. The vendor was contacted early about this disclosure=
    but did not respond in any way. 2026-05-18 4.7 CVE-2026-8773 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-8773 ] VDB-364398 | linlinjava litemall Da= tabase Setting DbUtil.java load argument injection [ https://vuldb.com/vuln= /364398 ]
    VDB-364398 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 64398/cti ]
    Submit #811469 | linlinjava litemall up to 1.8.0 Argument Injection [ https= ://vuldb.com/submit/811469 ] https://gist.github.com/A1AAAAAAAAAA1/d5ae30a17744459e7cc5902fff32a35b
    =C2=A0 Live Networks, Inc.--LIVE555 LIVE555 before 2026.04.22 contains an a= uthorization bypass vulnerability in RTSP session command handling that all= ows attackers to replay valid Session tokens from unauthenticated connectio= ns. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN = commands from a second TCP connection without authentication, causing serve=
    r crashes through virtual function call errors or disrupting active streams=
    by terminating victim sessions. 2026-05-19 5.9 CVE-2026-41470 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-41470 ] https://gist.github.com/yhcho0405= /ee9b67a96808ef19f22e8a4ee88c795f
    https://download.live555.com/ https://www.vulncheck.com/advisories/live555-rtsp-server-authorization-bypa= ss-via-session-token
    =C2=A0 lykich--Correct Prices The Correct Prices plugin for WordPress is vu= lnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var= iable in versions up to and including 1.0. This is due to the correct_price= s_page() function echoing $_SERVER['PHP_SELF'] into a form's action attribu=
    te without any input sanitization or output escaping (such as esc_url() or = esc_attr()). Because PHP_SELF reflects attacker-controlled path-info append=
    ed to the script URL, an attacker can break out of the attribute and inject=
    arbitrary markup. This makes it possible for unauthenticated attackers to = inject arbitrary web scripts in pages that execute if they can successfully=
    trick a user into performing an action such as clicking on a specially cra= fted link. 2026-05-20 6.1 CVE-2026-8627 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8627 ] https://www.wordfence.com/threat-intel/vulnerabilities/i= d/605c6c53-6920-42ba-8784-b3a186bbf821?source=3Dcve https://plugins.trac.wordpress.org/browser/correct-prices/trunk/correct_pri= ces.php#L134
    =C2=A0 Magepeople inc.--WpBookingly Missing Authorization vulnerability in = Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access=
    Control Security Levels. This issue affects WpBookingly: from n/a through = 1.2.9. 2026-05-20 6.5 CVE-2026-27405 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-27405 ] https://patchstack.com/database/wordpress/plugin/service-bo= oking-manager/vulnerability/wordpress-wpbookingly-plugin-1-2-9-broken-acces= s-control-vulnerability?_s_id=3Dcve
    =C2=A0 makeplane--plane Plane is an open-source project management tool. In=
    versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled=
    segment query parameter directly to a Django F() expression without valida= tion (unlike the regular AnalyticsEndpoint, which checks against an allowli= st), causing ORM Field Reference Injection. An authenticated workspace MEMB=
    ER can send GET /api/workspaces/<slug>/saved-analytic-view/<analytic_id>/ w= ith a crafted segment value that is forwarded into build_graph_plot() and t= raverses foreign-key relationships (e.g. workspace__owner__password) before=
    being projected via .values("dimension", "segment"), returning the referen= ced field values directly in the JSON response. This exposes sensitive data=
    such as bcrypt password hashes, API tokens, and related users' email addre= sses, making it a stronger primitive than the related order_by injection wh= ere values are only leaked through ordering. This issue has been fixed in v= ersion 1.3.1. 2026-05-20 6.5 CVE-2026-40102 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-40102 ] https://github.com/makeplane/plane/security/advisori= es/GHSA-93x3-ghh7-72j3
    https://github.com/makeplane/plane/releases/tag/v1.3.1
    =C2=A0 manchumahara--CBX 5 Star Rating & Review The CBX 5 Star Rating & Rev= iew plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi=
    a the 'page' parameter in all versions up to, and including, 1.0.7 due to i= nsufficient input sanitization and output escaping. This makes it possible = for unauthenticated attackers to inject arbitrary web scripts in pages that=
    execute if they can successfully trick an administrator into performing an=
    action such as clicking on a link. 2026-05-22 6.1 CVE-2026-6864 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-6864 ] https://www.wordfence.com/threat= -intel/vulnerabilities/id/9ee11e19-21a6-45df-a118-f6dec3b55bc1?source=3Dcve https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.7/tem= plates/admin/admin-rating-review-rating-avg-logs.php#L41 https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.7/tem= plates/admin/admin-rating-review-review-logs.php#L41 https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.8/tem= plates/admin/admin-rating-review-review-logs.php https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.8/tem= plates/admin/admin-rating-review-rating-avg-logs.php
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and below contain flawed logic that causes im= proper escaping of a textarea custom field's contents in the Update Issue p= age, (bug_update_page.php) allowing an attacker to inject HTML and, if CSP = settings permit, execute arbitrary JavaScript when the page is loaded. This=
    facilitates session theft, leading to admin account takeover, full project=
    data access. In order to exploit this issue, a textarea-type custom field = must be configured for the project, the attack must be carried out by an au= thenticated user with bug report permission (low privilege). This can affec=
    t any user viewing the bug edit form, including administrators. The issue h=
    as been fixed in version 2.28.2. If users cannot immediately upgrade, they = can work around the issue by using the default Content-Security Policy, whi=
    ch blocks script execution. 2026-05-20 5.4 CVE-2026-39960 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-39960 ] https://github.com/mantisbt/mantisbt/s= ecurity/advisories/GHSA-qj6w-v29q-4rgx https://github.com/mantisbt/mantisbt/commit/5fec0f448b7a7d7d539a6adb6dcccea= c4e4e4ab7
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and prior allow an authenticated user to uplo=
    ad attachments to private Issues they are not authorized to access. This is= sue has been fixed in version 2.28.2. 2026-05-19 4.3 CVE-2026-34754 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-34754 ] https://github.com/mantisbt/= mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e5= 2a6275206
    https://mantisbt.org/bugs/view.php?id=3D36976
    =C2=A0 Mattermost--Mattermost Mattermost Mobile Apps versions <=3D2.37 11.4=
    2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO a= uthentication callback origin which allows an attacker controlling a malici= ous Mattermost server to steal user credentials for a legitimate Mattermost=
    server via relaying the SSO code exchange flow through the mobile applicat= ion. Mattermost Advisory ID: MMSA-2025-00564 2026-05-21 6.1 CVE-2026-22880 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-22880 ] MMSA-2025-00564 [ htt= ps://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost Plugins versions <=3D11.5 11.1.5 1= 0.13.11 11.3.4.0 fail to properly check for permissions when processing com= mands in the Gitlab plugin which allows normal users to uninstall instances=
    or setup webhook connections via the {{gitlab instance {option}}} or the {= {/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-006=
    00 2026-05-18 6.5 CVE-2026-3117 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-3117 ] MMSA-2026-00600 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost Desktop App versions <=3D6.1 6.0.1=
    5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in=
    the Mattermost Desktop App which allows a malicious server owner to repeat=
    ed crash the application via calling {{window.open('javascript:alert()');}}=
    . Mattermost Advisory ID: MMSA-2026-00618 2026-05-18 6.5 CVE-2026-3471 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-3471 ] MMSA-2026-00618 [ https://= mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to archive th=
    e channel before removing persistent notifications which allows authenticat=
    ed user to crash the server via timing the creation of persistent notificat= ion message between the server deleting existing persistent notifications a=
    nd archiving the channel.. Mattermost Advisory ID: MMSA-2026-00637 2026-05-=
    22 6.5 CVE-2026-4635 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4635 ] M= MSA-2026-00637 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1 fail t=
    o verify channel membership when processing AI-assisted message rewrites wh= ich allows an authenticated attacker to read the content of threads in priv= ate channels and direct messages they do not have access to via a crafted r= equest to the post rewrite endpoint.. Mattermost Advisory ID: MMSA-2026-006=
    45 2026-05-18 6.5 CVE-2026-5163 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-5163 ] MMSA-2026-00645 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.2, 11.5.x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.1=
    4 fail to validate the TIFF IFD offset in the image header before allocatin=
    g memory, which allows authenticated users with file upload or posting perm= issions to cause a denial of service (server OOM) via uploading a crafted T= IFF file or posting a URL that serves one.. Mattermost Advisory ID: MMSA-20= 26-00648 2026-05-22 6.5 CVE-2026-5755 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-5755 ] MMSA-2026-00648 [ https://mattermost.com/security-updates ] =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 fail prevent disclosure of created use=
    r password which allows a malicious attacker to impersonate a user via the = use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614 20= 26-05-18 6.5 CVE-2026-6345 [ https://www.cve.org/CVERecord?id=3DCVE-2026-63=
    45 ] MMSA-2026-00614 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to validate t=
    he OAuth token scope on the callback which allows an authenticated Mattermo=
    st user to gain access to private repositories via modifying the scope para= meter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-0= 0628 2026-05-22 5.4 CVE-2026-28735 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-28735 ] MMSA-2026-00628 [ https://mattermost.com/security-updates ] =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to validate f= ile ownership and access control, which allows an authenticated user to acc= ess and download files belonging to other users or teams via crafted Boards=
    API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-0062=
    0 2026-05-22 5.9 CVE-2026-3473 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-3473 ] MMSA-2026-00620 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 fail to limit the size of the request = body on the start meeting API endpoint, which allows an authenticated attac= ker to cause resource exhaustion or denial of service via a crafted oversiz=
    ed HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA= -2026-00608 2026-05-18 4.3 CVE-2026-2325 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-2325 ] MMSA-2026-00608 [ https://mattermost.com/security-update=
    s ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 Fail to enforce slash command trigger-= word uniqueness during command updates which allows an authenticated team m= ember with Manage Own Slash Commands permission to hijack and impersonate e= xisting system or custom slash commands via editing their own slash command=
    trigger to an already-registered trigger through the command update API. M= attermost Advisory ID: MMSA-2026-00597 2026-05-18 4.3 CVE-2026-28732 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-28732 ] MMSA-2026-00597 [ https://m= attermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 fail to validate that a remote cluster=
    has access to a channel before processing membership removal requests duri=
    ng shared channel membership sync, which allows a malicious remote cluster =
    to remove any user from any channel, including private channels, via crafte=
    d membership sync messages targeting channels the remote cluster is not aut= horized to access. Mattermost Advisory ID: MMSA-2026-00576 2026-05-18 4.3 C= VE-2026-28759 [ https://www.cve.org/CVERecord?id=3DCVE-2026-28759 ] MMSA-20= 26-00576 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to sanitize t= eam member data when returned via API to users without elevated permissions=
    which allows a user without permissions to get data about team members rol=
    es via invoking various team API endpoints.. Mattermost Advisory ID: MMSA-2= 026-00626 2026-05-22 4.3 CVE-2026-3636 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-3636 ] MMSA-2026-00626 [ https://mattermost.com/security-update=
    s ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 fail to check the create_post channel = permission during post edit operations which allows an authenticated attack=
    er with revoked posting privileges to modify their existing posts via direc=
    t API requests to the post update and patch endpoints.. Mattermost Advisory=
    ID: MMSA-2026-00627 2026-05-18 4.3 CVE-2026-3637 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-3637 ] MMSA-2026-00627 [ https://mattermost.com/securi= ty-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1 fail t=
    o validate team-level run_create permission against the target team when cr= eating a playbook run which allows an authenticated team member to create r= uns in teams where they lack permission via specifying a different team ID =
    in the run creation API request. Mattermost Advisory ID: MMSA-2026-00629 20= 26-05-21 4.3 CVE-2026-4055 [ https://www.cve.org/CVERecord?id=3DCVE-2026-40=
    55 ] MMSA-2026-00629 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to validate u= ser-supplied input in API request handlers which allows an authenticated at= tacker to crash the plugin process via a crafted HTTP request to the PR det= ails endpoint.. Mattermost Advisory ID: MMSA-2026-00638 2026-05-22 4.3 CVE-= 2026-4646 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4646 ] MMSA-2026-00= 638 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.6.x <=3D 11.6.0, 11.5.=
    x <=3D 11.5.3, 11.4.x <=3D 11.4.4, 10.11.x <=3D 10.11.14 fail to enforce re= quest body size limits on plugin HTTP endpoints which allows an attacker to=
    cause a denial of service via crafted oversized HTTP requests.. Mattermost=
    Advisory ID: MMSA-2026-00646 2026-05-22 4.9 CVE-2026-5308 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-5308 ] MMSA-2026-00646 [ https://mattermost.c= om/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 11.4.=
    x <=3D 11.4.3 fail to validate the X-Requested-With header on the burn-on-r= ead reveal endpoint which allows an authenticated channel member to force t=
    he reveal of a burn-on-read message without recipient consent via a crafted=
    Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636 2026-05-18 4.=
    3 CVE-2026-6339 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6339 ] MMSA-2= 026-00636 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 fail to validate 7zip archive structur=
    e before processing which allows an authenticated attacker to cause server = memory exhaustion and denial of service via uploading a specially crafted 7= zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-= 2026-00573 2026-05-18 4.3 CVE-2026-6340 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-6340 ] MMSA-2026-00573 [ https://mattermost.com/security-update=
    s ]
    =C2=A0 Mattermost--Mattermost Mattermost Plugins versions <=3D11.5 11.1.5 1= 0.13.11 11.3.4.0 fail to have API-level checks on which groups the user can=
    create issues or attach comments to which allows a user that is member of = multiple groups to create issues to a locked group via direct API requests.=
    Mattermost Advisory ID: MMSA-2026-00602 2026-05-18 4.3 CVE-2026-6341 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-6341 ] MMSA-2026-00602 [ https://m= attermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost Plugins versions <=3D11.5 11.1.5 1= 0.13.11 11.3.4.0 fail to appropriately check for valid namespaces which all= ows plugin users to create subscriptions to groups that were not whiteliste=
    d via creating groups that share the same prefix as a whitelisted group. Ma= ttermost Advisory ID: MMSA-2026-00601 2026-05-18 4.3 CVE-2026-6342 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-6342 ] MMSA-2026-00601 [ https://matt= ermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13, 11.4.x <=3D 11.4.3 fail to check public/private permissio=
    ns which allows members without these permissions to access public playbook=
    s via /get.. Mattermost Advisory ID: MMSA-2026-00591 2026-05-18 4.3 CVE-202= 6-6343 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6343 ] MMSA-2026-00591=
    [ https://mattermost.com/security-updates ]
    =C2=A0 mcinvale--Faces of Users The Faces of Users plugin for WordPress is = vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attri= bute in the 'facesofusers' shortcode in all versions up to, and including, = 0.0.3 due to insufficient input sanitization and output escaping. This make=
    s it possible for authenticated attackers, with Contributor-level access an=
    d above, to inject arbitrary web scripts in pages that will execute wheneve=
    r a user accesses an injected page. 2026-05-20 6.4 CVE-2026-8038 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-8038 ] https://www.wordfence.com/threat= -intel/vulnerabilities/id/ea39d249-0345-4028-af58-31b298376950?source=3Dcve https://plugins.trac.wordpress.org/browser/faces-of-users/trunk/faces-of.ph= p#L62 https://plugins.trac.wordpress.org/browser/faces-of-users/tags/0.0.3/faces-= of.php#L62
    =C2=A0 Mesalvo--Meona Client Launcher Component Cleartext Storage of Sensit= ive Information in Memory vulnerability in Mesalvo Meona Client Launcher Co= mponent, Mesalvo Meona Server Component. This issue affects Meona Client La= uncher Component: through 19.06.2020 15:11:49; Meona Server Component: thro= ugh 2025.04 5+323020. 2026-05-20 6 CVE-2026-0857 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-0857 ] https://seccore.at/blog/cves-meona/
    =C2=A0 Mesalvo--Meona Client Launcher Component Insufficient Verification o=
    f Data Authenticity vulnerability in Mesalvo Meona Client Launcher Componen=
    t, Mesalvo Meona Server Component makes it possible to send messages to any=
    email address.=C2=A0This issue affects Meona Client Launcher Component: th= rough 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020=
    . 2026-05-20 4.4 CVE-2026-25602 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-25602 ] https://seccore.at/blog/cves-meona/
    =C2=A0 Microsoft--Microsoft 365 Copilot Improper neutralization of special = elements used in a command ('command injection') in M365 Copilot allows an = unauthorized attacker to disclose information over a network. 2026-05-22 6.=
    5 CVE-2026-42827 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42827 ] M365=
    Copilot Information Disclosure Vulnerability [ https://msrc.microsoft.com/= update-guide/vulnerability/CVE-2026-42827 ]
    =C2=A0 Microsoft--Microsoft Defender Antimalware Platform Microsoft Defende=
    r Denial of Service Vulnerability 2026-05-20 4 CVE-2026-45498 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-45498 ] Microsoft Defender Denial of Servi=
    ce Vulnerability [ https://msrc.microsoft.com/update-guide/vulnerability/CV= E-2026-45498 ]
    =C2=A0 Microsoft--Microsoft Edge (Chromium-based) Improper input validation=
    in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypa=
    ss a security feature over a network. 2026-05-18 5.4 CVE-2026-45492 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-45492 ] Microsoft Edge (Chromium-bas= ed) Security Feature Bypass Vulnerability [ https://msrc.microsoft.com/upda= te-guide/vulnerability/CVE-2026-45492 ]
    =C2=A0 Microsoft--Microsoft Edge (Chromium-based) Microsoft Edge (Chromium-= based) Spoofing Vulnerability 2026-05-18 5.4 CVE-2026-45494 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-45494 ] Microsoft Edge (Chromium-based) Spoo= fing Vulnerability [ https://msrc.microsoft.com/update-guide/vulnerability/= CVE-2026-45494 ]
    =C2=A0 Microsoft--Windows 11 Version 24H2 Microsoft is aware of a security = feature bypass vulnerability in Windows publicly referred to as &quot;Yello= wKey&quot;. The proof of concept for this vulnerability has been made publi=
    c violating coordinated vulnerability best practices. We are issuing this C=
    VE to provide mitigation guidance that can be implemented to protect agains=
    t this vulnerability until the security update is made available. Mitigatio=
    n FAQs Should I leverage the temporary mitigation? Microsoft recommends tha=
    t you consider implementing these mitigations if you are concerned your dev= ices and data are at risk of being compromised or stolen. For example, if y= our organization's employees take their work devices home or on business tr= avel. What impact to service availability/management could be caused by imp= lementing the mitigations? Implementing these mitigations will not impact s= ervice availability or management operations. Do customers need to revert t=
    he changes made to mitigate the vulnerability once the security update to p= rotect against this vulnerability is available? No. The security update wil=
    l maintain the mitigation's behavior once the security update is installed.=
    I am using TPM+PIN, am I at risk of this vulnerability being exploited No,=
    if you are using TPM+PIN the vulnerability is not exploitable. 2026-05-19 = 6.8 CVE-2026-45585 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45585 ] Wi= ndows BitLocker Security Feature Bypass Vulnerability [ https://msrc.micros= oft.com/update-guide/vulnerability/CVE-2026-45585 ]
    =C2=A0 MongoDB, Inc.--C Driver The MongoDB C Driver's legacy GridFS API acc= epts malformed file metadata from the database without adequate validation.=
    Crafted documents in a GridFS collection may cause any application that re= ads those files via the legacy API to either crash (via a division-by-zero)=
    or silently leak process memory contents (via an out-of-bounds read). 2026= -05-20 5.9 CVE-2026-9100 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9100=
    ] https://jira.mongodb.org/browse/CDRIVER-6281
    =C2=A0 MongoDB, Inc.--Compass Prototype pollution in csv parsing logic duri=
    ng import can lead to untrusted file paths (but not arguments) entering she= ll.openExternal after specific user behavior leading to "1-click" command e= xecution. 2026-05-20 4.3 CVE-2026-9101 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-9101 ] https://jira.mongodb.org/browse/COMPASS-10657
    =C2=A0 MongoDB, Inc.--MongoDB Server Creating a "2dsphere_bucket" index on =
    a non-timeseries bucket collection will succeed, but any subsequent attempt=
    to insert a document which triggers updating that index will crash the ser= ver. A similar issue occurs when creating "queryable_encrypted_range" indic= es. This issue affects MongoDB Server v7.0 versions prior to 7.0.32, v8.0 v= ersions prior to 8.0.21 and v8.2 versions prior to 8.2.6 2026-05-18 6.5 CVE= -2026-8843 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8843 ] https://jir= a.mongodb.org/browse/SERVER-116327
    =C2=A0 mrdollar4444--GSheet For Woo Importer The GSheet For Woo Importer pl= ugin for WordPress is vulnerable to unauthorized loss of data due to a miss= ing capability check on the process_ajax_restore_action() function in all v= ersions up to, and including, 2.3.1. This makes it possible for authenticat=
    ed attackers, with Subscriber-level access and above, to delete the plugin'=
    s Google Sheets API token and configuration options. 2026-05-21 4.3 CVE-202= 6-4843 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4843 ] https://www.wor= dfence.com/threat-intel/vulnerabilities/id/b0d60991-0675-4efa-9427-380e6b59= fe28?source=3Dcve https://plugins.trac.wordpress.org/browser/import-products-from-gsheet-for-= woo-importer/tags/2.3.1/src/Actions/AdminSettingsAction.php#L391
    =C2=A0 n/a--Ettercap A vulnerability has been found in Ettercap up to 0.8.3=
    . The affected element is the function FUNC_DECODER of the file src/dissect= ors/ec_gg.c of the component GG Dissector. The manipulation of the argument=
    gg leads to heap-based buffer overflow. The attack is possible to be carri=
    ed out remotely. The complexity of an attack is rather high. The exploitabi= lity is described as difficult. The exploit has been disclosed to the publi=
    c and may be used. Upgrading to version 0.8.4 is sufficient to fix this iss= ue. The identifier of the patch is feeae6fa366e01a3dd9f1857ec6aae847b2ae00c=
    . It is suggested to upgrade the affected component. 2026-05-24 5.6 CVE-202= 6-9365 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9365 ] VDB-365328 | Et= tercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow [ https://vuld= b.com/vuln/365328 ]
    VDB-365328 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365328= /cti ]
    Submit #813142 | Ettercap <=3Dv0.8.4 Heap-based Buffer Overflow [ https://v= uldb.com/submit/813142 ]
    https://github.com/Ettercap/ettercap/issues/1306 https://github.com/Ettercap/ettercap/pull/1307 https://github.com/Ettercap/ettercap/commit/feeae6fa366e01a3dd9f1857ec6aae8= 47b2ae00c
    https://github.com/Ettercap/ettercap/
    =C2=A0 n/a--exifreader Versions of the package exifreader before 4.39.0 are=
    vulnerable to Improper Handling of Highly Compressed Data (Data Amplificat= ion) due to decompressing PNG zTXt metadata without enforcing a built-in ma= ximum decompressed output size. When asynchronous parsing is enabled, a cra= fted PNG file containing a highly compressed zTXt chunk can cause ExifReade=
    r to materialize a disproportionately large Comment value in memory. 2026-0= 5-19 5.3 CVE-2026-8814 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8814 ]=
    https://security.snyk.io/vuln/SNYK-JS-EXIFREADER-16689340 https://gist.github.com/yuki-matsuhashi/cad1a45d936062438b4ab24613c34c55 https://github.com/mattiasw/ExifReader/commit/5f116128adc19f674902f8bf582bf= e7dd0a36375
    =C2=A0 n/a--JPress A vulnerability was determined in JPress up to 1.0.3. Th=
    e affected element is an unknown function of the file /ucenter/article/doWr= iteSave of the component UCenter Article Submission Endpoint. Executing a m= anipulation of the argument id/userId can lead to improper authorization. T=
    he attack may be performed from remote. The exploit has been publicly discl= osed and may be utilized. The project was informed of the problem early thr= ough an issue report but has not responded yet. 2026-05-24 6.3 CVE-2026-937=
    6 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9376 ] VDB-365339 | JPress = UCenter Article Submission Endpoint doWriteSave improper authorization [ ht= tps://vuldb.com/vuln/365339 ]
    VDB-365339 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65339/cti ]
    Submit #813253 | JPress 1.0.3 Improper Authorization [ https://vuldb.com/su= bmit/813253 ]
    https://github.com/JPressProjects/jpress/issues/194
    =C2=A0 n/a--postcss A vulnerability was determined in postcss up to 7.1.1. = Affected is the function toString of the file src/selectors/container.js of=
    the component AST Serialization. Executing a manipulation can lead to unco= ntrolled recursion. It is possible to launch the attack remotely. The explo=
    it has been publicly disclosed and may be utilized. The vendor explains, th=
    at according to his definition "DoS on server-side on user-generated CSS is=
    low risk for us (since most users compile own CSS with PostCSS)." 2026-05-=
    24 4.3 CVE-2026-9358 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9358 ] V= DB-365321 | postcss AST Serialization container.js toString recursion [ htt= ps://vuldb.com/vuln/365321 ]
    VDB-365321 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65321/cti ]
    Submit #813080 | postcss-selector-parser postcss <=3D 7.1.1 CWE-674: Uncont= rolled Recursion [ https://vuldb.com/submit/813080 ] https://gist.github.com/bx33661/581e3a38134601c04e19b4dfc9b459b9
    =C2=A0 nanomq--nanomq NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Mes= saging Platform. In versions 0.24.10 and below, when NanoMQ handles high-co= ncurrency reconnect traffic using a reconnect-collision payload, the broker=
    can crash due to a NULL pointer dereference during MQTT session resumption=
    for clean_start=3D0 clients. The transport's p_peer callback (tcptran_pipe= _peer()) iterates cpipe->subinfol while copying session metadata from the c= ached old pipe to the new reconnecting pipe, without checking whether the p= ointer is NULL. Under a reconnect race, cpipe->subinfol can be freed and se=
    t to NULL before session restore invokes this function, resulting in a remo=
    te unauthenticated Denial-of-Service (process crash) condition. This issue = has been fixed in version 0.24.11. 2026-05-19 5.9 CVE-2026-32134 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-32134 ] https://github.com/nanomq/nanom= q/security/advisories/GHSA-q36f-83mh-pcv2 https://github.com/nanomq/nanomq/issues/2241 https://github.com/nanomq/NanoNNG/commit/522ec62e29e60d1122f2aedaa6e702dcf0= 89f7bb
    https://github.com/nanomq/nanomq/releases/tag/0.24.11
    =C2=A0 NeoRazorX--facturascripts FacturaScripts is an open source accountin=
    g and invoicing software. In versions prior to 2026, the Library module sto= res and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IP=
    TC metadata. Any authenticated user who downloaded an image could extract t=
    he uploader's embedded metadata, which included GPS coordinates, device inf= ormation, timestamps, embedded comments/notes, thumbnail previews, and othe=
    r personally identifiable information (PII) preserved in the image metadata=
    . Of all FacturaScripts' image upload features, only the Library module com= bined unrestricted uploads, persistent storage, authenticated download acce= ss, and a total lack of server-side metadata sanitization. This vulnerabili=
    ty carries significant real-world impact: an employee uploading a photo tak=
    en at their home inadvertently discloses their precise home address to ever=
    y user with Library download access. This issue has been fixed in version 2= 026. 2026-05-18 6.5 CVE-2026-27892 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-27892 ] https://github.com/NeoRazorX/facturascripts/security/advisori= es/GHSA-q7f2-rv22-2xgr https://github.com/NeoRazorX/facturascripts/commit/b0725147a61a9a377b718058= 9af33ff52b4751e2
    =C2=A0 Netatalk--Netatalk Netatalk 2.0.0 through 4.4.2 generates AFP sessio=
    n tokens derived from predictable process IDs, which allows a remote authen= ticated attacker to cause a denial of service by exploiting the reconnect m= echanism. 2026-05-21 6.5 CVE-2026-44054 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-44054 ] Netatalk Security Advisory CVE-2026-44054 [ https://net= atalk.io/security/CVE-2026-44054 ]
    =C2=A0 Netatalk--Netatalk A stack-based buffer overflow in desktop.c in Net= atalk 1.3 through 4.2.2 allows a remote authenticated attacker to cause a d= enial of service, obtain limited information, or modify limited data. 2026-= 05-21 6 CVE-2026-44056 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44056 =
    ] Netatalk Security Advisory CVE-2026-44056 [ https://netatalk.io/security/= CVE-2026-44056 ]
    =C2=A0 Netatalk--Netatalk An authentication bypass vulnerability in Netatal=
    k 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an=
    arbitrary user via the admin auth user mechanism. 2026-05-21 6.4 CVE-2026-= 44058 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44058 ] Netatalk Securi=
    ty Advisory CVE-2026-44058 [ https://netatalk.io/security/CVE-2026-44058 ] =C2=A0 Netatalk--Netatalk Insufficient sanitization of volume paths in Neta= talk 3.1.0 through 4.4.2 allows a local privileged user to inject OS comman=
    ds and execute arbitrary code via a crafted volume path. 2026-05-21 6.7 CVE= -2026-44076 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44076 ] Netatalk = Security Advisory CVE-2026-44076 [ https://netatalk.io/security/CVE-2026-44= 076 ]
    =C2=A0 Netatalk--Netatalk Netatalk 1.5.0 through 4.4.2 uses DES-ECB for aut= hentication with a timing side channel, which allows a remote attacker to r= ecover authentication credentials via timing analysis. 2026-05-21 5.9 CVE-2= 026-44061 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44061 ] Netatalk Se= curity Advisory CVE-2026-44061 [ https://netatalk.io/security/CVE-2026-4406=
    1 ]
    =C2=A0 Netatalk--Netatalk An LDAP injection vulnerability in Netatalk 2.1.0=
    through 4.4.2 allows a remote authenticated attacker to manipulate LDAP qu= eries and obtain limited information or modify LDAP entries via crafted fil= ter input. 2026-05-21 4.2 CVE-2026-44063 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-44063 ] Netatalk Security Advisory CVE-2026-44063 [ https://net= atalk.io/security/CVE-2026-44063 ]
    =C2=A0 Netatalk--Netatalk Authentication modules in Netatalk 1.5.0 through = 4.4.2 fail to check the return value of seteuid(), which may allow a remote=
    authenticated attacker to retain elevated privileges under error condition=
    s. 2026-05-21 4 CVE-2026-44073 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-44073 ] Netatalk Security Advisory CVE-2026-44073 [ https://netatalk.io/s= ecurity/CVE-2026-44073 ]
    =C2=A0 NetBSD--src NetBSD prior to commit ec8451e contains a signed integer=
    overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cr= yptodev.c where the local variable iov_len is declared as a signed int but = assigned from an unsigned cop->dst_len value, causing undefined behavior wh=
    en cop->dst_len exceeds INT_MAX. A local attacker with access to /dev/crypt=
    o and a compression session type can exploit this vulnerability by providin=
    g a dst_len value exceeding INT_MAX to trigger a kernel panic through NULL = pointer dereference when CONFIG_SVS is disabled and corrupted UIO pointer a= rithmetic. 2026-05-18 5.5 CVE-2026-32849 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-32849 ] https://nasm.re/posts/uaf_netbsd_crypto/ https://github.com/NetBSD/src/commit/ec8451efc1565516aba9e7047e1a1a1ce7953a=
    2f
    https://www.vulncheck.com/advisories/netbsd-signed-integer-overflow-in-cryp= todev-op-via-cryptodev-c
    =C2=A0 NetBSD--src NetBSD prior to commit ec8451e contains a race condition=
    vulnerability in cryptodev_op() within the opencrypto subsystem that allow=
    s local attackers to trigger a double-free condition by concurrently issuin=
    g CIOCCRYPT operations on the same session identifier on SMP systems. Attac= kers can exploit mutable per-operation state embedded in the csession struc=
    t to corrupt kernel heap memory. 2026-05-18 4.7 CVE-2026-32848 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-32848 ] https://nasm.re/posts/uaf_netbsd_= crypto/ https://github.com/NetBSD/src/commit/ec8451efc1565516aba9e7047e1a1a1ce7953a=
    2f
    https://www.vulncheck.com/advisories/netbsd-cryptodev-race-condition-double= -free-via-cryptodev-op
    =C2=A0 nimiq--core-rs-albatross nimiq-blockchain provides persistent block = storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, netwo= rk-libp2p discovery accepts signed PeerContact updates from untrusted peers=
    and stores them in a peer contact book, eventually leading to address book=
    crash. A PeerContact can legally contain an empty addresses list (no intri= nsic validation enforces non-empty). Later, PeerContactBook::known_peers bu= ilds an address book by taking addresses.first().expect("every peer should = have at least one address"). If the attacker has inserted a signed peer con= tact with addresses=3D[], any call to get_address_book (RPC/web client) can=
    panic and crash the node/RPC task depending on panic settings. This issue = has been fixed in version 1.4.0. 2026-05-20 4.3 CVE-2026-40094 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-40094 ] https://github.com/nimiq/core-rs-= albatross/security/advisories/GHSA-c45m-6x25-3cjq https://github.com/nimiq/core-rs-albatross/pull/3715 https://github.com/nimiq/core-rs-albatross/releases/tag/v1.4.0
    =C2=A0 NousResearch--hermes-agent A security flaw has been discovered in No= usResearch hermes-agent up to 2026.4.16. This vulnerability affects the fun= ction _is_blocked_device of the file tools/file_tools.py of the component r= ead_file Tool. Performing a manipulation results in path traversal. The att= ack may be initiated remotely. The exploit has been released to the public = and may be used for attacks. The vendor was contacted early about this disc= losure but did not respond in any way. 2026-05-24 6.5 CVE-2026-9351 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-9351 ] VDB-365314 | NousResearch her= mes-agent read_file Tool file_tools.py _is_blocked_device path traversal [ = https://vuldb.com/vuln/365314 ]
    VDB-365314 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65314/cti ]
    Submit #812214 | NousResearch hermes-agent 2026.4.16 Path Traversal (CWE-22=
    ) [ https://vuldb.com/submit/812214 ] https://gist.github.com/YLChen-007/1d1aeff404cb88e06ec2fb3377f49fef
    =C2=A0 NousResearch--hermes-agent A vulnerability was detected in NousResea= rch hermes-agent up to 2026.4.16. The affected element is an unknown functi=
    on of the component Slack Agent/Mattermost Agent. The manipulation of the a= rgument format_message results in escaping of output. The attack can be exe= cuted remotely. The exploit is now public and may be used. The vendor was c= ontacted early about this disclosure but did not respond in any way. 2026-0= 5-24 6.5 CVE-2026-9354 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9354 ]=
    VDB-365317 | NousResearch hermes-agent Slack Agent/Mattermost Agent escape=
    output [ https://vuldb.com/vuln/365317 ]
    VDB-365317 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365317= /cti ]
    Submit #812226 | NousResearch hermes-agent 2026.4.16 Improper Encoding or E= scaping of Output (CWE-116) [ https://vuldb.com/submit/812226 ] https://gist.github.com/YLChen-007/e90fb38ac03284176bae49898a3a46a4
    =C2=A0 NousResearch--hermes-agent A weakness has been identified in NousRes= earch hermes-agent up to 2026.4.23. This issue affects the function _make_r= un_env of the file tools/environments/local.py of the component Messaging G= ateway Handler. Executing a manipulation can lead to information disclosure=
    . The attack may be launched remotely. The exploit has been made available =
    to the public and could be used for attacks. The vendor was contacted early=
    about this disclosure but did not respond in any way. 2026-05-24 5.3 CVE-2= 026-9352 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9352 ] VDB-365315 | = NousResearch hermes-agent Messaging Gateway local.py _make_run_env informat= ion disclosure [ https://vuldb.com/vuln/365315 ]
    VDB-365315 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65315/cti ]
    Submit #812215 | NousResearch hermes-agent 2026.4.23 Exposure of Sensitive = Information (CWE-200) [ https://vuldb.com/submit/812215 ] https://gist.github.com/YLChen-007/760b3940f708990e535214529c0c7a27
    =C2=A0 NousResearch--hermes-agent A security flaw has been discovered in No= usResearch hermes-agent 2026.4.23. Affected is the function _discover_dashb= oard_plugins of the file hermes_cli/web_server.py of the component CLI web-= dashboard Interface. Performing a manipulation of the argument HERMES_ENABL= E_PROJECT_PLUGINS results in incorrect comparison. The attack is only possi= ble with local access. The exploit has been released to the public and may =
    be used for attacks. The vendor was contacted early about this disclosure b=
    ut did not respond in any way. 2026-05-24 5.3 CVE-2026-9369 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-9369 ] VDB-365332 | NousResearch hermes-agen=
    t CLI web-dashboard web_server.py _discover_dashboard_plugins comparison [ = https://vuldb.com/vuln/365332 ]
    VDB-365332 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365332= /cti ]
    Submit #812230 | NousResearch hermes-agent 2026.4.23 Incorrect Comparison (= CWE-697) [ https://vuldb.com/submit/812230 ] https://gist.github.com/YLChen-007/062b77ceac6aa9844842a616f5d2ef30
    =C2=A0 Nozomi Networks--Guardian A Stored HTML Injection vulnerability was = discovered in the Smart Polling functionality due to improper validation of=
    an input parameter. An authenticated user with limited privileges can push=
    malicious remote strategies containing HTML tags through the sync. When a = victim views the affected remote strategy in the Smart Polling functionalit=
    y, the injected HTML renders in their browser, enabling phishing and possib=
    ly open redirect attacks. Full XSS exploitation and direct information disc= losure are prevented by the existing input validation and Content Security = Policy configuration. 2026-05-19 6.5 CVE-2025-40904 [ https://www.cve.org/C= VERecord?id=3DCVE-2025-40904 ] https://security.nozominetworks.com/NN-2026:= 7-01
    =C2=A0 Nozomi Networks--Guardian A Stored HTML Injection vulnerability was = discovered in the Credentials Manager functionality due to improper validat= ion of an input parameter. An authenticated user with administrative privil= eges can define a malicious identity containing HTML tags. When a victim at= tempts to delete the affected identity, the injected HTML renders in their = browser, enabling phishing and possibly open redirect attacks. Full XSS exp= loitation and direct information disclosure are prevented by the existing i= nput validation and Content Security Policy configuration. 2026-05-19 5.9 C= VE-2025-40901 [ https://www.cve.org/CVERecord?id=3DCVE-2025-40901 ] https:/= /security.nozominetworks.com/NN-2026:4-01
    =C2=A0 Nozomi Networks--Guardian A Stored HTML Injection vulnerability was = discovered in the Users functionality due to improper validation of an inpu=
    t parameter. An authenticated user with administrative privileges can creat=
    e a malicious user whose username contains HTML tags. When a victim attempt=
    s to delete a group containing the affected user, the injected HTML renders=
    in their browser, enabling phishing and possibly open redirect attacks. Fu=
    ll XSS exploitation and direct information disclosure are prevented by the = existing input validation and Content Security Policy configuration. 2026-0= 5-19 5.9 CVE-2025-40902 [ https://www.cve.org/CVERecord?id=3DCVE-2025-40902=
    ] https://security.nozominetworks.com/NN-2026:5-01
    =C2=A0 Nozomi Networks--Guardian A Stored HTML Injection vulnerability was = discovered in the Schedule Restore Archive functionality due to improper va= lidation of an input parameter. An authenticated user with administrative p= rivileges can define a malicious restore schedule containing HTML tags. Whe=
    n a victim views the affected schedule, the injected HTML renders in their = browser, enabling phishing and possibly open redirect attacks. Full XSS exp= loitation and direct information disclosure are prevented by the existing i= nput validation and Content Security Policy configuration. 2026-05-19 5.9 C= VE-2025-40903 [ https://www.cve.org/CVERecord?id=3DCVE-2025-40903 ] https:/= /security.nozominetworks.com/NN-2026:6-01
    =C2=A0 Nozomi Networks--Guardian An Angular template injection vulnerabilit=
    y was discovered in the Reports functionality due to improper validation of=
    an input parameter. An authenticated user with report privileges can defin=
    e a malicious report containing an Angular template payload, or a victim ca=
    n be socially engineered to import a malicious report template. When the vi= ctim views or imports the report, the Angular template executes in their br= owser context, allowing the attacker to modify application data, or disrupt=
    application availability. Full XSS exploitation and direct information dis= closure are prevented by the existing input validation and Content Security=
    Policy configuration. 2026-05-19 4.6 CVE-2025-40900 [ https://www.cve.org/= CVERecord?id=3DCVE-2025-40900 ] https://security.nozominetworks.com/NN-2026= :3-01
    =C2=A0 npitre--cramfs-tools A vulnerability was detected in npitre cramfs-t= ools up to 2.2. Affected is the function change_file_status of the file cra= mfsck.c. Performing a manipulation results in symlink following. The attack=
    requires a local approach. The exploit is now public and may be used. The = patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended =
    to apply a patch to fix this issue. 2026-05-18 4.2 CVE-2026-8784 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-8784 ] VDB-364408 | npitre cramfs-tools=
    cramfsck.c change_file_status symlink [ https://vuldb.com/vuln/364408 ] VDB-364408 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364408= /cti ]
    Submit #811897 | GNU cramfs-tools below v2.2 Symlink Following [ https://vu= ldb.com/submit/811897 ]
    https://github.com/npitre/cramfs-tools/issues/13 https://github.com/npitre/cramfs-tools/issues/13#issuecomment-4306102583 https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2= a6ac7667b4f
    https://github.com/npitre/cramfs-tools/
    =C2=A0 NVIDIA--TensorRT-LLM NVIDIA TRT-LLM for any platform contains a dese= rialization vulnerability and unsafe serialized handle. A successful exploi=
    t of this vulnerability might lead to code execution, data tampering, and i= nformation disclosure. 2026-05-20 6.3 CVE-2026-24142 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-24142 ] https://nvd.nist.gov/vuln/detail/CVE-2026-2= 4142
    https://www.cve.org/CVERecord?id=3DCVE-2026-24142 https://nvidia.custhelp.com/app/answers/detail/a_id/5805
    =C2=A0 NVIDIA--TensorRT-LLM NVIDIA TRT-LLM for any platform contains a vuln= erability where an attacker could cause an unchecked return value to a null=
    pointer dereference. A successful exploit of this vulnerability might lead=
    to denial of service. 2026-05-20 5.5 CVE-2026-24160 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-24160 ] https://nvd.nist.gov/vuln/detail/CVE-2026-2= 4160
    https://www.cve.org/CVERecord?id=3DCVE-2026-24160 https://nvidia.custhelp.com/app/answers/detail/a_id/5805
    =C2=A0 NVIDIA--Triton Inference Server NVIDIA Triton Inference Server conta= ins a vulnerability where an attacker could cause a path traversal issue. A=
    successful exploit of this vulnerability might lead to denial of service. = 2026-05-20 5.3 CVE-2026-24208 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -24208 ] https://nvd.nist.gov/vuln/detail/CVE-2026-24208 https://www.cve.org/CVERecord?id=3DCVE-2026-24208 https://nvidia.custhelp.com/app/answers/detail/a_id/5828
    =C2=A0 NVIDIA--Triton Inference Server NVIDIA Triton Inference Server conta= ins a vulnerability in the DALI backend, where an attacker could cause unco= ntrolled resource consumption. A successful exploit of this vulnerability m= ight lead to denial of service. 2026-05-20 5.7 CVE-2026-24215 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-24215 ] https://nvd.nist.gov/vuln/detail/C= VE-2026-24215
    https://www.cve.org/CVERecord?id=3DCVE-2026-24215 https://nvidia.custhelp.com/app/answers/detail/a_id/5828
    =C2=A0 oliverpos--Oliver POS A WooCommerce Point of Sale (POS) The Oliver P=
    OS - A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable t=
    o Authorization Bypass Through User-Controlled Key in all versions up to an=
    d including 2.4.2.6. The plugin protects its entire /wp-json/pos-bridge/* R= EST API namespace through the oliver_pos_rest_authentication() permission c= allback, which uses a loose PHP comparison (=3D=3D) to compare the attacker= -supplied 'OliverAuth' header value against the 'oliver_pos_authorization_t= oken' option. On fresh installations where the admin has not yet completed = the connection flow, this option is unset (get_option returns false). Due t=
    o PHP's type juggling, the loose comparison '0' =3D=3D false evaluates to t= rue, allowing an unauthenticated attacker to bypass authentication by sendi=
    ng 'OliverAuth: 0'. This grants full access to all POS API endpoints, enabl= ing attackers to read user data (including administrator details), update u= ser profiles (including email addresses), and delete non-admin users. An ad= min account email reset can lead to site takeover. 2026-05-20 6.5 CVE-2026-= 6072 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6072 ] https://www.wordf= ence.com/threat-intel/vulnerabilities/id/ca6aa922-9c58-445c-b88a-3d1d1c9510= 2c?source=3Dcve https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/class-= pos-bridge.php#L1679 https://plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes= /class-pos-bridge.php#L1679 https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/class-= pos-bridge.php#L1677 https://plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes= /class-pos-bridge.php#L1677 https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/class-= pos-bridge-user.php#L170 https://plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes= /class-pos-bridge-user.php#L170 https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/class-= pos-bridge-user.php#L195 https://plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes= /class-pos-bridge-user.php#L195 https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/class-= pos-bridge-user.php#L231 https://plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes= /class-pos-bridge-user.php#L231
    =C2=A0 olivesystem-- The =C3=A8=C2=A8=C2=BA=C3=A6=E2=80=93=C2=AD=C3=A3=E2= =80=9A=C2=B8=C3=A3=E2=80=9A=C2=A7=C3=A3=C6=92=C2=8D=C3=A3=C6=92=C2=AC=C3=A3= =C6=92=C2=BC=C3=A3=E2=80=9A=C2=BF=C3=A4=C2=BD=C5=93=C3=A6=CB=86=C2=90=C3=A3= =C6=92=E2=80=94=C3=A3=C6=92=C2=A9=C3=A3=E2=80=9A=C2=B0=C3=A3=E2=80=9A=C2=A4= =C3=A3=C6=92=C2=B3 (Diagnosis Generator) plugin for WordPress is vulnerable=
    to Stored Cross-Site Scripting via the 'js' parameter in versions up to an=
    d including 1.4.16. This is due to missing authorization checks and insuffi= cient input sanitization in the themeFunc() function. The function is hooke=
    d to 'admin_init' and processes theme update requests without verifying use=
    r capabilities, allowing any authenticated user (including subscribers) to = save malicious JavaScript to theme files. Additionally, the save() function=
    uses stripslashes() which removes WordPress's magic quotes protection. Thi=
    s makes it possible for authenticated attackers, with subscriber-level acce=
    ss and above, to inject arbitrary web scripts in theme files that will exec= ute whenever a user accesses a page containing the diagnosis form shortcode=
    . 2026-05-20 6.4 CVE-2026-5293 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-5293 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/c5293c0f= -90b0-41df-a623-90297d998c41?source=3Dcve https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/trunk/dia= gnosisAdminClass.php#L409 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/1.4.= 16/diagnosisAdminClass.php#L409 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/trunk/cla= ss/themeClass.php#L26 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/1.4.= 16/class/themeClass.php#L26 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/trunk/cla= ss/themeClass.php#L39 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/1.4.= 16/class/themeClass.php#L39 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/trunk/inc= lude_files/user-viewFormPage.php#L102 https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/1.4.= 16/include_files/user-viewFormPage.php#L102
    =C2=A0 omec-project--amf A vulnerability was detected in omec-project amf u=
    p to 2.1.1. Affected by this vulnerability is an unknown functionality of t=
    he component PathSwitchRequest Handler. The manipulation results in memory = corruption. The attack may be launched remotely. The exploit is now public = and may be used. It is advisable to implement a patch to correct this issue=
    . 2026-05-23 6.3 CVE-2026-9298 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-9298 ] VDB-365245 | omec-project amf PathSwitchRequest memory corruption =
    [ https://vuldb.com/vuln/365245 ]
    VDB-365245 | CTI Indicators (IOB, IOC) [ https://vuldb.com/vuln/365245/cti ] Submit #811684 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811684 ] https://github.com/omec-project/amf/issues/680 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A flaw has been found in omec-project amf up to 2.= 1.1. Affected by this issue is the function PDUSessionResourceModifyIndicat= ion of the file /go/src/amf/ngap/handler.go. This manipulation causes memor=
    y corruption. Remote exploitation of the attack is possible. The exploit ha=
    s been published and may be used. Applying a patch is the recommended actio=
    n to fix this issue. 2026-05-23 6.3 CVE-2026-9299 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-9299 ] VDB-365246 | omec-project amf handler.go PDUSes= sionResourceModifyIndication memory corruption [ https://vuldb.com/vuln/365= 246 ]
    VDB-365246 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365246= /cti ]
    Submit #811829 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811829 ] https://github.com/omec-project/amf/issues/681 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A vulnerability has been found in omec-project amf=
    up to 2.1.1. This affects an unknown part of the component NGSetupRequest = Handler. Such manipulation leads to memory corruption. The attack can be ex= ecuted remotely. The exploit has been disclosed to the public and may be us= ed. It is best practice to apply a patch to resolve this issue. 2026-05-23 = 6.3 CVE-2026-9300 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9300 ] VDB-= 365247 | omec-project amf NGSetupRequest memory corruption [ https://vuldb.= com/vuln/365247 ]
    VDB-365247 | CTI Indicators (IOB, IOC) [ https://vuldb.com/vuln/365247/cti ] Submit #811841 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811841 ] https://github.com/omec-project/amf/issues/679 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A vulnerability was found in omec-project amf up t=
    o 2.1.1. This vulnerability affects unknown code of the component NGReset M= essage Handler. Performing a manipulation results in memory corruption. The=
    attack is possible to be carried out remotely. The exploit has been made p= ublic and could be used. It is recommended to apply a patch to fix this iss= ue. 2026-05-23 6.3 CVE-2026-9301 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-9301 ] VDB-365248 | omec-project amf NGReset Message memory corruption =
    [ https://vuldb.com/vuln/365248 ]
    VDB-365248 | CTI Indicators (IOB, IOC) [ https://vuldb.com/vuln/365248/cti ] Submit #811842 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811842 ] https://github.com/omec-project/amf/issues/678 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A vulnerability was determined in omec-project amf=
    up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/= handler.go. Executing a manipulation of the argument InformationElement can=
    lead to memory corruption. The attack can be launched remotely. The exploi=
    t has been publicly disclosed and may be utilized. Upgrading to version 2.2=
    .0 is recommended to address this issue. The affected component should be u= pgraded. The same pull request fixes multiple security issues. 2026-05-18 4=
    .3 CVE-2026-8779 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8779 ] VDB-3= 64403 | omec-project amf handler.go NGSetupRequest memory corruption [ http= s://vuldb.com/vuln/364403 ]
    VDB-364403 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364403= /cti ]
    Submit #811616 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811616 ] https://github.com/omec-project/amf/issues/671 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/releases/tag/v2.2.0 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A vulnerability was identified in omec-project amf=
    up to 2.1.3-dev. The affected element is an unknown function of the file n= gap/dispatcher.go of the component NGAP Message Handler. The manipulation l= eads to memory corruption. The attack may be initiated remotely. The exploi=
    t is publicly available and might be used. Upgrading to version 2.2.0 is su= fficient to fix this issue. It is suggested to upgrade the affected compone= nt. The same pull request fixes multiple security issues. 2026-05-18 4.3 CV= E-2026-8780 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8780 ] VDB-364404=
    | omec-project amf NGAP Message dispatcher.go memory corruption [ https://= vuldb.com/vuln/364404 ]
    VDB-364404 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364404= /cti ]
    Submit #811617 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811617 ] https://github.com/omec-project/amf/issues/670 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/releases/tag/v2.2.0 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A security flaw has been discovered in omec-projec=
    t amf up to 2.1.3-dev. The impacted element is the function RANConfiguratio=
    n of the file ngap/handler.go. The manipulation results in null pointer der= eference. The attack may be launched remotely. The exploit has been release=
    d to the public and may be used for attacks. Upgrading to version 2.2.0 is = sufficient to resolve this issue. Upgrading the affected component is recom= mended. The same pull request fixes multiple security issues. 2026-05-18 4.=
    3 CVE-2026-8781 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8781 ] VDB-36= 4405 | omec-project amf handler.go RANConfiguration null pointer dereferenc=
    e [ https://vuldb.com/vuln/364405 ]
    VDB-364405 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364405= /cti ]
    Submit #811653 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811653 ] https://github.com/omec-project/amf/issues/673 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/releases/tag/v2.2.0 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A weakness has been identified in omec-project amf=
    up to 2.1.3-dev. This affects an unknown function of the file ngap/handler= .go of the component NGAP Message Handler. This manipulation causes null po= inter dereference. Remote exploitation of the attack is possible. The explo=
    it has been made available to the public and could be used for attacks. Upg= rading to version 2.2.0 mitigates this issue. It is recommended to upgrade = the affected component. The same pull request fixes multiple security issue=
    s. 2026-05-18 4.3 CVE-2026-8782 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-8782 ] VDB-364406 | omec-project amf NGAP Message handler.go null pointe=
    r dereference [ https://vuldb.com/vuln/364406 ]
    VDB-364406 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364406= /cti ]
    Submit #811654 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811654 ] https://github.com/omec-project/amf/issues/674 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/releases/tag/v2.2.0 https://github.com/omec-project/amf/
    =C2=A0 omec-project--amf A security vulnerability has been detected in omec= -project amf up to 2.1.3-dev. This impacts the function UERadioCapabilityCh= eckResponse of the file ngap/dispatcher.go. Such manipulation leads to null=
    pointer dereference. The attack can be executed remotely. The exploit has = been disclosed publicly and may be used. Upgrading to version 2.2.0 will fi=
    x this issue. Upgrading the affected component is advised. The same pull re= quest fixes multiple security issues. 2026-05-18 4.3 CVE-2026-8783 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-8783 ] VDB-364407 | omec-project amf = dispatcher.go UERadioCapabilityCheckResponse null pointer dereference [ htt= ps://vuldb.com/vuln/364407 ]
    VDB-364407 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364407= /cti ]
    Submit #811655 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption =
    [ https://vuldb.com/submit/811655 ] https://github.com/omec-project/amf/issues/675 https://github.com/omec-project/amf/pull/666 https://github.com/omec-project/amf/releases/tag/v2.2.0 https://github.com/omec-project/amf/
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in add.php that allows authenticated=
    attackers to inject arbitrary JavaScript by passing an unsanitized value t= hrough the ticket_id POST parameter directly into an HTML form input value = attribute. Attackers can craft a malicious request containing a JavaScript = payload that executes in the victim's browser when the response is rendered=
    . 2026-05-21 5.4 CVE-2026-48213 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-48213 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ad= d-php-ticket-id-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in add_nm.php that allows authentica= ted attackers to inject arbitrary JavaScript by passing an unsanitized valu=
    e through the ticket_id POST parameter directly into an HTML form input val=
    ue attribute and an inline JavaScript string literal. Attackers can craft a=
    malicious request containing a JavaScript payload that executes in the vic= tim's browser when the response is rendered. 2026-05-21 5.4 CVE-2026-48214 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-48214 ] https://github.com/op= enises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ad= d-nm-php-ticket-id-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in circle.php that allows authentica= ted attackers to inject arbitrary JavaScript by passing an unsanitized valu=
    e through the frm_id POST parameter directly into an HTML form input value = attribute. Attackers can craft a malicious request containing a JavaScript = payload that executes in the victim's browser when the response is rendered=
    . 2026-05-21 5.4 CVE-2026-48215 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-48215 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ci= rcle-php-frm-id-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in db_loader.php that allows authent= icated attackers to inject arbitrary JavaScript by passing an unsanitized v= alue through the multiple POST parameters (ticketshost, ticketsdb, ticketsu= ser, ticketspassword, ticketsprefix, db_schema) directly into HTML form inp=
    ut value attributes. Attackers can craft a malicious request containing a J= avaScript payload that executes in the victim's browser when the response i=
    s rendered. 2026-05-21 5.4 CVE-2026-48216 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-48216 ] https://github.com/openises/tickets/releases/tag/v3.44=
    .2
    https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-db= -loader-php-multiple-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in delete_module.php that allows aut= henticated attackers to inject arbitrary JavaScript by passing an unsanitiz=
    ed value through the multiple POST parameters (module_choice, flag, confirm= ation) directly into rendered HTML content and form action attributes. Atta= ckers can craft a malicious request containing a JavaScript payload that ex= ecutes in the victim's browser when the response is rendered. 2026-05-21 5.=
    4 CVE-2026-48217 [ https://www.cve.org/CVERecord?id=3DCVE-2026-48217 ] http= s://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-de= lete-module-php-multiple-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in icons/buttons/landb.php that allo=
    ws authenticated attackers to inject arbitrary JavaScript by passing an uns= anitized value through the frm_name and frm_id POST parameters directly int=
    o rendered HTML content and inline JavaScript. Attackers can craft a malici= ous request containing a JavaScript payload that executes in the victim's b= rowser when the response is rendered. 2026-05-21 5.4 CVE-2026-48218 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-48218 ] https://github.com/openises/= tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= ons-buttons-landb-php-frm-name-and-frm-id-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ics202.php that allows authentica= ted attackers to inject arbitrary JavaScript by passing an unsanitized valu=
    e through the frm_add_str POST parameter directly into an HTML form hidden = input value attribute. Attackers can craft a malicious request containing a=
    JavaScript payload that executes in the victim's browser when the response=
    is rendered. 2026-05-21 5.4 CVE-2026-48219 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-48219 ] https://github.com/openises/tickets/releases/tag/v3.= 44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= s202-php-frm-add-str-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ics205.php that allows authentica= ted attackers to inject arbitrary JavaScript by passing an unsanitized valu=
    e through the frm_add_str POST parameter directly into an HTML form hidden = input value attribute. Attackers can craft a malicious request containing a=
    JavaScript payload that executes in the victim's browser when the response=
    is rendered. 2026-05-21 5.4 CVE-2026-48220 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-48220 ] https://github.com/openises/tickets/releases/tag/v3.= 44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= s205-php-frm-add-str-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ics205a.php that allows authentic= ated attackers to inject arbitrary JavaScript by passing an unsanitized val=
    ue through the frm_add_str POST parameter directly into an HTML form hidden=
    input value attribute. Attackers can craft a malicious request containing =
    a JavaScript payload that executes in the victim's browser when the respons=
    e is rendered. 2026-05-21 5.4 CVE-2026-48221 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-48221 ] https://github.com/openises/tickets/releases/tag/v3= .44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= s205a-php-frm-add-str-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ics213.php that allows authentica= ted attackers to inject arbitrary JavaScript by passing an unsanitized valu=
    e through the frm_add_str POST parameter directly into an HTML form hidden = input value attribute. Attackers can craft a malicious request containing a=
    JavaScript payload that executes in the victim's browser when the response=
    is rendered. 2026-05-21 5.4 CVE-2026-48222 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-48222 ] https://github.com/openises/tickets/releases/tag/v3.= 44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= s213-php-frm-add-str-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ics213rr.php that allows authenti= cated attackers to inject arbitrary JavaScript by passing an unsanitized va= lue through the frm_add_str POST parameter directly into an HTML form hidde=
    n input value attribute. Attackers can craft a malicious request containing=
    a JavaScript payload that executes in the victim's browser when the respon=
    se is rendered. 2026-05-21 5.4 CVE-2026-48223 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-48223 ] https://github.com/openises/tickets/releases/tag/v= 3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= s213rr-php-frm-add-str-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ics214.php that allows authentica= ted attackers to inject arbitrary JavaScript by passing an unsanitized valu=
    e through the frm_add_str POST parameter directly into an HTML form hidden = input value attribute. Attackers can craft a malicious request containing a=
    JavaScript payload that executes in the victim's browser when the response=
    is rendered. 2026-05-21 5.4 CVE-2026-48224 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-48224 ] https://github.com/openises/tickets/releases/tag/v3.= 44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ic= s214-php-frm-add-str-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in landb.php that allows authenticat=
    ed attackers to inject arbitrary JavaScript by passing an unsanitized value=
    through the _type POST parameter directly into an HTML form hidden input v= alue attribute. Attackers can craft a malicious request containing a JavaSc= ript payload that executes in the victim's browser when the response is ren= dered. 2026-05-21 5.4 CVE-2026-48225 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-48225 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-la= ndb-php-type-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in os_watch.php that allows authenti= cated attackers to inject arbitrary JavaScript by passing an unsanitized va= lue through the ref and mode_orig POST parameters directly into HTML form h= idden input value attributes. Attackers can craft a malicious request conta= ining a JavaScript payload that executes in the victim's browser when the r= esponse is rendered. 2026-05-21 5.4 CVE-2026-48226 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-48226 ] https://github.com/openises/tickets/releases/= tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-os= -watch-php-ref-and-mode-orig-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in patient.php that allows authentic= ated attackers to inject arbitrary JavaScript by passing an unsanitized val=
    ue through the id and ticket_id GET parameters directly into an HTML form a= ction URL. Attackers can craft a malicious request containing a JavaScript = payload that executes in the victim's browser when the response is rendered=
    . 2026-05-21 5.4 CVE-2026-48227 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-48227 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-pa= tient-php-id-and-ticket-id-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in patient_w.php that allows authent= icated attackers to inject arbitrary JavaScript by passing an unsanitized v= alue through the id and ticket_id GET parameters directly into an HTML form=
    action URL. Attackers can craft a malicious request containing a JavaScrip=
    t payload that executes in the victim's browser when the response is render= ed. 2026-05-21 5.4 CVE-2026-48228 [ https://www.cve.org/CVERecord?id=3DCVE-= 2026-48228 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-pa= tient-w-php-id-and-ticket-id-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in routes_i.php that allows authenti= cated attackers to inject arbitrary JavaScript by passing an unsanitized va= lue through the ticket_id GET parameter directly into HTML form hidden inpu=
    t value attributes. Attackers can craft a malicious request containing a Ja= vaScript payload that executes in the victim's browser when the response is=
    rendered. 2026-05-21 5.4 CVE-2026-48229 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-48229 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ro= utes-i-php-ticket-id-parameter
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 contains a reflec= ted cross-site scripting vulnerability in ticketsmdb_import.php that allows=
    authenticated attackers to inject arbitrary JavaScript by passing an unsan= itized value through the multiple POST parameters (mdbhost, mdbdb, mdbuser,=
    mdbpassword, mdbprefix, ticketshost, ticketsdb, ticketsuser, ticketspasswo= rd, ticketsprefix) directly into HTML form hidden input value attributes. A= ttackers can craft a malicious request containing a JavaScript payload that=
    executes in the victim's browser when the response is rendered. 2026-05-21=
    5.4 CVE-2026-48230 [ https://www.cve.org/CVERecord?id=3DCVE-2026-48230 ] h= ttps://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ti= cketsmdb-import-php-multiple-parameters
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 embeds a hardcode=
    d WhitePages reverse-phone API key in wp1.php that is committed to the publ=
    ic source repository. Any actor with read access to the source tree can ext= ract the key and use it to make third-party API calls billed to or rate-lim= ited against the original owner's WhitePages account. 2026-05-21 5.3 CVE-20= 26-48243 [ https://www.cve.org/CVERecord?id=3DCVE-2026-48243 ] https://gith= ub.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-whitepages= -api-key-in-wp1-php
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 embeds a hardcode=
    d Google Maps API key in settings.inc.php that is committed to the public s= ource repository. The key can be extracted by anyone with read access to th=
    e source and used to make Google Maps Platform requests billed against the = original owner's Google Cloud project. 2026-05-21 5.3 CVE-2026-48244 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-48244 ] https://github.com/openises= /tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-google-map= s-api-key-in-settings-inc-php
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 embeds a hardcode=
    d Google Maps API key in tables.php that is committed to the public source = repository. The key can be extracted by anyone with read access to the sour=
    ce and used to make Google Maps Platform requests billed against the origin=
    al owner's Google Cloud project. 2026-05-21 5.3 CVE-2026-48245 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-48245 ] https://github.com/openises/ticke= ts/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-google-map= s-api-key-in-tables-php
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 disables TLS cert= ificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER =
    to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTT=
    PS requests for Google Maps Directions API lookups during incident report g= eneration. An attacker positioned on the network path between the server an=
    d the remote endpoint can present a forged certificate to intercept, monito=
    r, or modify the request and response, including any API keys or session-be= aring data in transit. 2026-05-21 5.9 CVE-2026-48246 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-48246 ] https://github.com/openises/tickets/release= s/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-disabled-tls-certifi= cate-verification-in-ajax-reports-php
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 disables TLS cert= ificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIF= YPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbou=
    nd HTTPS requests for general-purpose outbound HTTPS requests issued by the=
    shared helper functions. An attacker positioned on the network path betwee=
    n the server and the remote endpoint can present a forged certificate to in= tercept, monitor, or modify the request and response, including any API key=
    s or session-bearing data in transit. 2026-05-21 5.9 CVE-2026-48247 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-48247 ] https://github.com/openises/= tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-disabled-tls-certifi= cate-verification-in-incs-functions-inc-php
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 disables TLS cert= ificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEE=
    R to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound H= TTPS requests issued during the login/authentication flow. An attacker posi= tioned on the network path between the server and the remote endpoint can p= resent a forged certificate to intercept, monitor, or modify the request an=
    d response, including any API keys or session-bearing data in transit. 2026= -05-21 5.9 CVE-2026-48248 [ https://www.cve.org/CVERecord?id=3DCVE-2026-482=
    48 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-disabled-tls-certifi= cate-verification-in-incs-login-inc-php
    =C2=A0 Open ISES--Tickets Open ISES Tickets before 3.44.2 disables TLS cert= ificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL= _VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing = outbound HTTPS requests issued during the mobile (RouteMate) login flow. An=
    attacker positioned on the network path between the server and the remote = endpoint can present a forged certificate to intercept, monitor, or modify = the request and response, including any API keys or session-bearing data in=
    transit. 2026-05-21 5.9 CVE-2026-48249 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-48249 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-disabled-tls-certifi= cate-verification-in-rm-incs-mobile-login-inc-php
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker arbitrary code execution. 2026-05-19 6.5 CVE-2026-28733 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-28733 ] https://gitcode.com/o= penharmony/security/tree/master/zh/security-disclosure/2026/2026-05.md
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker cause information leak 2026-05-19 5.5 CVE-2026-25850 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-25850 ] https://gitcode.com/open= harmony/security/tree/master/zh/security-disclosure/2026/2026-05.md
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker cause information leak. 2026-05-19 5.5 CVE-2026-27766 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-27766 ] https://gitcode.com/ope= nharmony/security/tree/master/zh/security-disclosure/2026/2026-05.md
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in single_unit.php that allows authen= ticated attackers to inject arbitrary JavaScript by passing an unsanitized = value through the id GET parameter directly into an HTML attribute. Attacke=
    rs can craft a malicious URL containing a JavaScript payload in the id para= meter that executes in the victim's browser when the URL is visited. 2026-0= 5-20 4.6 CVE-2026-35007 [ https://www.cve.org/CVERecord?id=3DCVE-2026-35007=
    ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-si= ngle-unit-php-id-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in single.php that allows authenticat=
    ed attackers to inject arbitrary JavaScript by passing an unsanitized value=
    through the ticket_id GET parameter directly into an HTML attribute. Attac= kers can craft a malicious URL containing a JavaScript payload in the id pa= rameter that executes in the victim's browser when the URL is visited. 2026= -05-20 4.6 CVE-2026-35008 [ https://www.cve.org/CVERecord?id=3DCVE-2026-350=
    08 ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-si= ngle-php-ticket-id-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in add_note.php that allows authentic= ated attackers to inject arbitrary JavaScript by passing an unsanitized val=
    ue through the ticket_id GET parameter directly into a hidden input field V= ALUE attribute. Attackers can craft a malicious URL containing a JavaScript=
    payload in the ticket_id parameter that executes in the victim's browser w= hen the URL is visited. 2026-05-20 4.6 CVE-2026-35009 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-35009 ] https://github.com/openises/tickets/releas= es/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ad= d-note-php-ticket-id-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in patient_JF.php that allows authent= icated attackers to inject arbitrary JavaScript by passing an unsanitized v= alue through the ticket_id GET parameter directly into a JavaScript variabl=
    e assignment. Attackers can craft a malicious URL containing a JavaScript p= ayload in the ticket_id parameter that executes in the victim's browser whe=
    n the URL is visited. 2026-05-20 4.6 CVE-2026-35010 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-35010 ] https://github.com/openises/tickets/releases= /tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-pa= tient-jf-php-ticket-id-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in opena.php that allows authenticate=
    d attackers to inject arbitrary JavaScript by passing an unsanitized value = through the frm_call GET parameter directly into page output. Attackers can=
    craft a malicious URL containing a JavaScript payload in the frm_call para= meter that executes in the victim's browser when the URL is visited. 2026-0= 5-20 4.6 CVE-2026-35011 [ https://www.cve.org/CVERecord?id=3DCVE-2026-35011=
    ] https://github.com/openises/tickets/releases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-op= ena-php-frm-call-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in add_facnote.php that allows authen= ticated attackers to inject arbitrary JavaScript by passing an unsanitized = value through the ticket_id GET parameter directly into a hidden input fiel=
    d VALUE attribute. Attackers can craft a malicious URL containing a JavaScr= ipt payload in the ticket_id parameter that executes in the victim's browse=
    r when the URL is visited. 2026-05-20 4.6 CVE-2026-35012 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-35012 ] https://github.com/openises/tickets/rel= eases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ad= d-facnote-php-ticket-id-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in street_view.php that allows authen= ticated attackers to inject arbitrary JavaScript by passing unsanitized val= ues through the thelat and thelng GET parameters directly into JavaScript v= ariable assignments. Attackers can craft a malicious URL containing a JavaS= cript payload in either parameter that executes in the victim's browser whe=
    n the URL is visited. 2026-05-20 4.6 CVE-2026-35013 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-35013 ] https://github.com/openises/tickets/releases= /tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-st= reet-view-php-thelat-and-thelng-parameters
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in routes_nm.php that allows authenti= cated attackers to inject arbitrary JavaScript by passing an unsanitized va= lue through the ticket_id GET parameter directly into a hidden input field = VALUE attribute. Attackers can craft a malicious URL containing a JavaScrip=
    t payload in the ticket_id parameter that executes in the victim's browser = when the URL is visited. 2026-05-20 4.6 CVE-2026-35014 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-35014 ] https://github.com/openises/tickets/relea= ses/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-ro= utes-nm-php-ticket-id-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in do_unit_mail.php that allows authe= nticated attackers to inject arbitrary JavaScript by passing an unsanitized=
    value through the the_ticket GET parameter directly into a JavaScript vari= able assignment. Attackers can craft a malicious URL containing a JavaScrip=
    t payload in the the_ticket parameter that executes in the victim's browser=
    when the URL is visited. 2026-05-20 4.6 CVE-2026-35015 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-35015 ] https://github.com/openises/tickets/rele= ases/tag/v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-do= -unit-mail-php-the-ticket-parameter
    =C2=A0 openises--tickets Open ISES Tickets before 3.44.2 contains a reflect=
    ed cross-site scripting vulnerability in search.php that allows authenticat=
    ed attackers to inject arbitrary JavaScript by passing an unsanitized value=
    through the frm_query POST parameter directly into an HTML input field VAL=
    UE attribute. Attackers can craft a malicious request containing a JavaScri=
    pt payload in the frm_query parameter that executes in the victim's browser=
    when submitted. 2026-05-20 4.6 CVE-2026-35016 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-35016 ] https://github.com/openises/tickets/releases/tag/= v3.44.2 https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145= a9f2dbff https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-se= arch-php-frm-query-parameter
    =C2=A0 opensourcepos--Open Source Point of Sale A vulnerability was detecte=
    d in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affect=
    s the function getPicThumb of the file app/Controllers/Items.php. The manip= ulation of the argument pic_filename results in path traversal. The attack = may be launched remotely. The patch is identified as def0c27a0e252668df8d94= 2fc31e16d1edfd7323. A patch should be applied to remediate this issue. The = vendor was contacted early about this disclosure. 2026-05-18 4.3 CVE-2026-8= 802 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8802 ] VDB-364435 | opens= ourcepos Open Source Point of Sale Items.php getPicThumb path traversal [ h= ttps://vuldb.com/vuln/364435 ]
    VDB-364435 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 64435/cti ]
    Submit #802559 | opensourcepos Open Source Point of Sale 3.4.1 Path Travers=
    al [ https://vuldb.com/submit/802559 ] https://github.com/opensourcepos/opensourcepos/security/advisories/GHSA-xq6= 3-3v4g-39r5
    https://github.com/opensourcepos/opensourcepos/pull/4545 https://github.com/opensourcepos/opensourcepos/commit/def0c27a0e252668df8d9= 42fc31e16d1edfd7323
    =C2=A0 owencutajar--SponsorMe The SponsorMe plugin for WordPress is vulnera= ble to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version=
    s up to, and including, 0.5.2 due to insufficient input sanitization and ou= tput escaping. This makes it possible for unauthenticated attackers to inje=
    ct arbitrary web scripts in pages that execute if they can successfully tri=
    ck a user into performing an action such as clicking on a link. The PHP_SEL=
    F value is reflected in two separate locations within the vulnerable functi=
    on - a form action attribute and an anchor href attribute - both of which c=
    an be exploited by appending a crafted payload to the wp-admin/admin.php UR=
    L path. 2026-05-20 6.1 CVE-2026-8626 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-8626 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/7d= f7f541-b8aa-46fa-bfca-b333beea27f9?source=3Dcve https://plugins.trac.wordpress.org/browser/sponsorme/trunk/sponsorme.php#L4=
    40
    https://plugins.trac.wordpress.org/browser/sponsorme/trunk/sponsorme.php#L4=
    75
    =C2=A0 pftool--Alfie Feed Plugin The Alfie - Feed Plugin plugin for WordPre=
    ss is vulnerable to Cross-Site Request Forgery in all versions up to, and i= ncluding, 1.2.1. This is due to missing nonce validation on the alfie_manag= e() function which handles feed deletion via the 'delete' GET parameter. Th=
    is makes it possible for unauthenticated attackers to delete arbitrary plug=
    in feed data (from alfie_colindex, alfie_producten, alfie_reactions, and al= fie_searchproduct tables) via a forged request granted they can trick a sit=
    e administrator into performing an action such as clicking on a link. 2026-= 05-22 4.3 CVE-2026-4070 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4070 =
    ] https://www.wordfence.com/threat-intel/vulnerabilities/id/af36719a-8f7d-4= 6dc-a697-cfcbb08e45e2?source=3Dcve https://plugins.trac.wordpress.org/browser/alfie-the-productfeedtool-wp-plu= gin/trunk/include/alfie-manage.php#L60 https://plugins.trac.wordpress.org/browser/alfie-the-productfeedtool-wp-plu= gin/tags/1.2.1/include/alfie-manage.php#L60 https://plugins.trac.wordpress.org/browser/alfie-the-productfeedtool-wp-plu= gin/trunk/include/alfie-manage.php#L58 https://plugins.trac.wordpress.org/browser/alfie-the-productfeedtool-wp-plu= gin/tags/1.2.1/include/alfie-manage.php#L58
    =C2=A0 PowerDNS--Authoritative Insufficient Validation of Names During AXFR=
    2026-05-21 6.8 CVE-2026-42000 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-42000 ] https://docs.powerdns.com/authoritative/security-advisories/power= dns-advisory-powerdns-2026-06.html
    =C2=A0 PowerDNS--Authoritative Concurrency and locking defects in GSS-TSIG = 2026-05-21 5.9 CVE-2026-42002 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -42002 ] https://docs.powerdns.com/authoritative/security-advisories/powerd= ns-advisory-powerdns-2026-06.html
    =C2=A0 PowerDNS--Authoritative Incorrect Behaviour of Views with TCP PROXY = Requests 2026-05-21 4.8 CVE-2026-41999 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-41999 ] https://docs.powerdns.com/authoritative/security-adviso= ries/powerdns-advisory-powerdns-2026-06.html
    =C2=A0 PowerDNS--Authoritative Insufficient Validation of Member Zone Data = May Cause Catalog Zone Transfer to Fail 2026-05-21 4.9 CVE-2026-42396 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-42396 ] https://docs.powerdns.com/= authoritative/security-advisories/powerdns-advisory-powerdns-2026-06.html =C2=A0 Progress Software--MOVEit Automation Incorrect default permissions v= ulnerability in Progress Software MOVEit Automation allows Retrieve Embedde=
    d Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, f= rom 2025.1.0 before 2025.1.7. 2026-05-20 6.5 CVE-2026-8487 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-8487 ] https://docs.progress.com/bundle/movei= t-automation-release-notes-2026/page/Fixed-Issues-2026.html
    =C2=A0 Progress Software--MOVEit Automation Uncontrolled Memory Allocation = vulnerability in Progress Software MOVEit Automation allows Excessive Alloc= ation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.=
    0 before 2025.1.7. 2026-05-20 5.9 CVE-2026-8485 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-8485 ] https://docs.progress.com/bundle/moveit-automatio= n-release-notes-2026/page/Fixed-Issues-2026.html
    =C2=A0 Progress Software--MOVEit Automation Allocation of resources without=
    limits or throttling vulnerability in Progress Software MOVEit Automation = allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, fr=
    om 2025.1.0 before 2025.1.7. 2026-05-20 5.3 CVE-2026-8486 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-8486 ] https://docs.progress.com/bundle/moveit= -automation-release-notes-2026/page/Fixed-Issues-2026.html
    =C2=A0 Progress Software--MOVEit Automation Allocation of resources without=
    limits or throttling vulnerability in Progress Software MOVEit Automation = allows Excessive Allocation. This issue affects MOVEit Automation: before 2= 025.0.11, from 2025.1.0 before 2025.1.7. 2026-05-20 4.3 CVE-2026-8488 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-8488 ] https://docs.progress.com/b= undle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html
    =C2=A0 QuantumNous--new-api A weakness has been identified in QuantumNous n= ew-api up to 0.12.1. The impacted element is the function SearchUserTopUps/= SearchAllTopUps of the file model/topup.go of the component self Endpoint. = This manipulation causes sql injection. The attack can be initiated remotel=
    y. The exploit has been made available to the public and could be used for = attacks. The vendor was contacted early about this disclosure but did not r= espond in any way. 2026-05-23 6.3 CVE-2026-9305 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-9305 ] VDB-365252 | QuantumNous new-api self Endpoint to= pup.go SearchAllTopUps sql injection [ https://vuldb.com/vuln/365252 ] VDB-365252 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65252/cti ]
    Submit #812192 | QuantumNous new-api [Needs Manual Input] SQL Injection (CW= E-89) [ https://vuldb.com/submit/812192 ]
    Submit #812195 | QuantumNous new-api 0.12.1 Improper Neutralization of Data=
    Query Logic (CWE-943) (Duplicate) [ https://vuldb.com/submit/812195 ] https://gist.github.com/YLChen-007/cf501d0a66c81298b2f97e854f3813db
    =C2=A0 rdbeach--BLOGCHAT Chat System The BLOGCHAT Chat System plugin for Wo= rdPress is vulnerable to Cross-Site Request Forgery in all versions up to, = and including, 1.3.6.3. This is due to missing or incorrect nonce validatio=
    n on a function. This makes it possible for unauthenticated attackers to up= date settings and inject malicious web scripts via a forged request granted=
    they can trick a site administrator into performing an action such as clic= king on a link. 2026-05-20 6.1 CVE-2026-8420 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-8420 ] https://www.wordfence.com/threat-intel/vulnerabiliti= es/id/a62186aa-19aa-445b-8fdc-b029bdafd58f?source=3Dcve https://plugins.trac.wordpress.org/browser/blogchat-chat-system/trunk/wp-bl= ogchat-widget.php#L208 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.= 3/wp-blogchat-widget.php#L208 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/trunk/wp-bl= ogchat-widget.php#L215 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.= 3/wp-blogchat-widget.php#L215 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/trunk/wp-bl= ogchat-widget.php#L222 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.= 3/wp-blogchat-widget.php#L222 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/trunk/wp-bl= ogchat-widget.php#L293 https://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.= 3/wp-blogchat-widget.php#L293
    =C2=A0 Red Hat--Red Hat Build of Keycloak A flaw was found in Keycloak. The=
    cross-session verification proof is keyed only by (local userId, idpAlias)=
    and is not bound to the upstream identity that was actually verified, so a=
    second upstream account on the same IdP can consume it and get linked to t=
    he victim's local account. 2026-05-20 6.4 CVE-2026-9087 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-9087 ] https://access.redhat.com/security/cve/CV= E-2026-9087
    RHBZ#2480172 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2480172 ]
    =C2=A0 Red Hat--Red Hat Build of Keycloak A flaw was found in Keycloak. Whe=
    n both realm-level and client-level `notBefore` revocation policies are con= figured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to pr= operly honor the realm-level policy. This allows tokens that should have be=
    en revoked to remain active, potentially leading to unauthorized access or = continued session validity. This could impact the security of systems utili= zing Keycloak for identity and access management. 2026-05-19 5.4 CVE-2026-8= 922 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8922 ] https://access.red= hat.com/security/cve/CVE-2026-8922
    RHBZ#2479586 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2479586 ]
    =C2=A0 Red Hat--Red Hat Build of Keycloak A flaw was found in Keycloak. An = authenticated user can bypass configured WebAuthn policies during credentia=
    l registration by manipulating client-side JavaScript. This occurs because = the server-side processAction() fails to validate that the newly created cr= edential's parameters, such as public key algorithms, match the realm's con= figured WebAuthn policies. This could lead to the creation of credentials t= hat do not adhere to administrative security requirements, potentially weak= ening the overall security posture of the system by allowing non-compliant = authentication methods. 2026-05-19 4.3 CVE-2026-8830 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-8830 ] https://access.redhat.com/security/cve/CVE-2= 026-8830
    RHBZ#2479565 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2479565 ]
    =C2=A0 Red Hat--Red Hat build of Keycloak 26.4 A flaw was found in Keycloak=
    . This access control vulnerability in Keycloak's OpenID Connect (OIDC) tok=
    en introspection endpoint allows a confidential client to bypass audience r= estrictions. An attacker-controlled client with valid credentials can retri= eve sensitive token claims intended for other resource servers, compromisin=
    g the confidentiality of lightweight access tokens. This issue can be explo= ited remotely by any confidential client in the realm with valid credential=
    s. 2026-05-19 6.5 CVE-2026-37979 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-37979 ] RHSA-2026:19596 [ https://access.redhat.com/errata/RHSA-2026:19= 596 ]
    RHSA-2026:19597 [ https://access.redhat.com/errata/RHSA-2026:19597 ] https://access.redhat.com/security/cve/CVE-2026-37979
    RHBZ#2455328 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2455328 ]
    =C2=A0 Red Hat--Red Hat build of Keycloak 26.4 A flaw was found in Keycloak=
    . This authentication vulnerability allows a remote attacker to replay `Exe= cuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authenticati= on) flow. By intercepting an execute-actions email link, an attacker can re= gister their own authenticator to a victim's account. This leads to unautho= rized enrollment of a hardware-backed credential, enabling persistent accou=
    nt takeover. 2026-05-19 6.8 CVE-2026-37982 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-37982 ] RHSA-2026:19596 [ https://access.redhat.com/errata/RH= SA-2026:19596 ]
    RHSA-2026:19597 [ https://access.redhat.com/errata/RHSA-2026:19597 ] https://access.redhat.com/security/cve/CVE-2026-37982
    RHBZ#2455329 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2455329 ]
    =C2=A0 Red Hat--Red Hat build of Keycloak 26.4 A flaw was found in Keycloak=
    . An authenticated client could exploit an Insecure Direct Object Reference=
    (IDOR) vulnerability in the Authorization Services Protection API endpoint=
    . By knowing or obtaining a resource's unique identifier (UUID) belonging t=
    o another Resource Server within the same realm, the client could bypass au= thorization checks. This allows the client to perform unauthorized GET, PUT=
    , and DELETE operations on resources, leading to information disclosure and=
    potential unauthorized modification or deletion of data. 2026-05-19 6.8 CV= E-2026-4630 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4630 ] RHSA-2026:= 19596 [ https://access.redhat.com/errata/RHSA-2026:19596 ]
    RHSA-2026:19597 [ https://access.redhat.com/errata/RHSA-2026:19597 ] https://access.redhat.com/security/cve/CVE-2026-4630
    RHBZ#2450245 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2450245 ]
    =C2=A0 Red Hat--Red Hat build of Keycloak 26.4 A flaw was found in Keycloak=
    . A low-privilege administrator with the 'view-clients' role can exploit th=
    is by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary = user ID (userId) parameter. This vulnerability allows for cross-role person= ally identifiable information (PII) leakage, enabling unauthorized visibili=
    ty into user identities and authorizations across the realm. Exploitation i=
    s possible remotely via network access to the Admin API. 2026-05-19 4.9 CVE= -2026-37978 [ https://www.cve.org/CVERecord?id=3DCVE-2026-37978 ] RHSA-2026= :19596 [ https://access.redhat.com/errata/RHSA-2026:19596 ]
    RHSA-2026:19597 [ https://access.redhat.com/errata/RHSA-2026:19597 ] https://access.redhat.com/security/cve/CVE-2026-37978
    RHBZ#2455327 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2455327 ]
    =C2=A0 Red Hat--Red Hat build of Keycloak 26.4 A flaw was found in Keycloak=
    . A broken access control vulnerability in the Account Resources user looku=
    p endpoint allows a remote authenticated user, who owns at least one User-M= anaged Access (UMA) resource, to enumerate and harvest personally identifia= ble information (PII) for all realm users. By sending crafted requests with=
    arbitrary usernames or email values, the endpoint returns full profile obj= ects for unrelated users. This leads to broad profile-level information dis= closure. 2026-05-19 4.3 CVE-2026-37981 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-37981 ] RHSA-2026:19596 [ https://access.redhat.com/errata/RHSA= -2026:19596 ]
    RHSA-2026:19597 [ https://access.redhat.com/errata/RHSA-2026:19597 ] https://access.redhat.com/security/cve/CVE-2026-37981
    RHBZ#2455326 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2455326 ]
    =C2=A0 Red Hat--Red Hat Enterprise Linux 10 A flaw was found in libsolv. Th=
    is heap buffer overflow vulnerability occurs when a victim processes a spec= ially crafted `.solv` file containing negative size values in the `repo_add= _solv` function. This leads to an undersized memory allocation and a subseq= uent out-of-bounds write. An attacker could exploit this to cause a denial =
    of service (DoS). 2026-05-20 6.5 CVE-2026-9149 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-9149 ] https://access.redhat.com/security/cve/CVE-2026-91=
    49
    RHBZ#2460380 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2460380 ] https://github.com/openSUSE/libsolv/pull/617
    =C2=A0 Red Hat--Red Hat Enterprise Linux 10 A flaw was found in libsolv. Th=
    is stack-based buffer overflow vulnerability occurs in libsolv's Debian met= adata parser when processing specially crafted Debian repository metadata. =
    An attacker could exploit this by providing malicious SHA384 or SHA512 chec= ksum tags, leading to memory corruption and a denial of service (DoS) in th=
    e affected system. 2026-05-20 6.5 CVE-2026-9150 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-9150 ] https://access.redhat.com/security/cve/CVE-2026-9= 150
    RHBZ#2460379 [ https://bugzilla.redhat.com/show_bug.cgi?id=3D2460379 ] https://github.com/openSUSE/libsolv/pull/616
    =C2=A0 registrationformbuilder--Vedrixa Forms User Registration Form, Signu=
    p Form & Drag & Drop Form Builder The Vedrixa Forms - User Registration For=
    m, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerabl=
    e to authorization bypass in all versions up to, and including, 1.1.1. This=
    is due to the plugin not properly verifying that a user is authorized to p= erform an action. This makes it possible for authenticated attackers, with = subscriber-level access and above, to overwrite the structure of any form -=
    adding, removing, or altering fields - by writing attacker-controlled data=
    to the plugin's FORMS database table. The 'ajax-nonce' nonce used by this = handler is injected into the public frontend via wp_localize_script(), so a=
    ny authenticated user who visits a page containing a form shortcode can obt= ain it without any elevated access. 2026-05-22 4.3 CVE-2026-8692 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-8692 ] https://www.wordfence.com/threat= -intel/vulnerabilities/id/1b3b8a6c-1c84-4abe-ad4a-02302b04987b?source=3Dcve https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-build= er/tags/1.1.1/admin/class-registration-form-builder-admin.php#L866 https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-build= er/tags/1.1.1/includes/class-registration-form-builder.php#L174 https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-build= er/tags/1.1.1/public/class-registration-form-builder-public.php#L121 https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-build= er/tags/1.0.0/admin/class-registration-form-builder-admin.php#L866 https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-build= er/tags/1.0.0/includes/class-registration-form-builder.php#L174 https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-build= er/tags/1.0.0/public/class-registration-form-builder-public.php#L121 https://plugins.trac.wordpress.org/changeset?sfp_email=3D&sfph_mail=3D&repo= name=3D&old=3D3540543%40vedrixa-forms-registration-builder&new=3D3540543%40= vedrixa-forms-registration-builder&sfp_email=3D&sfph_mail=3D
    =C2=A0 Revolution Slider--Slider Revolution The Slider Revolution plugin fo=
    r WordPress is vulnerable to Sensitive Information Exposure in versions up = to, and including, 7.0.9 via the 'get_stream_data()' function. This makes i=
    t possible for unauthenticated attackers to extract sensitive data includin=
    g published password-protected post, page, and product content. 2026-05-20 = 5.3 CVE-2026-6728 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6728 ] http= s://www.wordfence.com/threat-intel/vulnerabilities/id/3cd7be2c-9ba9-4d25-89= 07-610898df5834?source=3Dcve
    https://www.sliderrevolution.com/changelog/
    =C2=A0 RsyncProject--rsync Rsync version=C2=A03.4.2 and prior contain symli=
    nk race condition vulnerabilities in path-based system calls including chmo=
    d, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and = lstat that allow local attackers to redirect operations to files outside th=
    e exported rsync module. Attackers with local filesystem access can exploit=
    the timing window between path resolution and syscall execution by swappin=
    g symlinks to apply sender-supplied permissions, ownership, timestamps, or = filenames to arbitrary files outside the intended module boundary on rsync = daemons configured with 'use chroot =3D no'. 2026-05-20 6.3 CVE-2026-43619 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-43619 ] https://github.com/Rs= yncProject/rsync/security/advisories/GHSA-4h9m-w5ff-j735 https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 https://www.vulncheck.com/advisories/rsync-symlink-race-condition-via-path-= based-syscalls
    =C2=A0 RsyncProject--rsync Rsync version=C2=A03.4.2 and prior contain a rec= eiver-side out-of-bounds array read vulnerability in recv_files() in receiv= er.c that allows a malicious rsync server to crash the rsync client process=
    . Attackers can exploit the vulnerability by setting CF_INC_RECURSE in comp= atibility flags and sending a specially crafted file list where the first s= orted entry is not the leading dot directory, followed by a transfer record=
    with ndx=3D0 and an iflag word without ITEM_TRANSFER, causing the receiver=
    to read 8 bytes before the allocated pointer array and dereference an inva= lid pointer at an unmapped address, resulting in a deterministic SIGSEGV cr= ash of the rsync client. 2026-05-20 6.5 CVE-2026-43620 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-43620 ] https://github.com/RsyncProject/rsync/sec= urity/advisories/GHSA-28pw-r563-rxvm https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 https://www.vulncheck.com/advisories/rsync-out-of-bounds-array-read-via-rec= v-files
    =C2=A0 RsyncProject--rsync Rsync version=C2=A03.4.2 and prior contain an au= thorization bypass vulnerability in the rsync daemon's hostname-based acces=
    s control list enforcement when configured with chroot. Attackers can bypas=
    s hostname-based deny rules by controlling the PTR record for their source =
    IP address, allowing connections from hostnames that administrators intende=
    d to deny when reverse DNS resolution fails and defaults to UNKNOWN. 2026-0= 5-20 4.8 CVE-2026-43617 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43617=
    ] https://github.com/RsyncProject/rsync/security/advisories/GHSA-rjfm-3w2m= -jf4f
    https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 https://www.vulncheck.com/advisories/rsync-authorization-bypass-via-hostnam= e-resolution
    =C2=A0 Samsung Open Source--Escargot Uncontrolled Recursion vulnerability i=
    n Samsung Open Source Escargot allows Oversized Serialized Data Payloads. T= his issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. 2026-= 05-19 5.5 CVE-2026-47309 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4730=
    9 ] https://github.com/Samsung/escargot/pull/1565
    =C2=A0 Samsung Open Source--Escargot Release of invalid pointer or referenc=
    e vulnerability in Samsung Open Source Escargot allows Buffer Manipulation.=
    This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. 202= 6-05-19 5.5 CVE-2026-47312 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47= 312 ] https://github.com/Samsung/escargot/pull/1565
    =C2=A0 Samsung Open Source--Escargot Memory allocation with excessive size = value vulnerability in Samsung Open Source Escargot allows Excessive Alloca= tion. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3=
    . 2026-05-19 5.5 CVE-2026-47313 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-47313 ] https://github.com/Samsung/escargot/pull/1565
    =C2=A0 Samsung Open Source--Escargot Improper Check for Unusual or Exceptio= nal Conditions vulnerability in Samsung Open Source Escargot allows Input D= ata Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce= 6baaf2afc2d3. 2026-05-19 5.5 CVE-2026-47315 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-47315 ] https://github.com/Samsung/escargot/pull/1565
    =C2=A0 Samsung Open Source--Escargot Improper Check or Handling of Exceptio= nal Conditions vulnerability in Samsung Open Source Escargot allows Input D= ata Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce= 6baaf2afc2d3. 2026-05-19 5.5 CVE-2026-47316 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-47316 ] https://github.com/Samsung/escargot/pull/1565
    =C2=A0 Samsung Open Source--Escargot Uncontrolled Recursion vulnerability i=
    n Samsung Open Source Escargot allows Excessive Allocation. This issue affe= cts Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. 2026-05-19 5.5 CVE-= 2026-47317 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47317 ] https://gi= thub.com/Samsung/escargot/pull/1565
    =C2=A0 Samsung Open Source--Walrus NULL pointer dereference vulnerability i=
    n Samsung Open Source Walrus allows an attacker to cause a denial of servic=
    e via a crafted WebAssembly module containing deeply nested instructions. T= his issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9. 2026-05= -19 5.5 CVE-2026-47307 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47307 =
    ] https://github.com/Samsung/walrus/pull/409
    =C2=A0 Samsung Open Source--Walrus NULL pointer dereference vulnerability i=
    n Samsung Open Source Walrus allows Pointer Manipulation. This issue affect=
    s Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9. 2026-05-19 5.5 CVE-2026= -47308 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47308 ] https://github= .com/Samsung/walrus/pull/409
    =C2=A0 shapedplugin--Location Weather WordPress Weather Forecast, AQI, Temp= erature and Weather Widget The Location Weather plugin for WordPress is vul= nerable to unauthorized modification of data due to missing capability chec=
    ks on the `splw_update_block_options()` and `lwp_clean_weather_transients()=
    ` functions in all versions up to, and including, 3.0.2. This makes it poss= ible for authenticated attackers, with Contributor-level access and above, =
    to disable all weather blocks and purge all weather cache transients. The n= once required for these actions is exposed to all authenticated users via `= wp_localize_script()` on the `init` hook. 2026-05-22 4.3 CVE-2026-7249 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-7249 ] https://www.wordfence.com/= threat-intel/vulnerabilities/id/d472011d-1623-4791-9d56-715d90fe0469?source= =3Dcve https://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.2/incl= udes/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L256 https://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.2/incl= udes/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L331 https://wordpress.org/plugins/location-weather/ https://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.3/incl= udes/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L256 https://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.3/incl= udes/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L332
    =C2=A0 Significant-Gravitas--AutoGPT AutoGPT is a workflow automation platf= orm for creating, deploying, and managing continuous artificial intelligenc=
    e agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platf= orm/backend/backend/blocks/email_block.py accepts a user-supplied smtp_serv=
    er (string) and smtp_port (integer) as per-execution block inputs, then pas= ses them directly to Python's smtplib.SMTP() to open a raw TCP connection w= ith no IP address validation. This completely bypasses the platform's harde= ned SSRF protections in backend/util/request.py - the validate_url_host() f= unction and BLOCKED_IP_NETWORKS blocklist that every other block uses to bl= ock connections to private, loopback, link-local, and cloud metadata addres= ses. An authenticated user on a shared AutoGPT deployment can use this to p= erform non-blind internal network port scanning and service fingerprinting:=
    smtplib reads the target's TCP banner on connect and embeds it in the exce= ption message, which is persisted as user-visible block output via the exec= ution framework. This issue has been fixed in version 0.6.52. 2026-05-19 5 = CVE-2026-33234 [ https://www.cve.org/CVERecord?id=3DCVE-2026-33234 ] https:= //github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-4jwj-6mg= 5-wrwf https://github.com/Significant-Gravitas/AutoGPT/releases/tag/autogpt-platfo= rm-beta-v0.6.52
    =C2=A0 simonholliday--Anomify AI Anomaly Detection and Alerting The Anomify=
    AI - Anomaly Detection and Alerting plugin for WordPress is vulnerable to = Stored Cross-Site Scripting via the 'anomify_api_key' parameter in versions=
    up to and including 0.3.6. This is due to insufficient input sanitization = and missing output escaping: the plugin applies sanitize_text_field() to th=
    e Metric Data Key input before saving it via update_option(), but sanitize_= text_field() strips HTML tags without encoding double-quote characters, and=
    the value is then echoed directly into an HTML attribute context (value=3D= "...") without esc_attr(). This makes it possible for authenticated attacke=
    rs with administrator-level access to inject arbitrary web scripts that exe= cute whenever a user visits the plugin's settings page. 2026-05-20 4.4 CVE-= 2026-6404 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6404 ] https://www.= wordfence.com/threat-intel/vulnerabilities/id/4036057c-0c43-4d9c-97db-4861d= 91a4daa?source=3Dcve https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Wp/include= s/admin_options.php#L43 https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/in= cludes/admin_options.php#L43 https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Wp/Admin.p= hp#L32 https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/Ad= min.php#L32 https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Config.php= #L152 https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Confi= g.php#L152
    =C2=A0 simonholliday--Anomify AI Anomaly Detection and Alerting The Anomify=
    AI - Anomaly Detection and Alerting plugin for WordPress is vulnerable to = Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (X= SS) in versions up to and including 0.3.6. This is due to missing nonce ver= ification on the settings page handler and insufficient output escaping in = the admin_options.php template. The settings form includes no wp_nonce_fiel= d() and the handler performs no check_admin_referer() check, meaning any cr= oss-origin POST can modify plugin settings. The API key field is sanitized = only with sanitize_text_field(), which strips HTML tags but does not encode=
    double-quote characters; the value is then rendered into an HTML attribute=
    via bare echo without esc_attr(), allowing a double-quote attribute-escape=
    payload to survive both sanitization and storage. This makes it possible f=
    or unauthenticated attackers to inject arbitrary web scripts by tricking a = logged-in administrator into visiting a malicious page that submits a forge=
    d request, storing the payload in the database and causing it to execute in=
    the administrator's browser whenever the plugin settings page is visited. = 2026-05-20 4.3 CVE-2026-6405 [ https://www.cve.org/CVERecord?id=3DCVE-2026-= 6405 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e02c2d-a= 38a-495c-9c37-098049297be2?source=3Dcve https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Wp/include= s/admin_options.php#L43 https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/in= cludes/admin_options.php#L43 https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Wp/Admin.p= hp#L31 https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/Ad= min.php#L31 https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Config.php= #L152 https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Confi= g.php#L152
    =C2=A0 smub--All in One SEO Powerful SEO Plugin to Boost SEO Rankings & Inc= rease Traffic The All in One SEO plugin for WordPress is vulnerable to Sens= itive Information Exposure via 'internalOptions' localized script data in v= ersions up to, and including, 4.9.7 due to sensitive internal option data b= eing passed to wp_localize_script() in post editor contexts without effecti=
    ve masking for low-privilege users. This makes it possible for authenticate=
    d attackers, with contributor-level access and above, to view configured AP= I/OAuth tokens and license-related values from page source. 2026-05-20 4.3 = CVE-2026-5075 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5075 ] https://= www.wordfence.com/threat-intel/vulnerabilities/id/0d8bc203-c17a-4b31-8f9e-6= 95f9e638cda?source=3Dcve https://plugins.trac.wordpress.org/changeset/3532318/all-in-one-seo-pack
    =C2=A0 smub--Photo Gallery, Sliders, Proofing and Themes NextGEN Gallery Th=
    e Photo Gallery, Sliders, Proofing and Themes - NextGEN Gallery plugin for = WordPress is vulnerable to Insecure Direct Object Reference in versions up =
    to and including 4.2.0. This is due to insufficient object-level authorizat= ion in the image deletion REST flow where the permission callback for DELET=
    E /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions = and does not enforce gallery ownership or 'NextGEN Manage others gallery' p= ermissions. This makes it possible for authenticated attackers, with Subscr= iber-level privileges and 'NextGEN Manage gallery' capability, to delete ga= llery images belonging to other users as well as their associated image fil=
    es from disk when deleteImg is enabled (default). 2026-05-20 4.3 CVE-2026-6= 566 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6566 ] https://www.wordfe= nce.com/threat-intel/vulnerabilities/id/439809ad-21ea-4a0b-b1fd-5de9f8f5ee7= a?source=3Dcve https://plugins.trac.wordpress.org/changeset/3533432/nextgen-gallery
    =C2=A0 smub--Slider by Soliloquy Responsive Image Slider for WordPress The = Slider by Soliloquy - Responsive Image Slider for WordPress plugin for Word= Press is vulnerable to Sensitive Information Exposure in all versions up to=
    , and including, 2.8.1 via the map_meta_cap. This makes it possible for aut= henticated attackers, with subscriber-level access and above, to extract dr= aft slider metadata including unpublished media URLs, captions, and slider = configuration authored by administrators or editors. 2026-05-22 4.3 CVE-202= 6-7636 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7636 ] https://www.wor= dfence.com/threat-intel/vulnerabilities/id/54115a9a-dadd-4f18-a139-02ec89f0= a571?source=3Dcve https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/gl= obal/posttype.php#L90 https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/gl= obal/posttype.php#L177 https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/includ= es/global/posttype.php#L177 https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/gl= obal/posttype.php#L125 https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/includ= es/global/posttype.php#L125 https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/includ= es/global/posttype.php#L90 https://plugins.trac.wordpress.org/changeset/3538404/soliloquy-lite/trunk/i= ncludes/global/posttype.php?old=3D3395148&old_path=3Dsoliloquy-lite%2Ftrunk= %2Fincludes%2Fglobal%2Fposttype.php
    =C2=A0 SourceCodester--Hospitals Patient Records Management System A securi=
    ty flaw has been discovered in SourceCodester Hospitals Patient Records Man= agement System 1.0. Impacted is an unknown function of the file /admin/pati= ents/view_history.php. The manipulation of the argument ID results in sql i= njection. The attack may be launched remotely. The exploit has been release=
    d to the public and may be used for attacks. 2026-05-23 6.3 CVE-2026-9342 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-9342 ] VDB-365305 | SourceCode= ster Hospitals Patient Records Management System view_history.php sql injec= tion [ https://vuldb.com/vuln/365305 ]
    VDB-365305 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65305/cti ]
    Submit #812834 | sourcecodester Hospital's Patient Records Management Syste=
    m V1.0 SQL injection [ https://vuldb.com/submit/812834 ] https://github.com/july-skyload/exp/issues/1
    https://www.sourcecodester.com/
    =C2=A0 Splunk--Splunk AI Toolkit In Splunk AI Toolkit versions below 5.7.3,=
    a low-privileged user that does not hold the 'admin' or 'power' roles coul=
    d access confidential data that was restricted through `srchFilter` configu= rations on custom roles.<br><br>The app contains an `authorize.conf` config= uration file with a `srchFilter` entry that modifies the built-in 'user' ro= le. Because the Splunk platform combines inherited search filters with the = `OR` SPL operator, the injected filter overrides more restrictive filters o=
    n child roles. 2026-05-20 6.5 CVE-2026-20238 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-20238 ] https://advisory.splunk.com/advisories/SVD-2026-0502 =C2=A0 steipete--summarize Summarize prior to 0.15.1 contains a missing aut= horization vulnerability in the content script window.postMessage bridge th=
    at allows malicious pages to perform unauthorized operations on automation = artifacts. Attackers can simulate runtime messages with spoofed sender iden= tifiers to list, read, create, overwrite, or delete automation artifacts sc= oped to the affected tab without proper authorization checks. 2026-05-18 6.=
    1 CVE-2026-45243 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45243 ] http= s://github.com/steipete/summarize/releases/tag/v0.15.2 https://github.com/steipete/summarize/pull/222 https://github.com/steipete/summarize/commit/357544063af535bd574752622f9eb9= 4be33ee5fd https://www.vulncheck.com/advisories/summarize-browser-extension-missing-au= thorization-via-content-script
    =C2=A0 steipete--summarize Summarize prior to 0.15.1 contains a missing aut= horization vulnerability that allows attackers to execute browser automatio=
    n actions without per-call user approval when the extension automation feat= ure is enabled. Attackers can influence the agent through malicious page or=
    summary content to invoke enabled extension automation tools such as navig= ation or debugger-backed actions, bypassing the final user approval step wh=
    en a user interacts with attacker-controlled content. 2026-05-18 5.4 CVE-20= 26-45244 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45244 ] https://gith= ub.com/steipete/summarize/releases/tag/v0.15.2 https://github.com/steipete/summarize/pull/219 https://github.com/steipete/summarize/commit/e64fe3ecd1bb4fdc181dcfa88c96b9= e1914ced0e https://www.vulncheck.com/advisories/summarize-unapproved-browser-automatio= n-execution
    =C2=A0 steipete--summarize Summarize prior to 0.15.1 contains an insecure f= ile permission vulnerability in the refresh-free configuration rewrite path=
    that allows local users to read sensitive credentials by exploiting defaul=
    t filesystem permissions. When the refresh-free path rewrites the configura= tion file, it creates the replacement with default process umask permission=
    s instead of preserving the original file permissions, exposing the config = file containing API keys and provider credentials to other local users on s= hared Unix-like systems. 2026-05-18 5.5 CVE-2026-45246 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-45246 ] https://github.com/steipete/summarize/rel= eases/tag/v0.15.2
    https://github.com/steipete/summarize/pull/217 https://github.com/steipete/summarize/commit/9e990193650a23dab73f37d5e1964d= 574a44098b https://www.vulncheck.com/advisories/summarize-insecure-file-permissions-in= formation-disclosure
    =C2=A0 storybookjs--telejson TeleJSON prior to 6.0.0 contains a DOM-based c= ross-site scripting vulnerability in the parse() function that allows attac= kers to execute arbitrary JavaScript by delivering a crafted JSON payload c= ontaining a malicious _constructor-name_ property value. The custom reviver=
    passes the constructor name directly to new Function() without sanitizatio=
    n when recreating object prototypes, enabling attackers to inject arbitrary=
    JavaScript through vectors such as postMessage in cross-frame communicatio=
    n contexts to achieve script execution within the application. 2026-05-20 6=
    .1 CVE-2026-47099 [ https://www.cve.org/CVERecord?id=3DCVE-2026-47099 ] htt= ps://github.com/storybookjs/telejson/security/advisories/GHSA-ccgf-5rwj-j3hv https://github.com/Niccolo10/Security-Advisories/blob/main/CVE-2026-47099/c= ve-2026-47099.md https://www.vulncheck.com/advisories/telejson-dom-based-xss-via-parse-funct= ion
    =C2=A0 strukturag--libheif libheif is a HEIF and AVIF file format decoder a=
    nd encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence = file with samples_per_chunk=3D0 in the stsc box causes an unsigned integer = underflow in the Chunk constructor (m_last_sample =3D 0 + 0 - 1 =3D UINT32_= MAX), mapping all samples to an empty chunk and resulting in a denial of se= rvice. When any sample is accessed, the library reads from index 0 of an em= pty std::vector, causing a guaranteed SEGV (null-page read). The file parse=
    s successfully without producing an error; the crash occurs on the first fr= ame access. This issue has been fixed in version 1.22.0. 2026-05-19 6.5 CVE= -2026-32738 [ https://www.cve.org/CVERecord?id=3DCVE-2026-32738 ] https://g= ithub.com/strukturag/libheif/security/advisories/GHSA-7f2h-cmpf-v9ww
    =C2=A0 strukturag--libheif libheif is a HEIF and AVIF file format decoder a=
    nd encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence = file causes an infinite loop in Box_stts::get_sample_duration(), consuming = 100% CPU indefinitely with zero progress, leading to DoS. The loop has no i= teration limit or timeout and is triggered during file open (parsing) - bef= ore any user interaction or image decoding. The process stays alive (no cra= sh, no error logged), making it invisible to crash-based monitoring. This i= ssue has been fixed in version 1.22.0. 2026-05-19 6.5 CVE-2026-32739 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-32739 ] https://github.com/struktur= ag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c https://github.com/strukturag/libheif/releases/tag/v1.22.0
    =C2=A0 strukturag--libheif libheif is a HEIF and AVIF file format decoder a=
    nd encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image w= ith strict_decoding=3Dfalse (the default), a corrupted tile silently fails =
    to decode and the library returns heif_error_Ok with no indication of failu= re, leading to an uninitialized heap memory information leak. The canvas is=
    allocated via create_clone_image_at_new_size() =C3=A2=E2=80=A0=E2=80=99 pl= ane.alloc() =C3=A2=E2=80=A0=E2=80=99 new (std::nothrow) uint8_t[allocation_= size] which does not zero the memory; only the alpha plane is explicitly in= itialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever wa=
    s previously at that heap address. The failed tile's region of the canvas i=
    s never written. It retains uninitialized heap data that is delivered to th=
    e caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane =3D 12,288+=
    bytes total). Any application using libheif to decode grid-based HEIF/AVIF=
    files with default settings is vulnerable: a crafted .heic or .avif file c= auses 4,096+ bytes of heap memory to appear as pixel values in the decoded = image, and the calling application receives heif_error_Ok, so it has no ind= ication the output contains heap garbage. In server-side image processing, =
    an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thum= bnails, CDN, social media) can leak cross-user data such as auth tokens, da= tabase results, and other users' image data. This issue has been fixed in v= ersion 1.22.0. 2026-05-19 6.5 CVE-2026-32814 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-32814 ] https://github.com/strukturag/libheif/security/advi= sories/GHSA-4m8r-34pg-rvwc https://github.com/strukturag/libheif/releases/tag/v1.22.0
    =C2=A0 strukturag--libheif libheif is a HEIF and AVIF file format decoder a=
    nd encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file ca=
    n trigger an out-of-bounds read in core sequence parsing logic, causing DoS=
    . A malformed file can have stco.entry_count =3D=3D 0 (creating no chunks) = while still passing validation because saio.entry_count =3D=3D 0 matches, b=
    ut with saiz.sample_count > 0 the SampleAuxInfoReader constructor still ent= ers its loop. This leads to an out-of-bounds dereference on the empty chunk= s[0] in chunked mode. 2026-05-22 6.5 CVE-2026-41069 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-41069 ] https://github.com/strukturag/libheif/securi= ty/advisories/GHSA-p82x-fpmv-576r https://github.com/strukturag/libheif/releases/tag/v1.22.0
    =C2=A0 submone--Amazon Scraper The Amazon Scraper plugin for WordPress is v= ulnerable to Cross-Site Request Forgery in all versions up to, and includin=
    g, 1.1. This is due to missing or incorrect nonce validation on a function.=
    This makes it possible for unauthenticated attackers to update settings an=
    d inject malicious web scripts via a forged request granted they can trick =
    a site administrator into performing an action such as clicking on a link. = 2026-05-20 4.3 CVE-2026-8419 [ https://www.cve.org/CVERecord?id=3DCVE-2026-= 8419 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/c956e4c5-b= f7e-4ec4-b795-74d477a61694?source=3Dcve https://plugins.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admi= n.php#L49 https://plugins.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-a= dmin.php#L49 https://plugins.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admi= n.php#L13 https://plugins.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-a= dmin.php#L13 https://plugins.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admi= n.php#L26 https://plugins.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-a= dmin.php#L26 https://plugins.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admi= n.php#L45 https://plugins.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-a= dmin.php#L45
    =C2=A0 svil4ok--Bottom Bar The Bottom Bar plugin for WordPress is vulnerabl=
    e to Cross-Site Request Forgery in all versions up to and including 0.1.7. = This is due to missing nonce verification on the plugin's settings update f= orms handled in bottom-bar-admin.php. None of the three settings forms (mai=
    n settings, sharing services, restore defaults) include a wp_nonce_field(),=
    and the server-side processing code never calls check_admin_referer() or a=
    ny equivalent nonce validation before processing POST data and calling upda= te_option(). This makes it possible for unauthenticated attackers to trick =
    a logged-in administrator into submitting a crafted request that updates pl= ugin configuration options, such as changing the language, maximum post cou= nts, or enabled sharing services. 2026-05-20 4.3 CVE-2026-6401 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-6401 ] https://www.wordfence.com/threat-i= ntel/vulnerabilities/id/db0715ed-a06e-4a68-b9c3-408887cae113?source=3Dcve https://plugins.trac.wordpress.org/browser/bottom-bar/trunk/bottom-bar-admi= n.php#L16 https://plugins.trac.wordpress.org/browser/bottom-bar/tags/0.1.7/bottom-bar= -admin.php#L16 https://plugins.trac.wordpress.org/browser/bottom-bar/trunk/bottom-bar-admi= n.php#L59 https://plugins.trac.wordpress.org/browser/bottom-bar/tags/0.1.7/bottom-bar= -admin.php#L59
    =C2=A0 syslink software AG--Avantra Use of default password vulnerability i=
    n syslink software AG Avantra on Linux, Windows allows Try Common or Defaul=
    t Usernames and Passwords. This issue affects Avantra: before 25.3.0. 2026-= 05-22 5.1 CVE-2026-8672 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8672 =
    ] https://support.avantra.com/hc/en-us/articles/5535551609759
    =C2=A0 syslink software AG--Avantra Unprotected transport of credentials vu= lnerability in syslink software AG Avantra on Linux, Windows allows Sniffin=
    g Attacks. This issue affects Avantra: before 25.3.0. 2026-05-22 5.9 CVE-20= 26-8673 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8673 ] https://suppor= t.avantra.com/hc/en-us/articles/5535621927071
    =C2=A0 Talend--Talend Administration Center A stored cross-site scripting v= ulnerability has been found in the Talend Administration Center. An attacke=
    r with permission to manage servers can store a XSS payload that can be tri= ggered by a different user. 2026-05-20 5.4 CVE-2026-9056 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-9056 ] https://community.qlik.com/t5/Official-S= upport-Articles/Security-fix-for-Qlik-Talend-Administration-Center-cross-si= te/ta-p/2548522
    =C2=A0 TeamViewer--DEX (On-premises) A broken access control vulnerability = exists in the TeamViewer DEX Platform (On=C3=A2=E2=82=AC=E2=80=98Premises) = prior version 9.2. Certain backend API endpoints do not correctly enforce a= uthorization checks, allowing an authenticated user with low privileges to = perform actions and access resources intended only for higher=C3=A2=E2=82= =AC=E2=80=98privileged roles.=C2=A0An attacker with low=C3=A2=E2=82=AC=E2= =80=98privileged credentials may exploit this to gain unauthorized access t=
    o administrative or sensitive functionality. 2026-05-22 5.4 CVE-2026-8381 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-8381 ] https://www.teamviewer.= com/en/resources/trust-center/security-bulletins/tv-2026-1005/
    =C2=A0 techjewel--FluentCRM Email Newsletter, Automation, Email Marketing, = Email Campaigns, Optins, Leads, and CRM Solution The FluentCRM - Email News= letter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CR=
    M Solution plugin for WordPress is vulnerable to Blind Server-Side Request = Forgery in all versions up to, and including, 2.9.87 via the 'SubscribeURL'=
    parameter. This makes it possible for unauthenticated attackers to make we=
    b requests to arbitrary locations originating from the web application and = can be used to query and modify information from internal services. Exploit= ation requires that the SES bounce handling key ('_fc_bounce_key') has neve=
    r been stored (i.e., the site is in its default/unconfigured state with res= pect to SES bounce handling) as visiting the bounce configuration page auto= -generates and stores a random key that causes the authentication check to = evaluate correctly and reject unauthenticated requests. 2026-05-22 5.4 CVE-= 2026-7798 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7798 ] https://www.= wordfence.com/threat-intel/vulnerabilities/id/5c3ca2d7-7af9-401f-bc5a-1796c= 6253cb0?source=3Dcve https://plugins.trac.wordpress.org/browser/fluent-crm/trunk/app/Hooks/Handl= ers/ExternalPages.php#L113 https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.9.87/app/Hooks= /Handlers/ExternalPages.php#L113 https://plugins.trac.wordpress.org/browser/fluent-crm/trunk/app/Hooks/Handl= ers/ExternalPages.php#L85 https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.9.87/app/Hooks= /Handlers/ExternalPages.php#L85 https://plugins.trac.wordpress.org/browser/fluent-crm/trunk/app/Hooks/Handl= ers/ExternalPages.php#L87 https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.9.87/app/Hooks= /Handlers/ExternalPages.php#L87 https://plugins.trac.wordpress.org/changeset?sfp_email=3D&sfph_mail=3D&repo= name=3D&old=3D3532271%40fluent-crm&new=3D3532271%40fluent-crm&sfp_email=3D&= sfph_mail=3D
    =C2=A0 Technitium--DNS Server Technitium DNS Server aggressively tries to f= etch missing RRSIG records or mismatched DNSKEY records. An attacker in con= trol of a domain can cause a vulnerable system to generate excessive networ=
    k traffic. Fixed in 15.0. 2026-05-19 5.8 CVE-2026-45557 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-45557 ] url [ https://github.com/TechnitiumSoftw= are/DnsServer/blo/master/CHANGELOG.md#version-150 ]
    url [ https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/= white/2025/va-26-138-02.json ]
    url [ https://www.cve.org/CVERecord?id=3DCVE-2026-45557 ]
    =C2=A0 Tencent--WeKnora A vulnerability has been found in Tencent WeKnora u=
    p to 0.3.6. Affected by this issue is the function getKnowledgeBaseForIniti= alization of the file internal/handler/initialization.go of the component C= onfig API Endpoint. The manipulation of the argument kbId leads to authoriz= ation bypass. It is possible to initiate the attack remotely. The exploit h=
    as been disclosed to the public and may be used. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-05-18 6.3 C= VE-2026-8786 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8786 ] VDB-36441=
    0 | Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseF= orInitialization authorization [ https://vuldb.com/vuln/364410 ]
    VDB-364410 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/364410= /cti ]
    Submit #812172 | Tencent WeKnora <=3D v0.3.6 Insecure Direct Object Referen=
    ce (CWE-639) [ https://vuldb.com/submit/812172 ] https://gist.github.com/YLChen-007/1cdc50418f29af7ae671466425e52c7b
    =C2=A0 themefusion--Avada (Fusion) Builder The Avada (Fusion) Builder plugi=
    n for WordPress is vulnerable to Stored Cross-Site Scripting via multiple s= hortcodes in all versions up to, and including, 3.15.2 due to insufficient = input sanitization and output escaping. This makes it possible for authenti= cated attackers, with Subscriber-level access and above, to inject arbitrar=
    y web scripts in pages that will execute whenever a user (typically an admi= nistrator) accesses a page displaying dynamic user data (such as via the Dy= namic Data feature pulling user biographical information). 2026-05-21 6.4 C= VE-2026-1543 [ https://www.cve.org/CVERecord?id=3DCVE-2026-1543 ] https://w= ww.wordfence.com/threat-intel/vulnerabilities/id/72a6b040-ed02-4561-82f2-4a= db820bdf7d?source=3Dcve https://themeforest.net/item/avada-responsive-multipurpose-theme/2833226 https://avada.com/documentation/avada-changelog/
    =C2=A0 Themeisle--Visualizer Improper Neutralization of Input During Web Pa=
    ge Generation ('Cross-site Scripting') vulnerability in Themeisle Visualize=
    r allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0. = 2026-05-20 6.5 CVE-2026-24573 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -24573 ] https://patchstack.com/database/wordpress/plugin/visualizer/vulner= ability/wordpress-visualizer-plugin-4-0-0-cross-site-scripting-xss-vulnerab= ility?_s_id=3Dcve
    =C2=A0 themeum--Kirki Freeform Page Builder, Website Builder & Customizer T=
    he Kirki - Freeform Page Builder, Website Builder & Customizer plugin for W= ordPress is vulnerable to authorization bypass in all versions up to, and i= ncluding, 6.0.6. This is due to the plugin not properly verifying that a us=
    er is authorized to perform an action. This makes it possible for authentic= ated attackers, with subscriber-level access and above, to view all Kirki f= rontend forms and read stored visitor form submission data, including conta=
    ct details, messages, and any other visitor-provided information submitted = through site forms. 2026-05-19 6.5 CVE-2026-8096 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-8096 ] https://www.wordfence.com/threat-intel/vulnerabi= lities/id/1a4414b1-6a49-42f8-9927-93763d1502ce?source=3Dcve https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.4/includes/Ajax.p= hp#L675
    https://plugins.trac.wordpress.org/changeset/3535640/kirki
    =C2=A0 Tobias--CF7 WOW Styler Missing Authorization vulnerability in Tobias=
    CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Sec= urity Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6. 20= 26-05-21 5.3 CVE-2026-27393 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2= 7393 ] https://patchstack.com/database/wordpress/plugin/cf7-styler/vulnerab= ility/wordpress-cf7-wow-styler-plugin-1-7-6-broken-access-control-vulnerabi= lity?_s_id=3Dcve
    =C2=A0 Trend Micro, Inc.--TrendAI Apex One A directory traversal vulnerabil= ity in the Apex One (on-premise) server could allow a pre-authenticated loc=
    al attacker to modify a key table on the server to inject malicious code to=
    deploy to agents on affected installations. This vulnerability is only exp= loitable on the on-premise version of Apex One and a potential attacker mus=
    t have access to the Apex One Server and already obtained administrative cr= edentials to the server via some other method to exploit this vulnerability=
    . 2026-05-21 6.7 CVE-2026-34926 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-34926 ] https://success.trendmicro.com/en-US/solution/KA-0023430 https://success.trendmicro.com/ja-JP/solution/KA-0022974 https://jvn.jp/en/vu/JVNVU90583059/ https://www.jpcert.or.jp/english/at/2026/at260014.html
    =C2=A0 TriliumNext--Trilium Trilium Notes is an open-source, cross-platform=
    hierarchical note taking application for building large personal knowledge=
    bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, = allowing an authenticated attacker to read sensitive arbitrary files from t=
    he server's filesystem. The uploadModifiedFileToAttachment function, which =
    is called when a POST request is received to /api/attachments/{attachmentId= }/upload-modified-file, replaces the content of the attachment with the con= tent from another file (whose path is provided in filePath of Request body)=
    . After which the content of the attachment can be viewed at /api/attachmen= ts/{attachmentId}/download. This exposes sensitive system files such as SSH=
    keys, credentials, configs, and OS files, potentially leading to remote co=
    de execution and compromise of co-hosted applications. This issue has been = fixed in version 0.102.2. 2026-05-19 6.8 CVE-2026-35593 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-35593 ] https://github.com/TriliumNext/Trilium/s= ecurity/advisories/GHSA-hf4x-22rg-pjjp https://github.com/TriliumNext/Trilium/releases/tag/v0.102.2
    =C2=A0 TriliumNext--Trilium Trilium Notes is a cross-platform, hierarchical=
    note taking application focused on building large personal knowledge bases=
    . Versions 0.102.1 and prior contain a critical security flaw where lack of=
    SVG sanitization combined with a disabled Content Security Policy (CSP) an=
    d a publicly reachable backend execution API results in an unauthenticated = Remote Code Execution (RCE). The vulnerability arises from an insecure-by-d= esign architecture: Trilium serves SVG attachments with the image/svg+xml M= IME type without any sanitization, and it explicitly disables Helmet's Cont= ent Security Policy middleware, removing the primary defense against script=
    execution in served assets. Because the malicious SVG runs under the Same-= Origin Policy, it can issue a fetch('/') to extract the csrfToken from the = document body. With that token, it can send a signed request to /api/script= /exec to execute arbitrary Node.js code on the server. An attacker can comp= romise the entire server instance simply by tricking an authenticated user = into viewing a shared SVG attachment. The issue has been fixed in version 0= .102.2. 2026-05-20 6.8 CVE-2026-39311 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-39311 ] https://github.com/TriliumNext/Trilium/security/advisories= /GHSA-p837-cxw3-m964 https://github.com/TriliumNext/Trilium/releases/tag/v0.102.2
    =C2=A0 TriliumNext--Trilium Trilium Notes is a cross-platform, hierarchical=
    note taking application focused on building large personal knowledge bases=
    . In versions 0.102.1 and prior, the Electron configuration is vulnerable t=
    o TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misle= ading macOS permission prompts by running malicious code under the identity=
    of the trusted app. The root cause is that the RunAsNode fuse allows launc= hing the app in a special Node.js mode using -e to execute arbitrary system=
    commands with Trilium Notes's permissions and identity. An attacker can le= verage this through a subprocess to request any sensitive permissions, such=
    as access to hardware (camera, microphone) and TCC-protected files, causin=
    g the TCC system prompt to appear as if the request came from Trilium rathe=
    r than the attacker's code, because macOS treats the subprocess as part of = the parent application. Exploitation allows access to TCC-protected resourc=
    es like the screen, camera, microphone, and folders such as ~/Documents and=
    ~/Downloads, undermining macOS's security model and UI integrity through s= ocial engineering. This issue has been fixed in version 0.102.2. 2026-05-19=
    5.5 CVE-2026-39309 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39309 ] h= ttps://github.com/TriliumNext/Trilium/security/advisories/GHSA-66pm-8hvq-2w=
    wx
    https://github.com/TriliumNext/Trilium/releases/tag/v0.102.2
    =C2=A0 Turkiye Electricity Transmission Corporation (TEA)--Mobile Applicati=
    on Improper restriction of excessive authentication attempts vulnerability =
    in Turkiye Electricity Transmission Corporation (TE=C3=84=C2=B0A=C3=85=C5=
    =BE) Mobile Application allows Brute Force. This issue affects Mobile Appli= cation: from 1.6.2 before 1.13. 2026-05-21 6.3 CVE-2026-1816 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-1816 ] https://siberguvenlik.gov.tr/guvenli= k-bildirimleri/detay/tr-26-0286
    =C2=A0 Turkiye Electricity Transmission Corporation (TEA)--Mobile Applicati=
    on Insufficient session expiration vulnerability in Turkiye Electricity Tra= nsmission Corporation (TE=C3=84=C2=B0A=C3=85=C5=BE) Mobile Application allo=
    ws Session Hijacking. This issue affects Mobile Application: from 1.6.2 bef= ore 1.13. 2026-05-21 5.7 CVE-2026-1815 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-1815 ] https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay= /tr-26-0286
    =C2=A0 UserSpice--userSpice userSpice 4.3.24 contains a cross-site scriptin=
    g vulnerability that allows attackers to inject malicious scripts through t=
    he X-Forwarded-For HTTP header. Attackers can send crafted requests to the = backup.php endpoint with XSS payloads in the X-Forwarded-For header that ex= ecute when administrators visit the audit log page. 2026-05-23 6.1 CVE-2018= -25349 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25349 ] ExploitDB-4487=
    1 [ https://www.exploit-db.com/exploits/44871 ]
    VulnCheck Advisory: userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-F=
    or Header [ https://www.vulncheck.com/advisories/userspice-cross-site-scrip= ting-via-x-forwarded-for-header ]
    =C2=A0 vatanyazilim--VatanSMS WP SMS The VatanSMS WP SMS plugin for WordPre=
    ss is vulnerable to Reflected Cross-Site Scripting via the `page` parameter=
    in all versions up to, and including, 1.01. This is due to insufficient in= put sanitization and output escaping. This makes it possible for unauthenti= cated attackers to inject arbitrary web scripts in pages that execute if th=
    ey can successfully trick an administrator into performing an action such a=
    s clicking on a link. 2026-05-20 6.1 CVE-2026-7462 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-7462 ] https://www.wordfence.com/threat-intel/vulnera= bilities/id/96ef8459-1600-4ca0-93c6-0ee42f8adabd?source=3Dcve https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includ= es/admin/groups/groups.php#L34 https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includ= es/admin/outbox/outbox.php#L5 https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includ= es/admin/subscribers/subscribers.php#L128
    =C2=A0 VillaTheme--HAPPY Missing Authorization vulnerability in VillaTheme = HAPPY allows Exploiting Incorrectly Configured Access Control Security Leve= ls. This issue affects HAPPY: from n/a through 1.0.10. 2026-05-21 6.5 CVE-2= 026-39593 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39593 ] https://pat= chstack.com/database/wordpress/plugin/happy-helpdesk-support-ticket-system/= vulnerability/wordpress-happy-plugin-1-0-10-broken-access-control-vulnerabi= lity?_s_id=3Dcve
    =C2=A0 Webmin--Webmin Webmin before 2.641 contains a stored cross-site scri= pting vulnerability in the email template description field of the System a=
    nd Server Status module that allows low-privileged authenticated attackers =
    to execute arbitrary JavaScript in the browser context of administrators by=
    injecting unsanitized input stored in save_tmpl.cgi and rendered unescaped=
    in list_tmpls.cgi. 2026-05-21 5.4 CVE-2026-22678 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-22678 ] https://webmin.com/changelog/webmin-2.641-rele= ased/ https://www.vulncheck.com/advisories/webmin-stored-xss-via-system-and-serve= r-status
    =C2=A0 winking--Word 2 Cash The Word 2 Cash plugin for WordPress is vulnera= ble to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in=
    versions up to and including 0.9.2. This is due to the complete absence of=
    nonce verification on the settings save handler in the w2c_admin() functio=
    n, combined with missing input sanitization before storage and missing outp=
    ut escaping when rendering the stored value. The w2c-definitions POST param= eter is saved raw via update_option() and later echoed without escaping ins= ide a <textarea> element. This makes it possible for unauthenticated attack= ers to forge a request on behalf of a logged-in administrator, storing arbi= trary JavaScript payloads that execute in the WordPress admin panel wheneve=
    r the settings page is visited. 2026-05-20 6.1 CVE-2026-6395 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-6395 ] https://www.wordfence.com/threat-int= el/vulnerabilities/id/e4c7ca5c-38aa-4413-83eb-29185cca2a74?source=3Dcve https://plugins.trac.wordpress.org/browser/word-2-cash/trunk/word2cash.php#= L31 https://plugins.trac.wordpress.org/browser/word-2-cash/tags/0.9.2/word2cash= .php#L31 https://plugins.trac.wordpress.org/browser/word-2-cash/trunk/word2cash.php#= L20 https://plugins.trac.wordpress.org/browser/word-2-cash/tags/0.9.2/word2cash= .php#L20 https://plugins.trac.wordpress.org/browser/word-2-cash/trunk/word2cash.php#= L18 https://plugins.trac.wordpress.org/browser/word-2-cash/tags/0.9.2/word2cash= .php#L18
    =C2=A0 WP Chill--Image Photo Gallery Final Tiles Grid Missing Authorization=
    vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Expl= oiting Incorrectly Configured Access Control Security Levels. This issue af= fects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11. 2026-0= 5-20 4.3 CVE-2026-27424 [ https://www.cve.org/CVERecord?id=3DCVE-2026-27424=
    ] https://patchstack.com/database/wordpress/plugin/final-tiles-grid-galler= y-lite/vulnerability/wordpress-image-photo-gallery-final-tiles-grid-plugin-= 3-6-11-broken-access-control-vulnerability?_s_id=3Dcve
    =C2=A0 wpbean--WPB Floating Menu or Categories Sticky Floating Side Menu & = Categories with Icons The WPB Floating Menu & Categories for WordPress - St= icky Side Menu with Icons plugin for WordPress is vulnerable to Stored Cros= s-Site Scripting via the 'Icon CSS Class' category field in all versions up=
    to, and including, 1.0.8 due to insufficient input sanitization and output=
    escaping. This makes it possible for authenticated attackers, with Editor-= level access and above, to inject arbitrary web scripts in pages that will = execute whenever a user accesses an injected page. 2026-05-21 4.9 CVE-2026-= 4811 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4811 ] https://www.wordf= ence.com/threat-intel/vulnerabilities/id/961702ff-60fb-41ff-99b0-a37ade0510= 83?source=3Dcve https://plugins.trac.wordpress.org/browser/wpb-floating-menu-or-categories/= tags/1.0.8/admin/category-icon.php#L41
    =C2=A0 wpdive--Nexa Blocks Gutenberg Blocks, Page Builder for Gutenberg Edi= tor & FSE The Nexa Blocks - Gutenberg Blocks, Page Builder for Gutenberg Ed= itor & FSE plugin for WordPress is vulnerable to Server-Side Request Forger=
    y (SSRF) in versions up to and including 1.1.1. This is due to the import_d= emo() function accepting a user-supplied URL in the demo_json_file POST par= ameter and passing it directly to wp_remote_get() without any URL validatio=
    n or restriction against internal or private network destinations. The nexa= _blocks_nonce required for the AJAX action is publicly exposed in the HTML = source of any frontend page where the plugin is active via wp_localize_scri=
    pt on the enqueue_block_assets hook, effectively making the nonce available=
    to all visitors and bypassing any intended authentication barrier. This ma= kes it possible for unauthenticated attackers to make server-side HTTP requ= ests to arbitrary internal or external destinations, potentially exposing i= nternal services, cloud metadata endpoints such as the AWS instance metadat=
    a service, localhost services, and other resources not intended to be publi= cly accessible. A secondary SSRF vector also exists whereby image URLs extr= acted from the attacker-controlled JSON response are subsequently fetched v=
    ia a second wp_remote_get() call, allowing chained exploitation through a c= rafted JSON payload. 2026-05-20 5.4 CVE-2026-6394 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-6394 ] https://www.wordfence.com/threat-intel/vulnerab= ilities/id/b4bb3067-7953-466d-a469-8a101450f133?source=3Dcve https://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/template/t= emplate.php#L242 https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/templ= ate/template.php#L242 https://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/template/t= emplate.php#L236 https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/templ= ate/template.php#L236 https://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/classes/en= queue-assets.php#L84 https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/class= es/enqueue-assets.php#L84
    =C2=A0 WPFunnels Team--Mail Mint Exposure of Sensitive System Information t=
    o an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint = allows Retrieve Embedded Sensitive Data. This issue affects Mail Mint: from=
    n/a through 1.19.5. 2026-05-21 4.3 CVE-2026-27349 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-27349 ] https://patchstack.com/database/wordpress/plu= gin/mail-mint/vulnerability/wordpress-mail-mint-plugin-1-19-5-sensitive-dat= a-exposure-vulnerability?_s_id=3Dcve
    =C2=A0 wpxpo--FastX The FastX theme for WordPress is vulnerable to unauthor= ized limited plugin installation and activation due to missing capability c= hecks on the 'ultp_install_callback' and 'ultp_activate_callback' functions=
    in all versions up to, and including, 1.0.2. This makes it possible for au= thenticated attackers, with Subscriber-level access and above, to install a=
    nd activate the PostX plugin. 2026-05-22 4.3 CVE-2026-2518 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-2518 ] https://www.wordfence.com/threat-intel= /vulnerabilities/id/6f5c4194-4f97-4f85-af90-e983ba9ce3a6?source=3Dcve https://themes.trac.wordpress.org/browser/fastx/1.0.2/classes/Initializatio= n.php#L264 https://themes.trac.wordpress.org/browser/fastx/1.0.2/classes/Initializatio= n.php#L249
    =C2=A0 wupsales--AI Chatbot & Workflow Automation by AIWU The AI Chatbot & = Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cr= oss-Site Scripting via the 'X-Forwarded-For' header in versions up to, and = including, 1.4.14 due to insufficient input sanitization and output escapin=
    g. This makes it possible for unauthenticated attackers to inject arbitrary=
    web scripts in pages that will execute whenever a user accesses an injecte=
    d page. NOTE: Practical exploitation is constrained due to a 20-character s= torage limit. 2026-05-20 6.4 CVE-2026-2955 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-2955 ] https://www.wordfence.com/threat-intel/vulnerabilities= /id/8d434250-aa16-4ba1-a1f8-289371176545?source=3Dcve https://plugins.trac.wordpress.org/changeset/3505998/ai-copilot-content-gen= erator
    =C2=A0 xpro--Xpro Addons 140+ Widgets for Elementor The Xpro Addons - 140+ = Widgets for Elementor plugin for WordPress is vulnerable to unauthorized mo= dification of data due to a missing capability check on the get_content_edi= tor function in all versions up to, and including, 1.5.0. This makes it pos= sible for unauthenticated attackers to create published Xpro templates. 202= 6-05-20 5.3 CVE-2025-15369 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15= 369 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/cf49d3fb-de= 14-42bc-bf51-f9adceba0d32?source=3Dcve https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk?rev= =3D3508547
    =C2=A0 yangzongzhuan--RuoYi-Vue A vulnerability was found in yangzongzhuan = RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of t=
    he file /common/upload of the component Common Upload Endpoint. Performing =
    a manipulation results in unrestricted upload. The attack is possible to be=
    carried out remotely. The vendor was contacted early about this disclosure=
    but did not respond in any way. 2026-05-24 6.3 CVE-2026-9374 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-9374 ] VDB-365338 | yangzongzhuan RuoYi-Vu=
    e Common Upload Endpoint upload FileUploadUtils.upload unrestricted upload =
    [ https://vuldb.com/vuln/365338 ]
    VDB-365338 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65338/cti ]
    Submit #813252 | RuoYi RuoYi-Vue 3.9.2 Cross Site Scripting [ https://vuldb= .com/submit/813252 ]
    =C2=A0 yog2515--General Options The General Options plugin for WordPress is=
    vulnerable to Stored Cross-Site Scripting in versions up to and including = 1.1.0. This is due to the use of sanitize_text_field() for output escaping =
    in the Contact Number (ad_contact_number) field - a function that strips HT=
    ML tags but does not encode double-quote characters to their HTML entity eq= uivalent (&quot;). When the stored value is echoed inside a double-quoted H= TML attribute (value=3D"..."), an attacker-supplied double-quote character = breaks out of the attribute context. Even with WordPress's wp_magic_quotes = mechanism (which prefixes quotes with a backslash), the resulting \" sequen=
    ce is NOT treated as an escaped quote by HTML parsers - the backslash is re= ndered as a literal character and the bare double-quote still closes the at= tribute. This makes it possible for authenticated attackers with Administra= tor-level access and above to inject arbitrary web scripts in the admin set= tings page that will execute whenever any administrator visits the General = Options settings page. 2026-05-20 4.4 CVE-2026-6399 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-6399 ] https://www.wordfence.com/threat-intel/vulner= abilities/id/d29c69bb-4feb-477e-b18f-934ece21aff6?source=3Dcve https://plugins.trac.wordpress.org/browser/general-options/trunk/direct-mai= n.php https://plugins.trac.wordpress.org/browser/general-options/tags/1.1.0/direc= t-main.php https://plugins.trac.wordpress.org/browser/general-options/trunk/direct-act= ion.php https://plugins.trac.wordpress.org/browser/general-options/tags/1.1.0/direc= t-action.php
    =C2=A0 ZTE--MU5250 There is an unauthorized access vulnerability in ZTE MU5= 250. Due to improper permission control of the Web interface, an unauthoriz=
    ed attacker can=C2=A0 modify configuration through the interface. 2026-05-1=
    9 6.3 CVE-2026-44408 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44408 ] = https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/26579042= 55874650158
    =C2=A0 ZTE--MU5250 There is an an information disclosure vulnerability in Z=
    TE MU5250. Due to improper configuration of the access control mechanism, a= ttackers can obtain information without authorization, causing the risk of = information disclosure. 2026-05-22 5.7 CVE-2026-44409 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-44409 ] https://support.zte.com.cn/zte-iccp-isuppo= rt-webui/bulletin/detail/3711746568357343342
    =C2=A0=20

    Back to top [ #top ]

    Low Vulnerabilities

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info b= aptisteArno--typebot.io TypeBot is a chatbot builder tool. In versions 3.15=
    .2 and prior, the bot engine's the findResult query does not filter results=
    by typebotId, allowing an authenticated user to load result data (user ans= wers, variable values) from a different typebot by supplying a foreign resu= ltId to the startChat endpoint. Exploitation is constrained by CUID2's cryp= tographically random 24-character IDs (making brute-force infeasible), the = requirement that rememberUser be enabled, and the need for matching variabl=
    e names in the current typebot. If successfully exploited, an attacker can = access the original user's previous answers, session variable values, and h= asStarted flag, potentially exposing PII like names, emails, and phone numb= ers. This issue has been fixed in version 3.16.0. 2026-05-22 3.1 CVE-2026-3= 9967 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39967 ] https://github.c= om/baptisteArno/typebot.io/security/advisories/GHSA-f475-7m4x-m6mx https://github.com/baptisteArno/typebot.io/commit/73162634e6bdebd37a1a571db= 4062d30854e0400
    https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0
    =C2=A0 Besen--BS20 EV Charging Station A vulnerability was determined in Be= sen BS20 EV Charging Station up to 20260426. This impacts an unknown functi=
    on of the component Bluetooth Low Energy Handler. Executing a manipulation = can lead to weak password requirements. The attack needs to be done within = the local network. This attack is characterized by high complexity. The exp= loitability is said to be difficult. The original disclosure mentions, that=
    "[t]hese vulnerabilities have been reported to Besen and we have received = their acknowlegement that they are reviewing this as of April 2026." 2026-0= 5-24 3.1 CVE-2026-9394 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9394 ]=
    VDB-365375 | Besen BS20 EV Charging Station Bluetooth Low Energy weak pass= word [ https://vuldb.com/vuln/365375 ]
    VDB-365375 | CTI Indicators (IOB, IOC, TTP) [ https://vuldb.com/vuln/365375= /cti ]
    Submit #813569 | Besen EV Charging Station BS20 EV Charger Weak Authenticat= ion [ https://vuldb.com/submit/813569 ] https://github.com/carfeii/besen#finding-1-weak-authentication-mechanism-in= -besen-home-ev-charging-station-via-ble
    =C2=A0 Besen--BS20 EV Charging Station A vulnerability was identified in Be= sen BS20 EV Charging Station up to 20260426. Affected is an unknown functio=
    n of the component BLE/UDP. The manipulation leads to insufficiently protec= ted credentials. The attack needs to be initiated within the local network.=
    The original disclosure mentions, that "[t]hese vulnerabilities have been = reported to Besen and we have received their acknowlegement that they are r= eviewing this as of April 2026." 2026-05-24 3.5 CVE-2026-9395 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-9395 ] VDB-365376 | Besen BS20 EV Charging=
    Station BLE/UDP insufficiently protected credentials [ https://vuldb.com/v= uln/365376 ]
    VDB-365376 | CTI Indicators (IOB, IOC, TTP) [ https://vuldb.com/vuln/365376= /cti ]
    Submit #813572 | Besen EV Charging Station BS20 EV Charger Insufficiently P= rotected Credentials [ https://vuldb.com/submit/813572 ] https://github.com/carfeii/besen#finding-2-cleartext-credential-exposure-vi= a-ble-and-udp-in-besen-home-ev-charging-station
    =C2=A0 Besen--BS20 EV Charging Station A security flaw has been discovered =
    in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerab= ility is an unknown functionality of the component Firmware Version Check. = The manipulation results in improper restriction of rendered ui layers. The=
    attack can be executed remotely. A high complexity level is associated wit=
    h this attack. The exploitation appears to be difficult. The original discl= osure mentions, that "[t]hese vulnerabilities have been reported to Besen a=
    nd we have received their acknowlegement that they are reviewing this as of=
    April 2026." 2026-05-24 3.7 CVE-2026-9396 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-9396 ] VDB-365377 | Besen BS20 EV Charging Station Firmware V= ersion Check ui layer [ https://vuldb.com/vuln/365377 ]
    VDB-365377 | CTI Indicators (IOB, IOC) [ https://vuldb.com/vuln/365377/cti ] Submit #813575 | Besen EV Charging Station BS20 EV Charger Improper Verific= ation of Cryptographic Signature [ https://vuldb.com/submit/813575 ] https://github.com/carfeii/besen#finding-3-firmware-version-check-manipulat= ion-and-ui-spoofing
    =C2=A0 Besen--BS20 EV Charging Station A security vulnerability has been de= tected in Besen BS20 EV Charging Station up to 20260426. This affects an un= known part of the component BLE/WiFi. Such manipulation leads to authentica= tion bypass by capture-replay. The attack must be carried out from within t=
    he local network. Attacks of this nature are highly complex. It is indicate=
    d that the exploitability is difficult. The original disclosure mentions, t= hat "[t]hese vulnerabilities have been reported to Besen and we have receiv=
    ed their acknowlegement that they are reviewing this as of April 2026." 202= 6-05-24 3.1 CVE-2026-9398 [ https://www.cve.org/CVERecord?id=3DCVE-2026-939=
    8 ] VDB-365379 | Besen BS20 EV Charging Station BLE/WiFi authentication rep= lay [ https://vuldb.com/vuln/365379 ]
    VDB-365379 | CTI Indicators (IOB, IOC, TTP) [ https://vuldb.com/vuln/365379= /cti ]
    Submit #813577 | Besen EV Charging Station BS20 EV Charger Improper Authori= zation [ https://vuldb.com/submit/813577 ] https://github.com/carfeii/besen#finding-5-unauthorized-tampering-of-charge= r-commands
    =C2=A0 Dell--PowerFlex Manager (Appliance) Dell PowerFlex Manager, version(=
    s) <=3D4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm=
    vulnerability in the ssh. A low privileged attacker with local access coul=
    d potentially exploit this vulnerability, leading to Protection mechanism b= ypass. 2026-05-22 3.6 CVE-2025-46371 [ https://www.cve.org/CVERecord?id=3DC= VE-2025-46371 ] https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025= -435-security-update-for-dell-powerflex-rack-multiple-third-party-component= -vulnerabilities https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-up= date-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabil= ities
    =C2=A0 HCL--BigFix Service Management (SM) HCL BigFix Service Management (S=
    M) is affected by a security misconfiguration due to a missing or insecure = "X-Content-Type-Options" header. This could allow browsers to perform MIME-= type sniffing, potentially causing malicious content to be interpreted and = executed incorrectly. 2026-05-20 3.7 CVE-2025-31985 [ https://www.cve.org/C= VERecord?id=3DCVE-2025-31985 ] https://support.hcl-software.com/csm?id=3Dkb= _article&sysparm_article=3DKB0128144
    =C2=A0 jarrodwatts--claude-hud Claude HUD through 0.0.12, patched in commit=
    234d9aa, contains a path traversal vulnerability that allows attackers to = read arbitrary files by supplying an unvalidated transcript_path value via = stdin JSON. Attackers can access any file readable by the process and the f= ile metadata is written to a persistent cache file with insufficient permis= sions, creating a forensic record of accessed paths that survives process e= xit. 2026-05-18 3.3 CVE-2026-47091 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-47091 ] https://github.com/jarrodwatts/claude-hud/issues/485 https://github.com/jarrodwatts/claude-hud/pull/487 https://github.com/jarrodwatts/claude-hud/commit/234d9aad919b51326a43bcf90b= 45ae35c23afc30 https://www.vulncheck.com/advisories/claude-hud-path-traversal-via-transcri= pt-path
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13 fail to escape some variables that could contain malicious=
    content during error page composition which allows an attacker with access=
    to edit some site configuration to execute some malicious code via injecti=
    ng some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-0062=
    2 2026-05-18 3.8 CVE-2026-3495 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-3495 ] MMSA-2026-00622 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13 fail to validate that the RefreshedToken differs from the = original invite token during remote cluster invite confirmation which allow=
    s an authenticated attacker to bypass token rotation and reuse the original=
    invite token via sending a crafted invite confirmation with a RefreshedTok=
    en matching the original token. Mattermost Advisory ID: MMSA-2026-00575 202= 6-05-18 3.7 CVE-2026-4273 [ https://www.cve.org/CVERecord?id=3DCVE-2026-427=
    3 ] MMSA-2026-00575 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13 fail to check if {{team_id}} was being changed when updati=
    ng playbooks, allowing users with only {{Manage Playbook Configurations}} p= ermission to change a playbook's team, bypassing manage members restriction=
    via PUT api. Mattermost Advisory ID: MMSA-2025-00552 2026-05-18 3.1 CVE-20= 26-4286 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4286 ] MMSA-2025-0055=
    2 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost Desktop App versions <=3D6.1 6.0.1=
    5.4.13.0 fail to prevent server-rendered content from closing an underlyin=
    g application view in the Mattermost Desktop App which allows a malicious s= erver or plugin to crash the desktop client via invoking {{window.close()}}=
    in the renderer context, leading to a denial of service condition at the c= lient level. Mattermost Advisory ID: MMSA-2026-00633 2026-05-18 3.5 CVE-202= 6-4643 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4643 ] MMSA-2026-00633=
    [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13 fail to validate the Host header when constructing respons=
    e URLs for custom slash commands which allows an authenticated attacker to = redirect slash command responses to an attacker-controlled server via a spo= ofed Host header.. Mattermost Advisory ID: MMSA-2026-00582 2026-05-18 3.5 C= VE-2026-6333 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6333 ] MMSA-2026= -00582 [ https://mattermost.com/security-updates ]
    =C2=A0 Mattermost--Mattermost Mattermost versions 11.5.x <=3D 11.5.1, 10.11=
    .x <=3D 10.11.13 fail to enforce client identity binding during the OAuth a= uthorization code redemption flow which allows an authenticated OAuth clien=
    t to redeem authorization codes issued to a different client via a crafted = token exchange request.. Mattermost Advisory ID: MMSA-2026-00570 2026-05-18=
    3.1 CVE-2026-6334 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6334 ] MMS= A-2026-00570 [ https://mattermost.com/security-updates ]
    =C2=A0 n/a--JeecgBoot A vulnerability has been found in JeecgBoot 3.9.1. Th=
    is issue affects some unknown processing of the file /openapi/call/ of the = component OpenAPI Endpoint. Such manipulation leads to improper authenticat= ion. The attack can be executed remotely. A high complexity level is associ= ated with this attack. The exploitability is assessed as difficult. The ven= dor was contacted early about this disclosure but did not respond in any wa=
    y. 2026-05-24 3.7 CVE-2026-9373 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-9373 ] VDB-365337 | JeecgBoot OpenAPI Endpoint call improper authenticat= ion [ https://vuldb.com/vuln/365337 ]
    VDB-365337 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365337= /cti ]
    Submit #813251 | jeecgboot JeecgBoot 3.9.1 Improper Authentication [ https:= //vuldb.com/submit/813251 ]
    =C2=A0 n/a--vBulletin A vulnerability was found in vBulletin 6.x. This impa= cts an unknown function of the component Login. Performing a manipulation r= esults in cross site scripting. It is possible to initiate the attack remot= ely. The exploit has been made public and could be used. VulDB is withholdi=
    ng an extended redistribution of exploit details to prevent simplified expl= oitation. The vendor was contacted early about this disclosure but did not = respond in any way. 2026-05-24 3.5 CVE-2026-9357 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-9357 ] VDB-365320 | vBulletin Login cross site scriptin=
    g [ https://vuldb.com/vuln/365320 ]
    VDB-365320 | CTI Indicators (IOB, IOC, TTP) [ https://vuldb.com/vuln/365320= /cti ]
    Submit #813052 | Cross Site Scripting no f=C3=83=C2=B3rum vBulletin 6.xx Vb= ulletin 6.x.x Cross Site Scripting [ https://vuldb.com/submit/813052 ]
    =C2=A0 NeoRazorX--facturascripts FacturaScripts is an open source accountin=
    g and invoicing software. Versions 2025.7 and prior contain a Reflected Cro= ss-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. = The application reflects the cookie's value directly into the HTML without = sanitization. The fsNick cookie is rendered into the DOM without encoding. = While the server does reject the modified session and forces a logout, the = HTML containing the payload reaches the browser first. This lets the script=
    execute immediately upon load, effectively beating the redirect. This issu=
    e has been fixed in version 2025.8. 2026-05-18 3.9 CVE-2026-27964 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-27964 ] https://github.com/NeoRazorX/f= acturascripts/security/advisories/GHSA-gq5c-rw37-g46c https://github.com/NeoRazorX/facturascripts/commit/9066e10326029adf012114e2= 7eb5f3f33f78ecfd
    =C2=A0 Netatalk--Netatalk A dead bounds check in the Spotlight RPC unmarsha= ller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path th=
    at provides no effective bounds protection, which may allow a remote authen= ticated attacker to obtain limited information via crafted Spotlight RPC re= quests. 2026-05-21 3.1 CVE-2026-44057 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-44057 ] Netatalk Security Advisory CVE-2026-44057 [ https://netata= lk.io/security/CVE-2026-44057 ]
    =C2=A0 Netatalk--Netatalk A race condition in the privilege toggle mechanis=
    m in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited=
    information, modify limited data, or cause a minor service disruption. 202= 6-05-21 3.9 CVE-2026-44059 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44= 059 ] Netatalk Security Advisory CVE-2026-44059 [ https://netatalk.io/secur= ity/CVE-2026-44059 ]
    =C2=A0 Netatalk--Netatalk An off-by-two error in lp_write() in papd in Neta= talk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify limi= ted data or cause a minor service disruption via crafted print data. 2026-0= 5-21 3.7 CVE-2026-44065 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44065=
    ] Netatalk Security Advisory CVE-2026-44065 [ https://netatalk.io/security= /CVE-2026-44065 ]
    =C2=A0 Netatalk--Netatalk A heap over-read in extended attribute (EA) heade=
    r parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated att= acker to obtain limited information or cause a minor service disruption via=
    crafted EA data. 2026-05-21 3.7 CVE-2026-44067 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-44067 ] Netatalk Security Advisory CVE-2026-44067 [ http= s://netatalk.io/security/CVE-2026-44067 ]
    =C2=A0 Netatalk--Netatalk An integer underflow in the volxlate function in = Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limit=
    ed information, modify limited data, or cause a minor service disruption vi=
    a crafted volume translation input. 2026-05-21 3.4 CVE-2026-44069 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-44069 ] Netatalk Security Advisory CVE= -2026-44069 [ https://netatalk.io/security/CVE-2026-44069 ]
    =C2=A0 Netatalk--Netatalk An unbounded memory reallocation in the charset c= onversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticate=
    d attacker to cause a minor denial of service via crafted character convers= ion requests. 2026-05-21 3.1 CVE-2026-44070 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-44070 ] Netatalk Security Advisory CVE-2026-44070 [ https://= netatalk.io/security/CVE-2026-44070 ]
    =C2=A0 Netatalk--Netatalk Netatalk 3.1.2 through 4.4.2 is compiled without = FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtim=
    e, potentially allowing a remote attacker to cause a minor denial of servic=
    e via memory errors that would otherwise be caught and safely terminated by=
    runtime protection. 2026-05-21 3.7 CVE-2026-44071 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-44071 ] Netatalk Security Advisory CVE-2026-44071 [ h= ttps://netatalk.io/security/CVE-2026-44071 ]
    =C2=A0 Netatalk--Netatalk Netatalk 2.1.0 through 4.4.2 combines multiple er= rno values using bitwise OR, resulting in incorrect error codes when multip=
    le error conditions occur simultaneously, which may allow a remote attacker=
    to cause a minor service disruption via conditions that trigger incorrect = error-handling paths. 2026-05-21 3.7 CVE-2026-44074 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-44074 ] Netatalk Security Advisory CVE-2026-44074 [ = https://netatalk.io/security/CVE-2026-44074 ]
    =C2=A0 Netatalk--Netatalk A missing break statement in DSI OpenSession proc= essing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch cas=
    e to fall through into DSIOPT_SERVQUANT, resulting in unintended session op= tion handling that may allow a remote attacker to cause a minor service dis= ruption via crafted DSI session options. 2026-05-21 3.7 CVE-2026-44075 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-44075 ] Netatalk Security Advisor=
    y CVE-2026-44075 [ https://netatalk.io/security/CVE-2026-44075 ]
    =C2=A0 Netatalk--Netatalk A format string argument mismatch in Netatalk 3.0=
    .3 through 4.4.2 allows a remote authenticated attacker to cause a minor de= nial of service via crafted input that triggers incorrect format string pro= cessing. 2026-05-21 3.1 CVE-2026-7835 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-7835 ] Netatalk Security Advisory CVE-2026-7835 [ https://netatalk= .io/security/CVE-2026-7835 ]
    =C2=A0 Netatalk--Netatalk An incorrect calculation in the hextoint macro in=
    Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling = allows a remote authenticated attacker to cause limited data modification v=
    ia crafted hexadecimal input. 2026-05-21 3.1 CVE-2026-7836 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-7836 ] Netatalk Security Advisory CVE-2026-78=
    36 [ https://netatalk.io/security/CVE-2026-7836 ]
    =C2=A0 Netatalk--Netatalk A time-of-check time-of-use (TOCTOU) condition in=
    the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privil= eged file operations, which may allow a remote attacker to cause limited da=
    ta modification under specific race conditions. 2026-05-21 3.7 CVE-2026-783=
    7 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7837 ] Netatalk Security Ad= visory CVE-2026-7837 [ https://netatalk.io/security/CVE-2026-7837 ]
    =C2=A0 Netatalk--Netatalk Netatalk 2.2.1 through 4.4.2 calls system() after=
    a failed chdir() without properly handling the error condition, which allo=
    ws a local privileged user to execute unintended commands or cause a minor = service disruption under specific conditions. 2026-05-21 2.5 CVE-2026-44072=
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-44072 ] Netatalk Security Ad= visory CVE-2026-44072 [ https://netatalk.io/security/CVE-2026-44072 ]
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker cause DOS. 2026-05-19 3.3 CVE-2026-25110 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-25110 ] https://gitcode.com/openharmony/secu= rity/tree/master/zh/security-disclosure/2026/2026-04.md
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker cause DOS. 2026-05-19 3.3 CVE-2026-27781 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-27781 ] https://gitcode.com/openharmony/secu= rity/tree/master/zh/security-disclosure/2026/2026-04.md
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker cause DOS. 2026-05-19 3.3 CVE-2026-28751 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-28751 ] https://gitcode.com/openharmony/secu= rity/tree/master/zh/security-disclosure/2026/2026-04.md
    =C2=A0 OpenHarmony--OpenHarmony in OpenHarmony v6.0 and prior versions allo=
    w a local attacker cause DOS. 2026-05-19 3.3 CVE-2026-33565 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-33565 ] https://gitcode.com/openharmony/secu= rity/tree/master/zh/security-disclosure/2026/2026-05.md
    =C2=A0 opensourcepos--Open Source Point of Sale A flaw has been found in op= ensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function=
    Login of the file app/Models/Employee.php of the component Employee Login.=
    This manipulation causes use of weak hash. Remote exploitation of the atta=
    ck is possible. The attack is considered to have high complexity. The explo= itability is considered difficult. The actual existence of this vulnerabili=
    ty is currently in question. The vendor explains: "[T]he code is still ther=
    e to allow the upgrade path to work. The default password is initially seed=
    ed with the old hash function, but then migrated to a newer one after login=
    . [T]he hash version check might be cleaned up in the future. Currently it'=
    s not actively in use as any password change will use a newer hash function=
    ." 2026-05-18 3.7 CVE-2026-8803 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-8803 ] VDB-364436 | opensourcepos Open Source Point of Sale Employee Log=
    in Employee.php login weak hash [ https://vuldb.com/vuln/364436 ]
    VDB-364436 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 64436/cti ]
    Submit #802561 | opensourcepos Open Source Point of Sale 3.4.1 Weak Encodin=
    g for Password [ https://vuldb.com/submit/802561 ]
    =C2=A0 QuantumNous--new-api A security vulnerability has been detected in Q= uantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyI= mage/GetByOnlyMJId of the file router/relay-router.go of the component Midj= ourney Image Relay Endpoint. Such manipulation leads to authorization bypas=
    s. The attack can be launched remotely. The attack requires a high level of=
    complexity. The exploitability is reported as difficult. The exploit has b= een disclosed publicly and may be used. The vendor was contacted early abou=
    t this disclosure but did not respond in any way. 2026-05-23 3.7 CVE-2026-9= 306 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9306 ] VDB-365253 | Quant= umNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJI=
    d authorization [ https://vuldb.com/vuln/365253 ]
    VDB-365253 | CTI Indicators (IOB, IOC, IOA) [ https://vuldb.com/vuln/365253= /cti ]
    Submit #812196 | QuantumNous new-api 0.12.1 Authorization Bypass Through Us= er-Controlled Key (CWE-639) [ https://vuldb.com/submit/812196 ] https://gist.github.com/YLChen-007/13974ead25fc6dac42fd7bac62fbb2df
    =C2=A0 RsyncProject--rsync Rsync versions before 3.4.3 contain an off-by-on=
    e out-of-bounds stack write vulnerability in the establish_proxy_connection=
    () function in socket.c that allows network attackers to corrupt stack memo=
    ry by sending a malformed HTTP proxy response. Attackers can exploit this b=
    y positioning themselves between the client and proxy or controlling the pr= oxy server to send a response line of 1023 or more bytes without a newline = terminator, causing a null byte to be written to an out-of-bounds stack add= ress when the RSYNC_PROXY environment variable is set. 2026-05-20 3.1 CVE-2= 026-45232 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45232 ] https://git= hub.com/RsyncProject/rsync/security/advisories/GHSA-8f85-j2cv-59m8 https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 https://www.vulncheck.com/advisories/rsync-off-by-one-stack-write-via-http-= proxy
    =C2=A0 SourceCodester--SUP Online Shopping A vulnerability was identified i=
    n SourceCodester SUP Online Shopping 1.0. The impacted element is an unknow=
    n function of the file /admin/productedit.php. The manipulation of the argu= ment productName leads to cross site scripting. It is possible to initiate = the attack remotely. The exploit is publicly available and might be used. 2= 026-05-24 2.4 CVE-2026-9377 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9= 377 ] VDB-365340 | SourceCodester SUP Online Shopping productedit.php cross=
    site scripting [ https://vuldb.com/vuln/365340 ]
    VDB-365340 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65340/cti ]
    Submit #813270 | sourcecodester SUP Online Shopping Project V1.0 Cross Site=
    Scripting [ https://vuldb.com/submit/813270 ] https://github.com/redshadowword-cell/CVE/issues/13 https://www.sourcecodester.com/
    =C2=A0 SPIP--SPIP action/cookie.php in ecrire in SPIP before 4.4.15 is pron=
    e to an open redirect vulnerability. 2026-05-24 3.5 CVE-2026-48832 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-48832 ] https://blog.spip.net/Mise-a-= jour-de-securite-sortie-de-SPIP-4-4-15.html?lang=3Dfr https://git.spip.net/spip/spip/-/commit/75629034697ab52a963a340afd10930407e= 1cd55 https://git.spip.net/spip/ecrire/-/commit/a22cb8a56f1e37ff3854b73ff3f66aa3d= f47070a
    =C2=A0 ulisesbocchio--jasypt-spring-boot A weakness has been identified in = ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulner= ability is the function getSecretKeySaltGenerator of the file jasypt-spring= -boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMC= onfig.java of the component Password Hash Handler. Executing a manipulation=
    can lead to use of a one-way hash with a predictable salt. The attack can =
    be launched remotely. The attack requires a high level of complexity. The e= xploitation appears to be difficult. The exploit has been made available to=
    the public and could be used for attacks. The project was informed of the = problem early through an issue report but has not responded yet. 2026-05-24=
    3.7 CVE-2026-9370 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9370 ] VDB= -365333 | ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.ja=
    va getSecretKeySaltGenerator hash predictable salt [ https://vuldb.com/vuln= /365333 ]
    VDB-365333 | CTI Indicators (IOB, IOC, TTP, IOA) [ https://vuldb.com/vuln/3= 65333/cti ]
    Submit #813198 | Ulises Bocchio jasypt-spring-boot 3.0.0 to 4.0.4 Cryptogra= phic Issues [ https://vuldb.com/submit/813198 ] https://github.com/ulisesbocchio/jasypt-spring-boot/issues/431 https://github.com/dntyfate/cve/issues/3 https://github.com/ulisesbocchio/jasypt-spring-boot/
    =C2=A0=20

    Back to top [ #top ]

    Severity Not Yet Assigned

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info 9= front--9front Mothra would respect a default value given by a website for H= TML file upload forms. An attacker could craft a website with a malicious d= efault file path, and then conceal this form element. 2026-05-22 not yet ca= lculated CVE-2026-9053 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9053 ]=
    https://git.9front.org/plan9front/9front/d145acc9ef0da47131af6ad94e87264e0= 4870d47/commit.html
    =C2=A0 9front--9front An attacker sending tcp, il, rudp, rudp, or gre packe=
    ts with a length less than the header size would trigger a kernel panic. 20= 26-05-22 not yet calculated CVE-2026-9054 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-9054 ] https://git.9front.org/plan9front/9front/7838d68969549f= 938cc8e80c0c2b4218cb12805c/commit.html https://git.9front.org/plan9front/9front/f86917b75e9562f90545b7e484dbdcd748= 236952/commit.html https://git.9front.org/plan9front/9front/70c97c334171c715df82774d1a47638aba= ca2db4/commit.html
    =C2=A0 Advantech--WebAccess/SCADA 8.0-2015.08.16=C2=A0 Cross Site Scripting=
    vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote = attacker to obtain sensitive information via the decryption field in the Cr= eate New Project User component 2026-05-22 not yet calculated CVE-2026-3622=
    6 [ https://www.cve.org/CVERecord?id=3DCVE-2026-36226 ] https://github.com/= NullByte8080/CVE-2026-36226
    =C2=A0 Altium--Altium 365 A missing authentication vulnerability exists in = the Altium 365 SearchService. A legacy SOAP endpoint exposes search index o= perations without requiring authentication, session tokens, or any form of = identity verification. An unauthenticated network attacker who can referenc=
    e a target workspace's identifier can interact with that workspace's search=
    index, crossing tenant boundaries. Successful exploitation allows reading =
    a workspace's indexed contents (such as component data, project and folder = names, and user metadata) and injecting, modifying, or deleting search inde=
    x entries. These operations affect the search index only, not the underlyin=
    g vault data, but they can disclose sensitive workspace information and com= promise the integrity and availability of search results. Altium 365 cloud = deployments are affected; on-premise Altium Enterprise Server is not affect= ed. 2026-05-21 not yet calculated CVE-2026-9152 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-9152 ] https://www.altium.com/platform/security-complian= ce/security-advisories
    =C2=A0 Altium--Altium Enterprise Server A path traversal vulnerability exis=
    ts in the Altium Enterprise Server ComparisonService due to missing filenam=
    e sanitization in the Gerber file upload APIs. A regular authenticated work= space user can supply a crafted filename in the multipart Content-Dispositi=
    on header to escape the intended temporary upload directory and write arbit= rary files to any location on the server filesystem. Because content-contro= lled files can be written to web-accessible directories, this can be escala= ted to remote code execution in the context of the service account. It can = also be used to overwrite application binaries or configuration files, lead= ing to service takeover or denial of service. 2026-05-20 not yet calculated=
    CVE-2026-9102 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9102 ] https:/= /www.altium.com/platform/security-compliance/security-advisories
    =C2=A0 Altium--Altium Enterprise Server A path traversal vulnerability exis=
    ts in the Altium Enterprise Server Viewer StorageController due to improper=
    handling of file path route parameters. On on-premise deployments that use=
    local filesystem storage, a regular authenticated user can supply a URL-en= coded absolute path (such as an encoded drive letter) in a Viewer storage A=
    PI request, causing the configured storage root to be discarded and allowin=
    g arbitrary files to be read from the server filesystem. Because the readab=
    le files include the server's master configuration, which stores database c= redentials, signing key locations, certificate passwords, and OAuth secrets=
    , exploitation can lead to disclosure of all server secrets and full compro= mise of the server and its data. Cloud deployments are not affected, as the=
    y use object storage and do not enable this component. 2026-05-20 not yet c= alculated CVE-2026-9129 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9129 =
    ] https://www.altium.com/platform/security-compliance/security-advisories =C2=A0 AMD[.]com--AMD EPYC 4004 Improper input validation in the System Man= agement Mode (SMM) communications buffer could allow a privileged attacker =
    to perform an out of bounds read or write to a limited section of the Top o=
    f Memory Segment (TSEG) memory region, potentially resulting in loss of con= fidentiality or integrity. 2026-05-19 not yet calculated CVE-2024-36343 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2024-36343 ] https://www.amd.com/en/r= esources/product-security/bulletin/AMD-SB-3030.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html =C2=A0 Apache Software Foundation--Apache Airflow Amazon provider In the AW=
    S Secrets Manager and SSM Parameter Store secrets backends of `apache-airfl= ow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve =
    a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the same path as an= other team's team-scoped secret when the caller had no team context. A priv= ileged caller without team context could therefore retrieve another team's = secret by crafting a colliding `conn_id`. Fixed in 9.28.0 by switching the = team-scope separator to `--` and rejecting team-shaped `conn_id`s when team=
    context is absent. Affects the experimental multi-tenant teams feature onl=
    y. Users are recommended to upgrade to `apache-airflow-providers-amazon` 9.= 28.0, which fixes the issue. 2026-05-19 not yet calculated CVE-2026-42526 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-42526 ] https://github.com/apa= che/airflow/pull/65703 https://lists.apache.org/thread/0092sz5g520d3qqjb01wd61myqlgjtyn
    =C2=A0 Apache Software Foundation--Apache Airflow CNCF Kubernetes provider = JWT tokens that were used by workers in Kubernetes Executors have been expo= sed to users who had read only access to Kuberentes Pods. This could allow = users with just read-only access to perform actions that were only availabl=
    e to running tasks via Task SDK and potentially allow to modify state of Ai= rflow Database for tasks. 2026-05-19 not yet calculated CVE-2026-27173 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-27173 ] https://github.com/apache= /airflow/pull/60108 https://lists.apache.org/thread/pk3m2z4s2rkmc0v6gh9hnch9spc6stqw
    =C2=A0 Apache Software Foundation--Apache Camel Camel-CXF and Camel-Knative=
    Message Header Injection via Missing Inbound Filtering The CXF and Knative=
    HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-c= xf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHea= derFilterStrategy in camel-knative-http) only filter outbound Camel-interna=
    l headers via setOutFilterStartsWith, while not configuring inbound filteri=
    ng via setInFilterStartsWith. As a result, an unauthenticated attacker can = inject Camel-internal headers (e.g. CamelExecCommandExecutable, CamelFileNa= me) via HTTP requests to CXF-RS or CXF-SOAP endpoints. When a route forward=
    s messages from these endpoints to header-driven components such as camel-e= xec or camel-file, the injected headers override configured values, enablin=
    g remote code execution or arbitrary file writes. This is the same pattern = that was previously addressed in camel-undertow (CVE-2025-30177), the broad=
    er incoming-header filter (CVE-2025-27636 and CVE-2025-29891), and non-HTTP=
    strategies (CVE-2026-40453). This issue affects Apache Camel: from 3.18.0 = before 4.14.6, from 4.15.0 before 4.18.2. Users are recommended to upgrade =
    to version 4.19.0, which fixes the issue. If users are on the 4.18.x LTS re= leases stream, then they are suggested to upgrade to 4.18.2. If users are o=
    n the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.1= 4.6. 2026-05-19 not yet calculated CVE-2026-47323 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-47323 ] https://camel.apache.org/security/CVE-2026-473= 23.html
    =C2=A0 Apache Software Foundation--Apache Camel K (Externally Controlled Re= ference to a Resource in Another Sphere), (Authorization Bypass Through Use= r-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Ku= bernetes namespace can create a Build resource, controlling the Pod generat= ion in a namespace of their choice, including the operator namespace. This = issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.= 9.2, from 2.10.0 before 2.10.1. Users are recommended to upgrade to version=
    2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue. 2026-05-21 not yet calc= ulated CVE-2026-45760 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45760 ]=
    https://camel.apache.org/security/CVE-2026-45760.html
    =C2=A0 Apache Software Foundation--Apache CXF The fix for=C2=A0CVE-2025-489= 13: Apache CXF: Untrusted JMS configuration can lead to RCE was not complet=
    e, meaning that another path in the code might lead to code execution capab= ilities, if untrusted users are allowed to configure JMS for Apache CXF. Us= ers are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fi=
    x this issue. 2026-05-22 not yet calculated CVE-2026-44417 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-44417 ] https://lists.apache.org/thread/bqg6g= jy2cx7rfyqjxcpv3jwjvmclvz4o
    =C2=A0 Apache Software Foundation--Apache CXF Insecure XML parser configura= tion in Apache CXF's WS-Transfer module may allow attackers to perform XXE = attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.1=
    1, which fix this issue. 2026-05-22 not yet calculated CVE-2026-44618 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-44618 ] https://lists.apache.org/t= hread/c7vb015f8ljmjl44030mn0yfq71f7sd7
    =C2=A0 Apache Software Foundation--Apache CXF An LDAP injection vulnerabili=
    ty in the LDAP Certificate repository of the XKMS server in Apache CXF may = allow an attacker to retrieve arbitrary certificates from the repository.= =C2=A0 Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11,=
    which fix this issue. 2026-05-22 not yet calculated CVE-2026-44930 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-44930 ] https://lists.apache.org/thr= ead/c1zqxppo1m5z3kbdhjn5p991zk09ynkh
    =C2=A0 Apache Software Foundation--Apache Fory Deserialization of untrusted=
    data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documen= ted DeserializationPolicy validation hooks during reduce-state restoration = and global-name resolution. An application is vulnerable if it deserializes=
    attacker-controlled data using PyFory Python-native mode with strict mode = disabled and relies on DeserializationPolicy to restrict unsafe classes, fu= nctions, or module attributes. This issue affects Apache Fory: from before = 1.0.0. Mitigation: Users of Apache Fory are recommended to upgrade to versi=
    on 1.0.0 or later, which enforces DeserializationPolicy validation for the = affected ReduceSerializer paths and thus fixes this issue. 2026-05-21 not y=
    et calculated CVE-2026-48207 [ https://www.cve.org/CVERecord?id=3DCVE-2026-= 48207 ] https://fory.apache.org/security/#cve-2026-48207-pyfory-reduceseria= lizer-deserializationpolicy-bypass
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Neutralization of = Special Elements Used in a Template Engine vulnerability in Apache OFBiz. T= his issue affects Apache OFBiz: before 24.09.06. Users are recommended to u= pgrade to version 24.09.06, which fixes the issue. Please note that in the = updated version, "Data Resource" records with dataTemplateTypeId =3D "FTL" = are no longer supported. Additionally, in the updated version, the "Ecommer=
    ce Customer" security group no longer includes content management grants. U= sers are advised to remove these permissions from any production site as we= ll. 2026-05-19 not yet calculated CVE-2026-29207 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-29207 ] https://lists.apache.org/thread/3rcrp8bh3x6ovrj= 5xnc0fm1f0nrn52r0
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Limitation of a Pa= thname to a Restricted Directory ('Path Traversal') vulnerability in Apache=
    OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recomme= nded to upgrade to version 24.09.06, which fixes the issue. 2026-05-19 not = yet calculated CVE-2026-29220 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -29220 ] https://lists.apache.org/thread/5hjnmt9no6mmtg8sxq3mhonzff1vkd5m =C2=A0 Apache Software Foundation--Apache OFBiz Server-Side Request Forgery=
    (SSRF) vulnerability in Apache OFBiz via Content component operations. Thi=
    s issue affects Apache OFBiz: before 24.09.06. Users are recommended to upg= rade to version 24.09.06, which fixes the issue. 2026-05-19 not yet calcula= ted CVE-2026-29226 [ https://www.cve.org/CVERecord?id=3DCVE-2026-29226 ] ht= tps://lists.apache.org/thread/6707wys8jxzmowxggn4cmtwwk9ygl2tr
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Input Validation v= ulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09= .06. Users are recommended to upgrade to version 24.09.06, which fixes the = issue. 2026-05-19 not yet calculated CVE-2026-31378 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-31378 ] https://lists.apache.org/thread/cbl8qkqtxv90= m6ssfwd58bnoh933v38t
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Neutralization of = Input During Web Page Generation ('Cross-site Scripting'), Improper Limitat= ion of a Pathname to a Restricted Directory ('Path Traversal'), Improper Co= ntrol of Generation of Code ('Code Injection') vulnerability in Apache OFBi=
    z. This issue affects Apache OFBiz: before 24.09.06. Users are recommended =
    to upgrade to version 24.09.06, which fixes the issue. 2026-05-19 not yet c= alculated CVE-2026-31379 [ https://www.cve.org/CVERecord?id=3DCVE-2026-3137=
    9 ] https://lists.apache.org/thread/1tcnkxjm0s6n1ohfb21brl25dt0hv9by
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Neutralization of = Special Elements used in an Expression Language Statement ('Expression Lang= uage Injection') vulnerability in Apache OFBiz. This issue affects Apache O= FBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06=
    , which fixes the issue. 2026-05-19 not yet calculated CVE-2026-31380 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-31380 ] https://lists.apache.org/t= hread/v2brvq1tf4q491obkxv8p7fc5qfshc08
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Authentication vul= nerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.0=
    6. Users are recommended to upgrade to version 24.09.06, which fixes the is= sue. 2026-05-19 not yet calculated CVE-2026-31387 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-31387 ] https://lists.apache.org/thread/3wgybgdvmbfvly= 24zm4sb4y53fc1pqcf
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Access Control vul= nerability in Apache OFBiz in multi-tenant deployments. This issue affects = Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version = 24.09.06, which fixes the issue. 2026-05-19 not yet calculated CVE-2026-313=
    88 [ https://www.cve.org/CVERecord?id=3DCVE-2026-31388 ] https://lists.apac= he.org/thread/npjchvnpnosoqpto46s2om12jd9s7py7
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Neutralization of = Input During Web Page Generation ('Cross-site Scripting') vulnerability in = Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r= ecommended to upgrade to version 24.09.06, which fixes the issue. 2026-05-1=
    9 not yet calculated CVE-2026-31906 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-31906 ] https://lists.apache.org/thread/1fblqdo89d3ps8kgtcnkcq8sh7gw= kcpn
    =C2=A0 Apache Software Foundation--Apache OFBiz Exposure of Sensitive Infor= mation to an Unauthorized Actor vulnerability in Apache OFBiz. This issue a= ffects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to v= ersion 24.09.06, which fixes the issue. 2026-05-19 not yet calculated CVE-2= 026-31909 [ https://www.cve.org/CVERecord?id=3DCVE-2026-31909 ] https://lis= ts.apache.org/thread/0hpopzz1qrhkzsbt3ncofs6qo0545r2h
    =C2=A0 Apache Software Foundation--Apache OFBiz Server-Side Request Forgery=
    (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: bef= ore 24.09.06. Users are recommended to upgrade to version 24.09.06, which f= ixes the issue. 2026-05-19 not yet calculated CVE-2026-31910 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-31910 ] https://lists.apache.org/thread/2sm= c4c4o056ovd2hoq1l29593y5y29vh
    =C2=A0 Apache Software Foundation--Apache OFBiz Use of Hard-coded Cryptogra= phic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: be= fore 24.09.06. Users are recommended to upgrade to version 24.09.06, which = fixes the issue. 2026-05-19 not yet calculated CVE-2026-31986 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-31986 ] https://lists.apache.org/thread/2h= l9xoqm8tq8b22x6vnmtp7tg3opcqgc
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Control of Generat= ion of Code ('Code Injection') vulnerability in email services of Apache OF= Biz. This issue affects Apache OFBiz: before 24.09.06. Users are recommende=
    d to upgrade to version 24.09.06, which fixes the issue. 2026-05-19 not yet=
    calculated CVE-2026-35086 [ https://www.cve.org/CVERecord?id=3DCVE-2026-35= 086 ] https://lists.apache.org/thread/g0s37yhnh2xwfts400crb2w8s337hgjx
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Neutralization of = Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in = Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r= ecommended to upgrade to version 24.09.06, which fixes the issue. 2026-05-1=
    9 not yet calculated CVE-2026-41919 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-41919 ] https://lists.apache.org/thread/592czh9o69n74c036vy30fnqknoc= w74p
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Authorization vuln= erability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before=
    24.09.06. Users are recommended to upgrade to version 24.09.06, which fixe=
    s the issue. 2026-05-19 not yet calculated CVE-2026-45187 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-45187 ] https://lists.apache.org/thread/pcmfyx= jyk7dg0btxqg9h7cr30yg8mr7k
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Authentication vul= nerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote=
    Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are=
    recommended to upgrade to version 24.09.06, which fixes the issue. 2026-05= -19 not yet calculated CVE-2026-45434 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-45434 ] https://lists.apache.org/thread/yw4owrzl0yho1yx7oqxvr6xjkm= ln9tq8
    =C2=A0 Apache Software Foundation--Apache OFBiz Improper Control of Generat= ion of Code ('Code Injection'), Improper Neutralization of Directives in Dy= namically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. = This issue affects Apache OFBiz: before 24.09.06. Users are recommended to = upgrade to version 24.09.06, which fixes the issue. 2026-05-19 not yet calc= ulated CVE-2026-46586 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46586 ]=
    https://lists.apache.org/thread/7mgjl81nrpxqtfcg6h5qtrx7wztbl4js
    =C2=A0 Apple--Private Cloud Compute Server Software An attacker in a privil= eged network position may be able to leak sensitive information. A path han= dling issue was addressed with improved validation. This issue is fixed in = PCC Release 5E290.3. 2026-05-18 not yet calculated CVE-2026-20685 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-20685 ] https://security.apple.com/doc= umentation/private-cloud-compute/releasenotes#darwin-init
    =C2=A0 APScheduler--JSONSerializer and CBORSerializer=C2=A0 The JSONSeriali= zer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.= 0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deseriali= zation. The unmarshal_object function allows for arbitrary class instantiat= ion and state injection by dynamically importing modules and calling __sets= tate__ on any class available in the Python environment. An attacker can ex= ploit this by submitting a specially crafted JSON or CBOR payload to an app= lication using these serializers 2026-05-19 not yet calculated CVE-2026-310=
    72 [ https://www.cve.org/CVERecord?id=3DCVE-2026-31072 ] https://github.com= /agronholm/apscheduler https://gist.github.com/nedlir/11fb77f35a59cbba73392a086b02a9c6
    =C2=A0 Arm--ArmNN In Arm ArmNN through 2026-03-27, an integer overflow in T= ensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite mo= del file to bypass buffer size validation and trigger a heap-based buffer o= ver-read during model optimization. The overflow occurs when multiplying te= nsor dimensions using 32-bit unsigned arithmetic without overflow detection=
    , causing GetNumBytes() to return an understated allocation size. During Op= timize()->InferOutputShapes(), the BatchToSpaceNdLayer reads beyond the all= ocated buffer. 2026-05-22 not yet calculated CVE-2026-42627 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-42627 ] https://github.com/ARM-software/armn= n/blob/main/src/armnn/Tensor.cpp https://github.com/ARM-software/armnn/blob/main/src/armnnTfLiteParser/TfLit= eParser.cpp
    =C2=A0 awesomemotive--NextGEN Gallery NextGEN Gallery version prior to 4.2.=
    1 are vulnerable to authenticated SQL injection via the 'orderby' parameter=
    on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'=
    . The root cause is an insufficient sanitization function ('_clean_column()=
    ') in the data mapper layer that uses a character blacklist instead of a wh= itelist approach. This allows an authenticated attacker with the 'NextGEN G= allery overview' capability (assigned to the Administrator role by default)=
    to inject arbitrary SQL into the 'ORDER BY' clause. 2026-05-20 not yet cal= culated CVE-2026-9059 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9059 ] = https://www.tenable.com/security/research/tra-2026-42
    =C2=A0 baptisteArno--typebot.io TypeBot is a chatbot builder tool. Versions=
    3.15.2 and prior contain a critical stored XSS vulnerability in the app.ty= pebot.io profile picture upload form. The application fails to sanitize or = restrict SVG/XML-based uploads and directly renders them when accessed thro= ugh the domain. By uploading a crafted malicious SVG file containing embedd=
    ed JavaScript, an attacker will execute arbitrary JavaScript code. This vul= nerability directly enables stored XSS exploitation because the payload is = persistently stored on your infrastructure (app.typebot.io) and accessible = from a public-facing, permanent link. Stored XSS via malicious SVG uploads =
    to app.typebot.io allows attackers to execute arbitrary JavaScript in victi= ms' browsers, enabling session/token theft, account takeover, and exfiltrat= ion of sensitive user data. This issue has been fixed in version 3.16.0. 20= 26-05-22 not yet calculated CVE-2026-39970 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-39970 ] https://github.com/baptisteArno/typebot.io/security/a= dvisories/GHSA-jj87-c343-26vp https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0
    =C2=A0 Best Practical--Request Tracker Request Tracker is vulnerable to a r= eflected cross-site scripting (XSS) vulnerability via the "Page" parameter =
    in GET requests. An attacker can craft a URL that, when opened, results in = arbitrary JavaScript execution in the victim's browser. This vulnerability = affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to=C2=A06.0.2. 20= 26-05-21 not yet calculated CVE-2026-6841 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-6841 ] https://cert.pl/en/posts/2026/05/CVE-2026-6841 https://requesttracker.com/request-tracker/ https://docs.bestpractical.com/release-notes/rt/5.0.10 https://docs.bestpractical.com/release-notes/rt/6.0.3
    =C2=A0 BillaBear--BillaBear BillaBear (all versions prior to Jan 2026) cont= ains a SQL Injection vulnerability in the EventRepository. User-controlled = input from metric filter names and aggregation properties is directly inter= polated into SQL queries using sprintf() without proper sanitization or ide= ntifier quoting. Although filter values are parameterized, the filter ident= ifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER = permissions can exploit this to execute arbitrary SQL commands. 2026-05-19 = not yet calculated CVE-2026-31069 [ https://www.cve.org/CVERecord?id=3DCVE-= 2026-31069 ] https://gist.github.com/nedlir/a50725b94650467f0593b8f4009ae19e https://github.com/BillaBear/billabear https://gist.github.com/nedlir/2377ba6e7fa2ad957210b52aa8e400d9
    =C2=A0 brainstormforce--Surecart SureCart version prior to 4.2.1 are vulner= able to authenticated SQL injection via multiple parameters ('model_name', = 'model_id', 'integration_id', 'provider') on the REST API endpoint '/sureca= rt/v1/integrations/{id}'. The root cause is a flawed escaping bypass in the=
    query builder ('wp-query-builder'). Values passed to the 'where()' method = are only sanitized via '$wpdb->prepare()' when they do **not** contain a do=
    t ('.') or the WordPress table prefix ('wp_'). By including a dot anywhere =
    in the payload, an attacker completely bypasses the escaping logic and inje= cts arbitrary SQL into the 'WHERE' clause, allowing full UNION-based extrac= tion of the database. 2026-05-20 not yet calculated CVE-2026-9065 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-9065 ] https://www.tenable.com/securit= y/research/tra-2026-43
    =C2=A0 Broadcom--Automic Automation Execution with unnecessary privileges v= ulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux = Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris=
    Sparc 64 allows Privilege Escalation, Target Programs with Elevated Privil= eges. This issue affects Automic Automation: < 24.4.4 HF1. 2026-05-19 not y=
    et calculated CVE-2026-8370 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8= 370 ] https://support.broadcom.com/web/ecx/support-content-notification/-/e= xternal/content/SecurityAdvisories/0/37512
    =C2=A0 BYD--Atto3 In BYD Atto3, an attacker can obtain an authentication ke=
    y through Brute Force attack, which is permanently available. The authentic= ation key enables flash to the Electronic Parking Break (EPB) and Supplemen= tal Restoration System (SRS) related ECUs. 2026-05-19 not yet calculated CV= E-2025-61081 [ https://www.cve.org/CVERecord?id=3DCVE-2025-61081 ] https://= www.notion.so/BYD-Atto3-26215fb6156c8000b338db3c2011f637?source=3Dcopy_link https://www.notion.so/CVE-2025-61081-26215fb6156c8000b338db3c2011f637
    =C2=A0 Centralny Instytut Ochrony Pracy - Pastwowy Instytut Badawczy--STER =
    A SQL injection vulnerability has been identified in STER. Improper neutral= ization of input provided by user into multiple Search Filters allows for S=
    QL Injection attacks. It allows an authenticated attacker to view sensitive=
    data such as=C2=A0data belonging to other users, or any other data that th=
    e application itself is able to access This issue was fixed in version 9.5.=
    2026-05-22 not yet calculated CVE-2026-25606 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-25606 ] https://cert.pl/posts/2026/05/CVE-2026-25606 https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pageLabe= l=3DP52000165211572544981480
    =C2=A0 Centralny Instytut Ochrony Pracy - Pastwowy Instytut Badawczy--STER = Use of a weak password encoding algorithm in STER software allows the value=
    of the password to be guessed after analyzing how passwords with known val= ues are encoded. This issue was fixed in version 9.5. 2026-05-22 not yet ca= lculated CVE-2026-25607 [ https://www.cve.org/CVERecord?id=3DCVE-2026-25607=
    ] https://cert.pl/posts/2026/05/CVE-2026-25606 https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pageLabe= l=3DP52000165211572544981480
    =C2=A0 Centralny Instytut Ochrony Pracy - Pastwowy Instytut Badawczy--STER = STER uses unencrypted TCP traffic to transmit data over the network. It all= ows an attacker to=C2=A0conduct a Man-In-The-Middle attack and obtain sensi= tive data such as passwords, personal data, or authentication tokens. This = issue was fixed in version 9.5. 2026-05-22 not yet calculated CVE-2026-2560=
    8 [ https://www.cve.org/CVERecord?id=3DCVE-2026-25608 ] https://cert.pl/pos= ts/2026/05/CVE-2026-25606 https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pageLabe= l=3DP52000165211572544981480
    =C2=A0 Chroma--ChromaDB A pre-authentication, code injection vulnerability =
    in version 1.0.0 or later of the ChromaDB Python project allows an unauthen= ticated attacker to run arbitrary code on the server by sending a malicious=
    model repository and trust_remote_code set to true in the=C2=A0/api/v2/ten= ants/{tenant}/databases/{db}/collections endpoint. 2026-05-18 not yet calcu= lated CVE-2026-45829 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45829 ] = https://www.hiddenlayer.com/research/chromatoast-served-pre-auth https://github.com/chroma-core/chroma/issues/6717
    =C2=A0 ClipBucket--ClipBucket v5 v.5.5.2 An issue in ClipBucket v5 v.5.5.2 = allows an attacker to execute arbitrary code via the Authentication interfa= ce, login page endpoint and HTTP response security headers components 2026-= 05-22 not yet calculated CVE-2026-37470 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-37470 ] http://clipbucket.com https://medium.com/@arpit03sharma2003/cve-2026-37470-clickjacking-vulnerabi= lity-in-clipbucket-v5-leads-to-credential-theft-and-8415def7804a
    =C2=A0 CODESYS--Visualization The affected product may expose credentials r= emotely between low privileged visualization users during concurrent login = operations due to insufficient isolation of authentication data. The vulner= ability affects only login operations within an active visualization sessio=
    n. 2026-05-21 not yet calculated CVE-2026-0393 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-0393 ] https://codesys.csaf-tp.certvde.com/.well-known/cs= af/white/2026/advisory2026-07_vde-2026-052.json
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below=C2=A0 is vul= nerable to=C2=A0unauthenticated file usage disclosure via missing permissio=
    n check in the usage controller.=C2=A0=C2=A0Any unauthenticated visitor can=
    request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive =
    a list of every page that references that file, including page IDs, handles=
    , and full URLs. This includes pages that are otherwise restricted by permi= ssions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0 = score of 6.9 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/V= A:N/SC:N/SI:N/SA:N. Thanks Eldudareeno=C2=A0for reporting. 2026-05-21 not y=
    et calculated CVE-2026-6826 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6= 826 ] https://documentation.concretecms.org/9-x/developers/introduction/ver= sion-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS In Concrete CMS 9.5.0 and below,=C2=A0 th=
    e submit_password() method in concrete/controllers/single_page/download_fil= e.php allows unauthorized file access since downloading permission-restrict=
    ed files bypasses the view_file permission check.=C2=A0Files without passwo= rds can be downloaded and any user who knows a file's password can download=
    a password protected file regardless of whether they have permission to ac= cess the file.=C2=A0The Concrete CMS security team gave this vulnerability =
    a CVSS v.4.0 score of 6.3 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:= N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N.=C2=A0 Thanks=C2=A0Youssef Eid for reportin=
    g 2026-05-21 not yet calculated CVE-2026-7879 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-7879 ] https://documentation.concretecms.org/9-x/developer= s/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is subject t= o=C2=A0Insecure Direct Object Reference=C2=A0(IDOR) in the Express Entry De= tail block via the exEntryID parameter. This IDOR leads to unauthorized acc= ess to all Express form submissions.=C2=A0The Concrete CMS security team ga=
    ve this vulnerability a CVSS v.4.0 score of 6.3 with vector=C2=A0CVSS:4.0/A= V:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Tristan = Madani for reporting. 2026-05-21 not yet calculated CVE-2026-7881 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-7881 ] https://documentation.concretec= ms.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to unauthorized file deletion due to an Inverted CSRF token check in the = DeleteFile controller.=C2=A0The code throws an error when the token IS vali=
    d and proceeds with file deletion when the token is invalid or missing. Thi=
    s effectively disables CSRF protection for the file deletion endpoint, allo= wing cross-site request forgery attacks against users who have permission t=
    o edit conversation messages.=C2=A0The Concrete CMS security team gave this=
    vulnerability a CVSS v.4.0 score of=C2=A02.3 with a vector of=C2=A0CVSS:4.= 0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Ma= ndani for reporting. 2026-05-21 not yet calculated CVE-2026-7882 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-7882 ] https://documentation.concretecm= s.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to=C2=A0IDOR in AddMessage/UpdateMessage via attachments[] parameter whic=
    h can lead to file permission bypass.=C2=A0The `AddMessage` and `UpdateMess= age` conversation controllers accept user-supplied file attachment IDs and = load files directly via `$em->find(File::class, $attachmentID)` without che= cking per-file permissions (`canViewFile()`). A user who can post in any co= nversation can reference any file in the CMS file manager by its sequential=
    ID, effectively bypassing the file permission system.=C2=A0 The Concrete C=
    MS security team gave this vulnerability a CVSS v.4.0 score of=C2=A02.3 wit=
    h a vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/= SA:N.=C2=A0Thanks Tristan Mandani for reporting.=C2=A0if a site truly has p= rivate files, the owner should set up a private storage location https://do= cumentation.concretecms.org/user-guide/editors-reference/dashboard/system-a= nd-maintenance/files/file-storage-locations outside of the webroot so that = permissions can be checked on view as well. That way, even if a authorized = user attaches a file, or otherwise links to it, unauthorized users won't be=
    able to view the file. 2026-05-21 not yet calculated CVE-2026-7886 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-7886 ] https://documentation.concret= ecms.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS For Concrete CMS 9.5.0 and below, OAuth 2=
    .0 Authorization-Code Handler Bypasses Account Status. A=C2=A0user with uIs= Active=3D0 (suspended, banned, terminated employee) can still authenticate = via OAuth and receive valid API tokens.=C2=A0The Concrete CMS security team=
    gave this vulnerability a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.= 0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N. Thanks=C2=A00x4c6= 16e for reporting. 2026-05-21 not yet calculated CVE-2026-7887 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-7887 ] https://documentation.concretecms.= org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS In Concrete CMS 9.5.0 and below, the RSS = Displayer block accepts a feed URL from any page editor and fetches it serv= er-side without validation=C2=A0enabling redirect-to-internal bypasses.=C2= =A0=C2=A0The Concrete CMS security team gave this vulnerability a CVSS v.4.=
    0 score of=C2=A02.1 with a vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC= :N/VI:L/VA:N/SC:L/SI:N/SA:N. 2026-05-21 not yet calculated CVE-2026-7890 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-7890 ] https://documentation.co= ncretecms.org/9-x/developers/introduction/version-history/951-release-notes =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below fails to san= itize path traversal sequences in the ptComposerFormLayoutSetControlCustomT= emplate field when saving page type composer form layouts. An authenticated=
    rogue administrator with composer form editing rights can exploit this to = include arbitrary readable files on the server. Combined with the file uplo= ader's extension-only validation (which permits PHP code in files saved wit=
    h image extensions like .png), this can result in=C2=A0authenticated remote=
    code execution.=C2=A0The Concrete CMS security team gave this vulnerabilit=
    y a CVSS v.4.0 score of 9.4 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/U= I:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H=C2=A0 =C2=A0Thanks=C2=A0Yonatan Drori=C2= =A0(Tenzai)=C2=A0for reporting. 2026-05-21 not yet calculated CVE-2026-8134=
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-8134 ] https://documentation= .concretecms.org/9-x/developers/introduction/version-history/951-release-no= tes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to Remote Code Execution due to insecure deserialization occurring in the= =C2=A0ExpressEntryList=C2=A0block controller. An rogue administrator with p= rivileges to add blocks to an area can bypass the intended protection mecha= nism (_fromCIF =3D=3D=3D true), which normally restricts malicious inputs o= ver form POST requests, by leveraging the REST API functionality. Because t=
    he REST API parses requests using json_decode(), the string "true" is evalu= ated as a strict PHP Boolean(true).=C2=A0 This bypass allows the attacker t=
    o inject a malicious serialized payload =C2=A0into the block's filterFields=
    database column. The payload will subsequently be executed when the block'=
    s data is viewed or edited by an administrator leading to complete server t= akeover (RCE).The Concrete CMS security team gave this vulnerability a CVSS=
    v.4.0 score of 8.9 with a vector of=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N= /VC:H/VI:H/VA:H/SC:H/SI:H/SA:H.=C2=A0 Thanks Nguy=C3=A1=C2=BB=E2=80=A6n V= =C3=84=C6=92n Thi=C3=A1=C2=BB=E2=80=A1n https://github.com/Thien225409 =C2= =A0for reporting 2026-05-21 not yet calculated CVE-2026-8135 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-8135 ] https://documentation.concretecms.or= g/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to Stored XSS via external-link page cvName because updateCollectionAlias= External bypasses being sanitized. The Concrete CMS security team gave this=
    vulnerability a CVSS v.4.0 score of 2.0 with vector=C2=A0CVSS:4.0/AV:N/AC:= L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N.=C2=A0 Thanks=C2=A0Yonatan D= rori (Tenzai) for reporting. 2026-05-21 not yet calculated CVE-2026-8139 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-8139 ] https://documentation.co= ncretecms.org/9-x/developers/introduction/version-history/951-release-notes =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below does not val= idate a CSRF token before processing requests to /dashboard/extend/install/= download/<remoteId>. The download() method in concrete/controllers/single_p= age/dashboard/extend/install.php checks only the canInstallPackages() permi= ssion before fetching a remote marketplace package and writing it to the se= rver's DIR_PACKAGES directory. Because the endpoint is a state-changing GET=
    route with no token enforcement, an attacker who can cause an authenticate=
    d administrator to visit a crafted page can force an arbitrary marketplace = package to be downloaded. In order to be vulnerable, the victim must be pas= sing canInstallPackages() and the site must be connected to the Concrete ma= rketplace.=C2=A0The Concrete CMS security team gave this vulnerability a CV=
    SS v.4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI= :A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0 https://github.com/maru1009 = =C2=A0for reporting. 2026-05-21 not yet calculated CVE-2026-8140 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-8140 ] https://documentation.concretecm= s.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to Stored XSS via OAuth integration name. The OAuth authorize template re= nders the integration name (admin-controlled) through Concrete's t() transl= ation helper as a sprintf-style format. The <strong>...</strong> wrap is bu= ilt by PHP string interpolation before t() runs, so the integration name la= nds in the translated output as raw HTML. A rogue admin could potentially s= noop on login submissions.The Concrete CMS security team gave this vulnerab= ility a CVSS v.4.0 score of=C2=A07.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT= :P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N=C2=A0 Thanks Yonatan Drori (Tenz= ai) for reporting. 2026-05-21 not yet calculated CVE-2026-8197 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-8197 ] https://documentation.concretecms.= org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below has Stored X=
    SS on the height parameter.=C2=A0The controller does not validate or saniti=
    ze $height.=C2=A0Any user with editor privileges can inject malicious JavaS= cript that executes in the context of any visitor's browser, potentially le= ading to session hijacking, credential theft, or other malicious actions.= =C2=A0The Concrete CMS security team gave this vulnerability a CVSS v.4.0 s= core of=C2=A07.3 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI= :H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0Alfin Joseph for reporting. 2026-05-21 = not yet calculated CVE-2026-8203 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-8203 ] https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to authorization Bypass in the Calendar Event Frontend Dialog which can a= llow cross-calendar data disclosure. A public calendar block can be used as=
    a pivot point to access private calendar data. The Concrete CMS security t= eam gave this vulnerability a CVSS v.4.0 score of=C2=A06.3 with vector=C2= =A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks= =C2=A0Winston Crooker for reporting. 2026-05-21 not yet calculated CVE-2026= -8204 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8204 ] https://document= ation.concretecms.org/9-x/developers/introduction/version-history/951-relea= se-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to authorization bypass in the Calendar Block since action_get_events doe=
    s not check canView on the calendar=C2=A0which results in restricted event = details being disclosed.=C2=A0The Concrete CMS security team gave this vuln= erability a CVSS v.4.0 score of=C2=A06.3 with vector=C2=A0CVSS:4.0/AV:N/AC:= L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks lalalala5678 for rep= orting. 2026-05-21 not yet calculated CVE-2026-8205 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-8205 ] https://documentation.concretecms.org/9-x/dev= elopers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to IDOR combined with a missing authentication gate. The endpoint=C2=A0/c= cm/system/dialogs/file/usage/{fID}=C2=A0accepts an integer file ID in the U=
    RL and returns internal site structure data (page IDs, versions, URL paths)=
    to anyone who sends a GET request. The Concrete CMS security team gave thi=
    s vulnerability a CVSS v.4.0 score of=C2=A06.3 with vector=C2=A0CVSS:4.0/AV= :N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Winston C= rooker for reporting. 2026-05-21 not yet calculated CVE-2026-8236 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-8236 ] https://documentation.concretec= ms.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to IDOR.=C2=A0The `/ccm/frontend/conversations/message_detail` endpoint r= eturns the full content of any conversation message. An unauthenticated att= acker can enumerate all conversation messages, including messages from rest= ricted pages, member-only areas, and the moderation queue. File attachments=
    with download URLs are also exposed.=C2=A0The Concrete CMS security team g= ave this vulnerability a CVSS v.4.0 score of=C2=A06.3 with Vector=C2=A0CVSS= :4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudar= eeno for reporting. 2026-05-21 not yet calculated CVE-2026-8237 [ https://w= ww.cve.org/CVERecord?id=3DCVE-2026-8237 ] https://documentation.concretecms= .org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to IDOR.=C2=A0The=C2=A0'/ccm/frontend/conversations/message_page'=C2=A0en= dpoint returns the full content of any conversation message. An unauthentic= ated attacker can enumerate all conversation messages, including messages f= rom restricted pages, member-only areas, and the moderation queue. File att= achments with download URLs are also exposed.=C2=A0The Concrete CMS securit=
    y team gave this vulnerability a CVSS v.4.0 score of=C2=A06.3 with Vector= =C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Than=
    ks Tristan Madani for reporting. 2026-05-21 not yet calculated CVE-2026-823=
    8 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8238 ] https://documentatio= n.concretecms.org/9-x/developers/introduction/version-history/951-release-n= otes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to IDOR.=C2=A0The=C2=A0'/ccm/frontend/conversations/get_rating'=C2=A0endp= oint confirms existence and returns rating score for any message by ID.=C2= =A0The Concrete CMS security team gave this vulnerability a CVSS v.4.0 scor=
    e of=C2=A06.3 with Vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/= VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting. 2026-05-21 not ye=
    t calculated CVE-2026-8239 [ https://www.cve.org/CVERecord?id=3DCVE-2026-82=
    39 ] https://documentation.concretecms.org/9-x/developers/introduction/vers= ion-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is=C2=A0vuln= erable to unauthenticated page metadata disclosure across every page with a=
    configured summary template, revealing the existence of private, draft, an=
    d restricted pages while leaking title, path, description, and author infor= mation.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS = v.4.0 score of=C2=A06.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/= VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Winston Crooker for reporting. 2= 026-05-21 not yet calculated CVE-2026-8240 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-8240 ] https://documentation.concretecms.org/9-x/developers/i= ntroduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to Reflected XSS in Legacy Pagination via HTML attribute injection.=C2=A0= Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolatin=
    g its $URL field into href=3D"" (<a href=3D"{$linkURL}" =C3=A2=E2=82=AC=C2= =A6>).=C2=A0Any authenticated admin or report viewer with access to `/dashb= oard/reports/forms/legacy` who clicks the crafted URL fires the payload in = their session.=C2=A0The Concrete CMS security team gave this vulnerability =
    a CVSS v.4.0 score of=C2=A06.0 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:= N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) fo=
    r reporting 2026-05-21 not yet calculated CVE-2026-8245 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-8245 ] https://documentation.concretecms.org/9-x= /developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS below 9.5.0 and below is vul= nerable to password change without reauthorization and session-hardening by= pass.=C2=A0The user-profile edit controller passes the entire raw POST arra=
    y to UserInfo::update() without field whitelisting resulting in password ch= ange without requiring the current password=C2=A0 and also resulting in reg= istered users able to disable the per-user-IP-pinning in the session valida= tor which is meant to detect hijacking.=C2=A0=C2=A0The Concrete CMS securit=
    y team gave this vulnerability a CVSS v.4.0 score of 5.3 with vector=C2=A0C= VSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2= =A00x4c616e for reporting. 2026-05-21 not yet calculated CVE-2026-8327 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-8327 ] https://documentation.conc= retecms.org/9-x/developers/introduction/version-history/951-release-notes =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to IDOR in surveys.=C2=A0To be vulnerable, a=C2=A0site would have to be c= onfigured in such a way that both public and private surveys are present on=
    the site. An=C2=A0unauthenticated attacker can vote in the restricted surv=
    ey by submitting the restricted optionID through the public survey's endpoi= nt.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS v.4.=
    0 score of=C2=A06.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N= /VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0 Zer0daySec https://github.com/Zee99=
    y =C2=A0for reporting 2026-05-21 not yet calculated CVE-2026-8337 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-8337 ] https://documentation.concretec= ms.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to CSRF via Backend\File::approveVersion.=C2=A0Victim with=C2=A0edit_file= _contents=C2=A0permission is CSRF'd into publishing an attacker-chosen prev= iously-uploaded version (downgrade to an older version of a file, or activa= tion of a co-editor's unpublished version).=C2=A0The Concrete CMS security = team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector=C2=A0CVS= S:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winsto=
    n Crooker for reporting. 2026-05-22 not yet calculated CVE-2026-8340 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-8340 ] https://documentation.concre= tecms.org/9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to IDOR + wrong-authorization-level in the Express association Reorder di= alog.=C2=A0 This can cause=C2=A0Cross-entity state tampering=C2=A0with view= -only permission on one entry.=C2=A0To be affected, a website has to be usi=
    ng express and relying on express entity ordering.=C2=A0The Concrete CMS se= curity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector= =C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Than=
    ks Winston Crooker for reporting. 2026-05-22 not yet calculated CVE-2026-83=
    47 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8347 ] https://documentati= on.concretecms.org/9-x/developers/introduction/version-history/951-release-= notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below is vulnerabl=
    e to missing authorization in the bulk_user_assignment.php which can lead t=
    o privilege escalation=C2=A0to Administrative Group.=C2=A0Any authenticated=
    user with access to the bulk user assignment dashboard page can add any us=
    er email to any group and can remove legitimate admins.=C2=A0The Concrete C=
    MS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with vec= tor=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. T= hanks=C2=A0Vincent55 for reporting. 2026-05-21 not yet calculated CVE-2026-= 8350 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8350 ] https://documenta= tion.concretecms.org/9-x/developers/introduction/version-history/951-releas= e-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS version 9.0 to 9.5.0 is vuln= erable to Stored XSS via page name in the Atomik theme. A rogue editor=C2= =A0can inject arbitrary JavaScript that executes in the context of any auth= enticated user visiting the affected account pages. This can lead to sessio=
    n hijacking, credential theft, malicious actions performed on behalf of use= rs, and potential privilege escalation.=C2=A0The Concrete CMS security team=
    gave this vulnerability a CVSS v.4.0 score of=C2=A02.1 with vector=C2=A0CV= SS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0= Yonatan Drori (Tenzai) for reporting. 2026-05-22 not yet calculated CVE-202= 6-8353 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8353 ] https://documen= tation.concretecms.org/9-x/developers/introduction/version-history/951-rele= ase-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/d= elete.=C2=A0 The The Concrete CMS security team gave this vulnerability a C= VSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/V= C:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for report= ing. 2026-05-21 not yet calculated CVE-2026-8409 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-8409 ] https://documentation.concretecms.org/9-x/develo= pers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/b= ulk/delete.=C2=A0 The The Concrete CMS security team gave this vulnerabilit=
    y a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/U= I:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for r= eporting. 2026-05-21 not yet calculated CVE-2026-8410 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-8410 ] https://documentation.concretecms.org/9-x/d= evelopers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/b= ulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v= .4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/V= I:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting. = 2026-05-21 not yet calculated CVE-2026-8411 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-8411 ] https://documentation.concretecms.org/9-x/developers/= introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/b= ulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.= 4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI= :L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting. 2= 026-05-21 not yet calculated CVE-2026-8412 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-8412 ] https://documentation.concretecms.org/9-x/developers/i= ntroduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/b= ulk/design. The Concrete CMS security team gave this vulnerability a CVSS v= .4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/V= I:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting. = 2026-05-21 not yet calculated CVE-2026-8413 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-8413 ] https://documentation.concretecms.org/9-x/developers/= introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/= duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.= 4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI= :L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting. 2= 026-05-21 not yet calculated CVE-2026-8414 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-8414 ] https://documentation.concretecms.org/9-x/developers/i= ntroduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/expres= s/association/reorder. The Concrete CMS security team gave this vulnerabili=
    ty a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/= UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for = reporting. 2026-05-21 not yet calculated CVE-2026-8415 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-8415 ] https://documentation.concretecms.org/9-x/= developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file = addFavoriteFolder($id). The Concrete CMS security team gave this vulnerabil= ity a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N= /UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for=
    reporting. 2026-05-21 not yet calculated CVE-2026-8416 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-8416 ] https://documentation.concretecms.org/9-x= /developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below does not val= idate a CSRF token before processing requests to /dashboard/extend/update/d= o_update/<pkgHandle>. The do_update() method in concrete/controllers/single= _page/dashboard/extend/update.php checks only canInstallPackages() before e= xecuting upgradeCoreData() and upgrade() on the named package's controller.=
    Because the endpoint is a state-changing GET route with no token enforceme= nt, an attacker can force an authenticated administrator to trigger a packa=
    ge upgrade via a single cross-site navigation.In order to be vulnerable, th=
    e victim must be passing canInstallPackages() and and a target package must=
    already be already installed.=C2=A0The Concrete CMS security team gave thi=
    s vulnerability a CVSS v.4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV= :N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0 https://= github.com/maru1009 =C2=A0for reporting. 2026-05-21 not yet calculated CVE-= 2026-8417 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8417 ] https://docu= mentation.concretecms.org/9-x/developers/introduction/version-history/951-r= elease-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below contains a C= SRF vulnerability in the install_package() method of concrete/controllers/s= ingle_page/dashboard/extend/install.php. =C2=A0An attacker who can cause an=
    authenticated administrator to visit a crafted page,=C2=A0 and who has pla= ced or caused a package to be present under DIR_PACKAGES/<handle>/, can for=
    ce the installation of that package without any CSRF protection. Package in= stallation executes the package controller's install() method as the web se= rver user, enabling remote code execution.=C2=A0=C2=A0In order to be vulner= able, the victim must be passing canInstallPackages.=C2=A0The Concrete CMS = security team gave this vulnerability a CVSS v.4.0 score of=C2=A07.5 with v= ector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.=
    Thanks=C2=A0 https://github.com/maru1009 =C2=A0for reporting. 2026-05-21 n=
    ot yet calculated CVE-2026-8421 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-8421 ] https://documentation.concretecms.org/9-x/developers/introduction= /version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below does not val= idate a CSRF token before processing requests to /dashboard/extend/update/p= repare_remote_upgrade/<remoteMPID>. An attacker who controls the remote pac= kage returned for a known marketplace item ID can overwrite the package PHP=
    on disk and force its upgrade() method to execute in a single browser navi= gation. This results in remote code execution as the web server user.=C2=A0= =C2=A0=C2=A0In order to be vulnerable, the victim must be passing canInstal= lPackages,=C2=A0victim site must be connected to the Concrete marketplace; = and the attacker controls the package returned for a marketplace item ID al= ready installed on the victim site.=C2=A0The Concrete CMS security team gav=
    e this vulnerability a CVSS v.4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4= .0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0http= s://github.com/maru1009=C2=A0for reporting. 2026-05-21 not yet calculated C= VE-2026-8426 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8426 ] https://d= ocumentation.concretecms.org/9-x/developers/introduction/version-history/95= 1-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file = removeFavoriteFolder($id). The Concrete CMS security team gave this vulnera= bility a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/P= R:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) = for reporting. 2026-05-21 not yet calculated CVE-2026-8427 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-8427 ] https://documentation.concretecms.org/= 9-x/developers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9.5.0 and below emits a CSRF=
    token in the local_available_update.php view ($token->output('do_update'))=
    but the corresponding do_update() method in concrete/controllers/single_pa= ge/dashboard/system/update/update.php never calls $this->token->validate('d= o_update'). The form is rendered as a POST form, meaning the token reaches = the browser, but because the controller discards it without verification, a=
    n attacker can craft a cross-site POST that triggers a core CMS update to a=
    n attacker-specified version string.=C2=A0=C2=A0In order to be vulnerable, = theictim must be passing canUpgrade()anda valid update version must be pres= ent under DIR_CORE_UPDATES.=C2=A0The Concrete CMS security team gave this v= ulnerability a CVSS v.4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV:N/= AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0https://gith= ub.com/maru1009=C2=A0for reporting. 2026-05-21 not yet calculated CVE-2026-= 8428 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8428 ] https://documenta= tion.concretecms.org/9-x/developers/introduction/version-history/951-releas= e-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file = star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0=
    score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/= VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting. 2026= -05-21 not yet calculated CVE-2026-8432 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8432 ] https://documentation.concretecms.org/9-x/developers/int= roduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file = rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4=
    .0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:= L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting. 20= 26-05-21 not yet calculated CVE-2026-8433 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-8433 ] https://documentation.concretecms.org/9-x/developers/in= troduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file = rescanMultiple(). The Concrete CMS security team gave this vulnerability a = CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/= VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for repor= ting. 2026-05-21 not yet calculated CVE-2026-8434 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-8434 ] https://documentation.concretecms.org/9-x/devel= opers/introduction/version-history/951-release-notes
    =C2=A0 Concrete CMS--Concrete CMS Concrete CMS 9 before 9.5.0 is vulnerable=
    to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file = approveVersion().=C2=A0The Concrete CMS security team gave this vulnerabili=
    ty a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/= UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for = reporting. 2026-05-21 not yet calculated CVE-2026-8435 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-8435 ] https://documentation.concretecms.org/9-x/= developers/introduction/version-history/951-release-notes
    =C2=A0 Creartia Internet Consulting--ICMS Content Management Authorization = Bypass vulnerability in Creartia's ICMS software could allow an attacker to=
    gain unauthorized access to protected features by manipulating the HTTP re= direct headers of the login process, causing the script to continue running=
    and enabling privilege escalation without the need for credentials. 2026-0= 5-18 not yet calculated CVE-2026-4320 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-4320 ] https://www.incibe.es/en/incibe-cert/notices/aviso/authoriz= ation-bypass-icms-content-management-creartia-internet-consulting
    =C2=A0 cyntler--react-doc-viewer v1.17.1 Cross-Site Scripting (XSS) vulnera= bility in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to exec= ute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component=
    fails to sanitize file content and explicitly casts raw data as a ReactNod=
    e 2026-05-20 not yet calculated CVE-2026-30691 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-30691 ] https://github.com/cyntler/react-doc-viewer/issue= s/317
    https://github.com/walidriouah/CVE-2026-30691
    =C2=A0 Dell--Portrait Dell Color Management Application An issue was discov= ered in the Portrait Dell Color Management application before 3.7.0 for Del=
    l monitors. On Windows, a symbolic link vulnerability allows a local low-pr= ivileged user to escalate privileges to Administrator. During installation,=
    the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Port= rait Displays\CW\data\i1D3\ while running with elevated privileges. Because=
    the installer does not properly validate symbolic links or reparse points =
    at the destination path, an attacker can create a malicious link that redir= ects the write operation to an arbitrary system location, enabling arbitrar=
    y file creation or overwrite with elevated privileges. 2026-05-19 not yet c= alculated CVE-2026-34883 [ https://www.cve.org/CVERecord?id=3DCVE-2026-3488=
    3 ] https://www.portrait.com/dell-security-cve-updates/ https://www.portrait.com/dell
    =C2=A0 Devolutions--Server Improper access control in the entry activity lo=
    g feature in Devolutions Server allows an authenticated user with access to=
    an entry but without the required permission to retrieve that entry's acti= vity logs via a crafted API request. This issue affects : * Devolutions Ser= ver 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and ear= lier 2026-05-22 not yet calculated CVE-2026-5171 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-5171 ] https://devolutions.net/security/advisories/DEVO= -2026-0013/
    =C2=A0 Devolutions--Server Improper authorization in the Active Directory b= rowsing feature in Devolutions Server allows a low-privileged authenticated=
    user to obtain authentication material associated with a stored PAM provid=
    er service account via authentication relay to an attacker-controlled serve=
    r. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0=
    * Devolutions Server 2025.3.20.0 and earlier 2026-05-22 not yet calculated=
    CVE-2026-7325 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7325 ] https:/= /devolutions.net/security/advisories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Improper enforcement of the sealed-entry workflo=
    w in the entry sensitive-data retrieval feature in Devolutions Server allow=
    s an authenticated user with access to a sealed entry to retrieve its sensi= tive data without triggering the unseal audit notification via a crafted AP=
    I request. This issue affects : * Devolutions Server 2026.1.6.0 through 202= 6.1.16.0 * Devolutions Server 2025.3.20.0 and earlier 2026-05-22 not yet ca= lculated CVE-2026-8477 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8477 ]=
    https://devolutions.net/security/advisories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Improper handling of factor key state in the mul= ti-factor authentication management feature in Devolutions Server allows an=
    attacker with knowledge of a user's password to bypass the user's multi-fa= ctor authentication after the user reconfigures their factors. This issue a= ffects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 2026-05-22 not=
    yet calculated CVE-2026-9047 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -9047 ] https://devolutions.net/security/advisories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Missing authorization in the vault import featur=
    e in Devolutions Server=C2=A0=C2=A02026.1.16.0 and earlier allows a low-pri= vileged authenticated user to create new vaults via a crafted import reques=
    t. 2026-05-22 not yet calculated CVE-2026-9223 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-9223 ] https://devolutions.net/security/advisories/DEVO-2= 026-0013/
    =C2=A0 Devolutions--Server Missing authorization in the user profile update=
    feature in Devolutions Server allows an authenticated Active Directory use=
    r to modify their own profile attributes via a crafted API request. This is= sue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolut= ions Server 2025.3.20.0 and earlier 2026-05-22 not yet calculated CVE-2026-= 9224 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9224 ] https://devolutio= ns.net/security/advisories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Improper input validation in the external authen= tication provider flow in Devolutions Server allows an unauthenticated remo=
    te attacker to redirect victims to an attacker-controlled domain via a craf= ted login link. This issue affects : * Devolutions Server 2026.1.6.0 throug=
    h 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier 2026-05-22 not y=
    et calculated CVE-2026-9245 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9= 245 ] https://devolutions.net/security/advisories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Improper access control in the entry documentati=
    on and attachment features in Devolutions Server allows an authenticated us=
    er with vault read access to retrieve the documentation and attachments of = sealed entries via a crafted API request. This issue affects : * Devolution=
    s Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 an=
    d earlier 2026-05-22 not yet calculated CVE-2026-9246 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-9246 ] https://devolutions.net/security/advisories= /DEVO-2026-0013/
    =C2=A0 Devolutions--Server Insufficient logging in the entry export feature=
    in Devolutions Server allows an authenticated user with export permissions=
    to export a sealed entry without triggering the unseal notification to adm= inistrators via a crafted export request. This issue affects : * Devolution=
    s Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 an=
    d earlier 2026-05-22 not yet calculated CVE-2026-9247 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-9247 ] https://devolutions.net/security/advisories= /DEVO-2026-0013/
    =C2=A0 Devolutions--Server Authorization bypass in the entry duplication fe= ature in Devolutions Server allows an authenticated user with write access =
    to any vault to copy documentation and attachments from an entry in a vault=
    they cannot access via a crafted save request. This issue affects : * Devo= lutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.2= 0.0 and earlier 2026-05-22 not yet calculated CVE-2026-9248 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-9248 ] https://devolutions.net/security/advi= sories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Unverified password change in Devolutions Server=
    allows an attacker to change a user's password without providing the previ= ous one via a crafted password change request. This issue affects : * Devol= utions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20=
    .0 and earlier 2026-05-22 not yet calculated CVE-2026-9249 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-9249 ] https://devolutions.net/security/advis= ories/DEVO-2026-0013/
    =C2=A0 Devolutions--Server Missing authorization in the entry status manage= ment feature in Devolutions Server allows a non-administrator authenticated=
    user to bypass the administrator-enforced Pending Approval flow and gain a= ccess to an entry's data via a crafted status change request. This issue af= fects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions S= erver 2025.3.20.0 and earlier 2026-05-22 not yet calculated CVE-2026-9251 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-9251 ] https://devolutions.net= /security/advisories/DEVO-2026-0013/
    =C2=A0 discourse--discourse Discourse is an open-source discussion platform=
    . In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, =
    an authenticated user on a Discourse instance with the form templates featu=
    re enabled can read the name and structured content of form templates that = are intended exclusively for categories they are not authorized to access. = Impact is limited to disclosure of site configuration metadata. This issue = has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest= .1. 2026-05-19 not yet calculated CVE-2026-33514 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-33514 ] https://github.com/discourse/discourse/security= /advisories/GHSA-w6g7-p2p9-2m5h https://github.com/discourse/discourse/commit/ae5c9570fb918442c4d96abc83c1e= 7e169909b02
    =C2=A0 discourse--discourse Discourse is an open-source discussion platform=
    . In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, =
    a vulnerability in the discourse-subscriptions plugin allows users to gain = access to subscription-gated groups without completing payment. This issue = has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest= .1. 2026-05-19 not yet calculated CVE-2026-34154 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-34154 ] https://github.com/discourse/discourse/security= /advisories/GHSA-pjgj-7mjq-6j7g
    =C2=A0 Drupal--Colorbox Inline Improper Neutralization of Input During Web = Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox I= nline allows Cross-Site Scripting (XSS). This issue affects Colorbox Inline=
    : from 0.0.0 before 2.1.1. 2026-05-19 not yet calculated CVE-2026-8493 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-8493 ] https://www.drupal.org/sa-= contrib-2026-036
    =C2=A0 Drupal--Date iCal Missing Authorization vulnerability in Drupal Date=
    iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 be= fore 4.0.15. 2026-05-19 not yet calculated CVE-2026-8495 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-8495 ] https://www.drupal.org/sa-contrib-2026-0=
    37
    =C2=A0 Drupal--Drupal core Improper Neutralization of Input During Web Page=
    Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core al= lows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0=
    before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from=
    11.3.0 before 11.3.7. 2026-05-19 not yet calculated CVE-2026-6365 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-6365 ] https://www.drupal.org/sa-core= -2026-001
    =C2=A0 Drupal--Drupal core Improperly Controlled Modification of Dynamicall= y-Determined Object Attributes vulnerability in Drupal Drupal core allows O= bject Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, = from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 1= 1.3.7. 2026-05-19 not yet calculated CVE-2026-6366 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-6366 ] https://www.drupal.org/sa-core-2026-002
    =C2=A0 Drupal--Drupal core Improper Neutralization of Input During Web Page=
    Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core al= lows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.=
    0 before 11.3.7. 2026-05-19 not yet calculated CVE-2026-6367 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-6367 ] https://www.drupal.org/sa-core-2026-= 003
    =C2=A0 Drupal--Node View Permissions Improper Check for Unusual or Exceptio= nal Conditions vulnerability in Drupal Node View Permissions allows Forcefu=
    l Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7= .0, from 2.0.0 before 2.0.1. 2026-05-19 not yet calculated CVE-2026-8491 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-8491 ] https://www.drupal.org/s= a-contrib-2026-034
    =C2=A0 Drupal--Obfuscate Improper Neutralization of Input During Web Page G= eneration ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows=
    Cross-Site Scripting (XSS). This issue affects Obfuscate: from 0.0.0 befor=
    e 2.0.2. 2026-05-19 not yet calculated CVE-2026-6871 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-6871 ] https://www.drupal.org/sa-contrib-2026-033 =C2=A0 Drupal--Orejime Improper Neutralization of Input During Web Page Gen= eration ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cro= ss-Site Scripting (XSS). This issue affects Orejime: from 0.0.0 before 2.0.= 16. 2026-05-19 not yet calculated CVE-2026-6095 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-6095 ] https://www.drupal.org/sa-contrib-2026-032
    =C2=A0 Drupal--Simple Hierarchical Select (shs) Simple Hierarchical Select = (SHS) for Drupal 7 contains cross-site scripting risk due to improper outpu=
    t escaping of term-derived text. Confirmed affected paths include field for= matter output (shs_field_formatter_view) and term-tree child-term data gene= ration (shs_term_get_children). Malicious taxonomy term names can be render=
    ed unsafely depending on output context. This affects versions from 7.x-1.0=
    through (and including) 7.x-1.10. 2026-05-21 not yet calculated CVE-2026-4= 929 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4929 ] NES patch branch c= omparison [ https://www.herodevs.com/vulnerability-directory/cve-2026-4929 ] https://d7es.tag1.com/security-advisories/simple-hierarchical-select-modera= tely-critical-cross-site-scripting
    =C2=A0 Drupal--Term Reference Tree In the Drupal 7 Term Reference Tree modu= le, two stored XSS vectors exist in the widget/formatter rendering pipeline=
    . Vector A (token display templates): When the Token module is enabled and = token display templates are configured, attacker-controlled token output (e= .g., term description) is rendered without proper sanitization. Any user wh=
    o can edit the referenced taxonomy terms can inject HTML/JS that executes w= hen the field is rendered. Vector B (term label rendering): Taxonomy term l= abels are not properly sanitized before being rendered in the widget, allow= ing a user with permission to create or edit taxonomy terms to inject scrip=
    ts into the term name that execute when a form containing the widget is vie= wed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11. 2026-05= -21 not yet calculated CVE-2026-4093 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-4093 ] https://www.herodevs.com/vulnerability-directory/cve-2026-40=
    93
    https://d7es.tag1.com/security-advisories/taxonomy-term-reference-tree-widg= et-moderately-critical-cross-site-scripting
    =C2=A0 Drupal--Translate Drupal with GTranslate Modification of Assumed-Imm= utable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate=
    allows Resource Location Spoofing. This issue affects Translate Drupal wit=
    h GTranslate: from 0.0.0 before 3.0.5. 2026-05-19 not yet calculated CVE-20= 26-8492 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8492 ] https://www.dr= upal.org/sa-contrib-2026-035
    =C2=A0 Easy Chat--Easy Chat Server 3.1 Directory Traversal vulnerability in=
    Easy Chat Server 3.1 allows a remote attacker to obtain sensitive informat= ion and execute arbitrary code via the UserName parameter 2026-05-22 not ye=
    t calculated CVE-2026-36227 [ https://www.cve.org/CVERecord?id=3DCVE-2026-3= 6227 ] http://easy.com
    https://github.com/NullByte8080/CVE-2026-36227
    =C2=A0 Easy Chat--Easy Chat Server 3.1 Buffer Overflow vulnerability in Eas=
    y Chat Server 3.1 allows a remote attacker to obtain sensitive information = and execute arbitrary code via the chat message functionality 2026-05-22 no=
    t yet calculated CVE-2026-36228 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-36228 ] http://easy.com
    https://github.com/NullByte8080/CVE-2026-36228
    =C2=A0 Espon--Epson L14150 FL27PB Buffer Overflow vulnerability in EPSON L1= 4150 FL27PB allows a remote attacker to execute arbitrary code via the RAW = Printing Service (JetDirect) on TCP port 9100 2026-05-20 not yet calculated=
    CVE-2026-39047 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39047 ] https= ://github.com/AzhariRamadhan/CVE-PORT-9100 https://gist.github.com/AzhariRamadhan/1defc815542fb72e6025da2ce53a1046
    =C2=A0 Follett--Software's Destiny Library Manager Directory traversal in F= ollett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU=
    1 allows remote attackers to read arbitrary system and application files vi=
    a the image parameter 2026-05-22 not yet calculated CVE-2025-45145 [ https:= //www.cve.org/CVERecord?id=3DCVE-2025-45145 ] http://follett.com https://medium.com/@jaredutahusa/cve-2025-45145-unauthenticated-local-file-= inclusion-in-fsc-destiny-40a3f11b3a4d
    =C2=A0 frappe--frappe Frappe is a full-stack web application framework. Ver= sions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read = vulnerability via Path Traversal. The issue is resolved in versions 16.15.0=
    , 15.105.0 and above. 2026-05-20 not yet calculated CVE-2026-39352 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-39352 ] https://github.com/frappe/fra= ppe/security/advisories/GHSA-67rf-pxgh-vfqv https://github.com/frappe/frappe/releases/tag/v16.15.0
    =C2=A0 frappe--lms Frappe Learning Management System (LMS) is a learning sy= stem that helps users structure their content. In versions 2.50.0 and below=
    , a user with course editing role could upload a SCORM ZIP package to write=
    files outside the intended directory. This issue has been resolved in vers= ion 2.50.1. 2026-05-20 not yet calculated CVE-2026-39405 [ https://www.cve.= org/CVERecord?id=3DCVE-2026-39405 ] https://github.com/frappe/lms/security/= advisories/GHSA-mxh7-g3r7-g96h https://github.com/frappe/lms/releases/tag/v2.50.1
    =C2=A0 FreeBSD--FreeBSD libcasper(3) communicates with helper processes via=
    UNIX domain sockets, and uses the select(2) system call to wait for data t=
    o become available. However, it does not verify that its socket descriptor = fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024). An = attacker able to cause an application using libcasper(3) to allocate large = file descriptors, e.g., by opening many descriptors and executing a program=
    which is not careful to close them upon startup, may trigger stack corrupt= ion. If the target application runs with setuid root privileges, this could=
    be used to escalate local privileges. 2026-05-21 not yet calculated CVE-20= 26-39461 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39461 ] https://secu= rity.freebsd.org/advisories/FreeBSD-SA-26:22.libcasper.asc
    =C2=A0 FreeBSD--FreeBSD The setcred(2) system call is only available to pri= vileged users. However, before the privilege level of the caller is checked=
    , the user-supplied list of supplementary groups is copied into a fixed-siz=
    e kernel stack buffer without first validating its length. If the supplied = list exceeds the capacity of that buffer, a stack buffer overflow occurs. B= ecause the bounds check on the supplementary groups list occurs after the k= ernel stack buffer has already been written, an unprivileged local user may=
    trigger the overflow without holding any special privilege. Successful exp= loitation may allow an attacker to execute arbitrary code in the context of=
    the kernel, allowing an unprivileged local user to gain elevated privilege=
    s on the affected system. 2026-05-21 not yet calculated CVE-2026-45250 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-45250 ] https://security.freebsd.= org/advisories/FreeBSD-SA-26:18.setcred.asc
    =C2=A0 FreeBSD--FreeBSD A file descriptor can be closed while a thread is b= locked in a poll(2) or select(2) call waiting for that descriptor. Because = the blocked thread does not hold a reference to the underlying object, this=
    closure may result in the object being freed while the thread remains bloc= ked. In this situation, the kernel must remove the blocked thread from the = per-object wait queue prior to freeing the object. In the case of some file=
    descriptor types, the kernel failed to unlink blocked threads from the obj= ect before freeing it. When the blocked thread is subsequently woken, it ac= cesses memory that has already been freed resulting in a use-after-free vul= nerability. The use-after-free vulnerability may be triggered by an unprivi= leged local user and can be exploited to obtain superuser privileges. 2026-= 05-21 not yet calculated CVE-2026-45251 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-45251 ] https://security.freebsd.org/advisories/FreeBSD-SA-26:1= 9.file.asc
    =C2=A0 FreeBSD--FreeBSD When a fusefs file system implements extended attri= butes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon=
    to retrieve the list of extended attributes for a given file. The FUSE pro= tocol requires the daemon to return a packed list of NUL-terminated strings=
    . The fusefs kernel module calls strlen() on this daemon-supplied buffer wi= thout first verifying that the entire list is NUL-terminated. If a maliciou=
    s daemon sends a non-NUL-terminated list, the fusefs kernel module may read=
    beyond the end of one heap-allocated buffer and potentially write beyond t=
    he end of a second buffer. A malicious daemon could disclose up to 253 byte=
    s of kernel heap memory, or it could inject up to 250 attacker-controlled b= ytes into unallocated kernel heap space. 2026-05-21 not yet calculated CVE-= 2026-45252 [ https://www.cve.org/CVERecord?id=3DCVE-2026-45252 ] https://se= curity.freebsd.org/advisories/FreeBSD-SA-26:20.fusefs.asc
    =C2=A0 FreeBSD--FreeBSD ptrace(PT_SC_REMOTE) failed to properly validate pa= rameters for the syscall(2) and __syscall(2) meta-system calls. As a result=
    , a user with the ability to debug a process may trigger arbitrary code exe= cution in the kernel, even if the target process has no special privileges.=
    The missing validation allows an unprivileged local user to escalate privi= leges, potentially gaining full control of the affected system. 2026-05-21 = not yet calculated CVE-2026-45253 [ https://www.cve.org/CVERecord?id=3DCVE-= 2026-45253 ] https://security.freebsd.org/advisories/FreeBSD-SA-26:21.ptrac= e.asc
    =C2=A0 FreeBSD--FreeBSD In the case of the cap_net service, when a key pres= ent in the old limit was omitted from the new limit, the missing key was tr= eated as "allow any" instead of being rejected. In certain scenarios, an ap= plication that had previously restricted a subset of network operations cou=
    ld ask for a new limit that extended the permissions of the process. 2026-0= 5-21 not yet calculated CVE-2026-45254 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-45254 ] https://security.freebsd.org/advisories/FreeBSD-SA-26:2= 4.cap_net.asc
    =C2=A0 FreeBSD--FreeBSD When bsdinstall or bsdconfig are prompted to scan f=
    or nearby Wi-Fi networks, they build up a list of network names and use bsd= dialog(1) to prompt the user to select a network. This is implemented using=
    a shell script, and the code which handled network names was not careful t=
    o prevent expansion by the shell. As a result, a suitably crafted network n= ame can be used to execute commands via a subshell. The problem can be expl= oited to execute code as root on the system running bsdinstall or bsdconfig=
    . The attacker would need to create an access point with a specially crafte=
    d name and be within range of a Wi-Fi scan. Note that bsdinstall and bsdcon= fig are vulnerable as soon as the user prompts them to scan for nearby netw= orks; they do not need to actually select the malicious network. 2026-05-21=
    not yet calculated CVE-2026-45255 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-45255 ] https://security.freebsd.org/advisories/FreeBSD-SA-26:23.bsdi= nstall.asc
    =C2=A0 FreePBX--security-reporting FreePBX is an open source IP PBX. In ver= sions below 16.0.71 and 17.0.6, the backup module does not properly sanitiz=
    e data during restore operations, potentially leading to compromise if the = backup contains carefully crafted hostile data. During backup restore opera= tions, FreePBX extracts selected files from a user-supplied tar archive. If=
    a malicious file exists in the archive, it is read and passed directly to = unserialize() without validation, class restrictions, or integrity checks. = This issue allows Remote Code Execution during restoration of the backup as=
    the web server user (typically asterisk or www-data). The attack does not = require shell access, CLI access, or filesystem write permissions beyond th=
    e normal restore workflow. Authentication with a known username that has su= fficient access permissions and/or write access to backup files is required=
    . This issue has been fixed in versions 16.0.71 and 17.0.6. 2026-05-18 not = yet calculated CVE-2026-26978 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -26978 ] https://github.com/FreePBX/security-reporting/security/advisories/= GHSA-5v7h-49gr-jcwr https://github.com/FreePBX/backup/commit/45c57e1207cbf9fd1c5f76f8a3e72d204a= 69a472 https://github.com/FreePBX/backup/commit/64781af5c80cce0cff21a981be4d8e6a7a= 71f2c4
    =C2=A0 glpi-project--glpi GLPI is a free asset and IT management software p= ackage. In versions 11.0.0 through 11.0.6, an authenticated user with forms=
    READ permission can export the structure of unauthorized forms. This issue=
    has been fixed in version 11.0.7. 2026-05-18 not yet calculated CVE-2026-3= 2312 [ https://www.cve.org/CVERecord?id=3DCVE-2026-32312 ] https://github.c= om/glpi-project/glpi/security/advisories/GHSA-cg63-qchq-q626 https://github.com/glpi-project/glpi/releases/tag/11.0.7
    =C2=A0 goauthentik--authentik authentik is an open-source identity provider=
    . In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent= icated non-admin users with at least one OAuth2 access token can retrieve t=
    he client_secret of confidential OAuth2 providers they have previously auth= enticated against, exposing sensitive information to users without the corr= ect permissions. This logic is GET /api/v3/oauth2/access_tokens/. The API r= esponse includes a nested provider object containing client_id and client_s= ecret for providers configured with client_type: confidential, which should=
    not be accessible to low-privilege users. This issue has been fixed in ver= sions 2025.12.5 and 2026.2.3. 2026-05-22 not yet calculated CVE-2026-40166 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-40166 ] https://github.com/go= authentik/authentik/security/advisories/GHSA-hhpc-rqgm-pxj4 https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12.5 https://github.com/goauthentik/authentik/releases/tag/version%2F2026.2.3
    =C2=A0 gohttp--gohttp An issue in gohttp commit 34ea51 allows attackers to = execute a directory traversal via supplying a crafted request. 2026-05-19 n=
    ot yet calculated CVE-2025-70950 [ https://www.cve.org/CVERecord?id=3DCVE-2= 025-70950 ] https://github.com/itang/gohttp/issues/13 https://gist.github.com/Lime-Cocoa/202127ae5f4dcc4b39909ce7ac1c8466
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh An authenticated SSH cl= ient that repeatedly opened channels which were rejected by the server caus=
    ed unbounded memory growth, eventually crashing the server process and affe= cting all connected users. Rejected channels are now properly removed from = the connection's internal state and released for garbage collection. 2026-0= 5-22 not yet calculated CVE-2026-39827 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-39827 ] https://go.dev/issue/35127
    https://go.dev/cl/781320 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://pkg.go.dev/vuln/GO-2026-5016
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh When an SSH server auth= entication callback returned PartialSuccessError with non-nil Permissions, = those permissions were silently discarded, potentially dropping certificate=
    restrictions such as force-command after a second factor succeeded. Return= ing non-nil Permissions with PartialSuccessError now results in a connectio=
    n error. 2026-05-22 not yet calculated CVE-2026-39828 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-39828 ] https://go.dev/issue/79562 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781621
    https://pkg.go.dev/vuln/GO-2026-5014
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh The RSA and DSA public = key parsers did not enforce size limits on key parameters. A crafted public=
    key with an excessively large modulus or DSA parameter could cause several=
    minutes of CPU consumption during signature verification. This could be tr= iggered by unauthenticated clients during public key authentication. RSA mo= duli are now limited to 8192 bits, and DSA parameters are validated per FIP=
    S 186-2. 2026-05-22 not yet calculated CVE-2026-39829 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-39829 ] https://go.dev/issue/79565 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781641
    https://go.dev/cl/781661
    https://pkg.go.dev/vuln/GO-2026-5018
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh A malicious SSH peer co= uld send unsolicited global request responses to fill an internal buffer, b= locking the connection's read loop. The blocked goroutine could not be rele= ased by calling Close(), resulting in a resource leak per connection. Unsol= icited global responses are now discarded. 2026-05-22 not yet calculated CV= E-2026-39830 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39830 ] https://= go.dev/issue/79564
    https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781640
    https://go.dev/cl/781664
    https://pkg.go.dev/vuln/GO-2026-5017
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh The Verify() method for=
    FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed= 25519@openssh.com) did not check the User Presence flag. Signatures generat=
    ed without physical touch were accepted, allowing unattended use of a hardw= are security key. To restore the previous behavior, return a "no-touch-requ= ired" extension in Permissions.Extensions from PublicKeyCallback. 2026-05-2=
    2 not yet calculated CVE-2026-39831 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-39831 ] https://go.dev/issue/79566 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781662
    https://pkg.go.dev/vuln/GO-2026-5019
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh When writing data large=
    r than 4GB in a single Write call on an SSH channel, an integer overflow in=
    the internal payload size calculation caused the write loop to spin indefi= nitely, sending empty packets without making progress. The size comparison = now uses int64 to prevent truncation. 2026-05-22 not yet calculated CVE-202= 6-39834 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39834 ] https://go.de= v/issue/79567
    https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781663
    https://pkg.go.dev/vuln/GO-2026-5020
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh SSH servers which use C= ertChecker as a public key callback without setting IsUserAuthority or IsHo= stAuthority could be caused to panic by a client presenting a certificate. = CertChecker now returns an error instead of panicking when these callbacks = are nil. 2026-05-22 not yet calculated CVE-2026-39835 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-39835 ] https://go.dev/issue/79563 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781660
    https://pkg.go.dev/vuln/GO-2026-5015
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh Previously, CVE-2024-45= 337 fixed an authorization bypass for misused ssh server configurations; if=
    any other type of callback is passed other than public key, then the sourc= e-address validation would be skipped. 2026-05-22 not yet calculated CVE-20= 26-46595 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46595 ] https://go.d= ev/issue/79570
    https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781642
    https://pkg.go.dev/vuln/GO-2026-5023
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh An incorrectly placed c= ast from bytes to int allowed for server-side panic in the AES-GCM packet d= ecoder for well-crafted inputs. 2026-05-22 not yet calculated CVE-2026-4659=
    7 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46597 ] https://go.dev/issu= e/79561
    https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://go.dev/cl/781620
    https://pkg.go.dev/vuln/GO-2026-5013
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh/agent When adding a key=
    to a remote agent constraint extensions such as restrict-destination-v00@o= penssh.com were not serialized in the request. Destination restrictions wer=
    e silently stripped when forwarding keys, allowing unrestricted use of the = key on the remote host. The client now serializes all constraint extensions=
    . Additionally, the in-memory keyring returned by NewKeyring() now rejects = keys with unsupported constraint extensions instead of silently ignoring th= em. 2026-05-22 not yet calculated CVE-2026-39832 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-39832 ] https://go.dev/issue/79435
    https://go.dev/cl/778642 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://pkg.go.dev/vuln/GO-2026-5006
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh/agent The in-memory key= ring returned by NewKeyring() silently accepted keys with the ConfirmBefore= Use constraint but never enforced it. The key would sign without any confir= mation prompt, with no indication to the caller that the constraint was not=
    in effect. NewKeyring() now returns an error when unsupported constraints = are requested. 2026-05-22 not yet calculated CVE-2026-39833 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-39833 ] https://go.dev/issue/79436 https://go.dev/cl/778640
    https://go.dev/cl/778641 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://pkg.go.dev/vuln/GO-2026-5005
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh/agent For certain craft=
    ed inputs, a 'ed25519.PrivateKey' was created by casting malformed wire byt= es, leading to a panic when used. 2026-05-22 not yet calculated CVE-2026-46= 598 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46598 ] https://go.dev/is= sue/79596
    https://go.dev/cl/781360 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://pkg.go.dev/vuln/GO-2026-5033
    =C2=A0 golang.org/x/crypto--golang.org/x/crypto/ssh/knownhosts Previously, =
    a revoked 'SignatureKey' belonging to a CA was not correctly checked for re= vocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revok= ed. 2026-05-22 not yet calculated CVE-2026-42508 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-42508 ] https://go.dev/issue/79568
    https://go.dev/cl/781220 https://groups.google.com/g/golang-announce/c/a082jnz-LvI https://pkg.go.dev/vuln/GO-2026-5021
    =C2=A0 golang.org/x/net--golang.org/x/net/html Parsing arbitrary HTML can c= onsume excessive CPU time, possibly leading to denial of service. 2026-05-2=
    2 not yet calculated CVE-2026-25680 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-25680 ] https://go.dev/cl/781702
    https://go.dev/issue/79573 https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://pkg.go.dev/vuln/GO-2026-5028
    =C2=A0 golang.org/x/net--golang.org/x/net/html Parsing arbitrary HTML which=
    is then rendered using Render can result in an unexpected HTML tree. This = can be leveraged to execute XSS attacks in applications that attempt to san= itize input HTML before rendering. 2026-05-22 not yet calculated CVE-2026-2= 5681 [ https://www.cve.org/CVERecord?id=3DCVE-2026-25681 ] https://go.dev/i= ssue/79574
    https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://go.dev/cl/781703
    https://pkg.go.dev/vuln/GO-2026-5029
    =C2=A0 golang.org/x/net--golang.org/x/net/html Parsing arbitrary HTML which=
    is then rendered using Render can result in an unexpected HTML tree. This = can be leveraged to execute XSS attacks in applications that attempt to san= itize input HTML before rendering. 2026-05-22 not yet calculated CVE-2026-2= 7136 [ https://www.cve.org/CVERecord?id=3DCVE-2026-27136 ] https://go.dev/i= ssue/79575
    https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://go.dev/cl/781685
    https://pkg.go.dev/vuln/GO-2026-5030
    =C2=A0 golang.org/x/net--golang.org/x/net/html Parsing arbitrary HTML which=
    is then rendered using Render can result in an unexpected HTML tree. This = can be leveraged to execute XSS attacks in applications that attempt to san= itize input HTML before rendering. 2026-05-22 not yet calculated CVE-2026-4= 2502 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42502 ] https://go.dev/i= ssue/79572
    https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://go.dev/cl/781701
    https://pkg.go.dev/vuln/GO-2026-5027
    =C2=A0 golang.org/x/net--golang.org/x/net/html Parsing arbitrary HTML which=
    is then rendered using Render can result in an unexpected HTML tree. This = can be leveraged to execute XSS attacks in applications that attempt to san= itize input HTML before rendering. 2026-05-22 not yet calculated CVE-2026-4= 2506 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42506 ] https://go.dev/i= ssue/79571
    https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://go.dev/cl/781700
    https://pkg.go.dev/vuln/GO-2026-5025
    =C2=A0 golang.org/x/net--golang.org/x/net/idna The ToASCII and ToUnicode fu= nctions incorrectly accept Punycode-encoded labels that decode to an ASCII-= only label. For example, ToUnicode("xn--example-.com") incorrectly returns = the name "example.com" rather than an error. This behavior can lead to priv= ilege escalation in programs using the idna package. For example, a program=
    which performs privilege checks on the ASCII hostname may reject "example.= com" but permit "xn--example-.com". If that program subsequently converts t=
    he ASCII hostname to Unicode, it will inadvertently permits access to the U= nicode name "example.com". 2026-05-22 not yet calculated CVE-2026-39821 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-39821 ] https://go.dev/cl/767220 https://go.dev/issue/78760 https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 https://pkg.go.dev/vuln/GO-2026-5026
    =C2=A0 golang.org/x/sys--golang.org/x/sys/windows NewNTUnicodeString does n=
    ot check for string length overflow. When provided with a string that overf= lows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it r= eturns a truncated string rather than an error. 2026-05-22 not yet calculat=
    ed CVE-2026-39824 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39824 ] htt= ps://go.dev/issue/78916
    https://go.dev/cl/770080 https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg https://pkg.go.dev/vuln/GO-2026-5024
    =C2=A0 Google--Chrome Inappropriate implementation in UI in Google Chrome o=
    n Windows prior to 148.0.7778.179 allowed a remote attacker who had comprom= ised the renderer process to perform UI spoofing via a crafted HTML page. (= Chromium security severity: Critical) 2026-05-20 not yet calculated CVE-202= 6-9110 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9110 ] https://chromer= eleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308= .html
    https://issues.chromium.org/issues/503551154
    =C2=A0 Google--Chrome Use after free in WebRTC in Google Chrome on Linux pr= ior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code v=
    ia a crafted HTML page. (Chromium security severity: Critical) 2026-05-20 n=
    ot yet calculated CVE-2026-9111 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-9111 ] https://chromereleases.googleblog.com/2026/05/stable-channel-upda= te-for-desktop_0841193308.html
    https://issues.chromium.org/issues/504551032
    =C2=A0 Google--Chrome Use after free in GPU in Google Chrome on Windows pri=
    or to 148.0.7778.179 allowed a remote attacker to execute arbitrary code in= side a sandbox via a crafted HTML page. (Chromium security severity: High) = 2026-05-20 not yet calculated CVE-2026-9112 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-9112 ] https://chromereleases.googleblog.com/2026/05/stable-= channel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/489791425
    =C2=A0 Google--Chrome Out of bounds read in GPU in Google Chrome on Mac pri=
    or to 148.0.7778.179 allowed a remote attacker to perform an out of bounds = memory read via a crafted HTML page. (Chromium security severity: High) 202= 6-05-20 not yet calculated CVE-2026-9113 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-9113 ] https://chromereleases.googleblog.com/2026/05/stable-cha= nnel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/489585044
    =C2=A0 Google--Chrome Use after free in QUIC in Google Chrome on prior to 1= 48.0.7778.179 allowed a remote attacker to execute arbitrary code inside a = sandbox via malicious network traffic. (Chromium security severity: High) 2= 026-05-20 not yet calculated CVE-2026-9114 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-9114 ] https://chromereleases.googleblog.com/2026/05/stable-c= hannel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/495798630
    =C2=A0 Google--Chrome Insufficient policy enforcement in Service Worker in = Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypas=
    s same origin policy via a crafted HTML page. (Chromium security severity: = High) 2026-05-20 not yet calculated CVE-2026-9115 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-9115 ] https://chromereleases.googleblog.com/2026/05/s= table-channel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/495999481
    =C2=A0 Google--Chrome Insufficient policy enforcement in ServiceWorker in G= oogle Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak c= ross-origin data via a crafted HTML page. (Chromium security severity: High=
    ) 2026-05-20 not yet calculated CVE-2026-9116 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2026-9116 ] https://chromereleases.googleblog.com/2026/05/stabl= e-channel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/497436273
    =C2=A0 Google--Chrome Type Confusion in GFX in Google Chrome on Linux, Chro= meOS prior to 148.0.7778.179 allowed a remote attacker who had compromised = the renderer process to potentially perform a sandbox escape via a crafted = video file. (Chromium security severity: High) 2026-05-20 not yet calculate=
    d CVE-2026-9117 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9117 ] https:= //chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0= 841193308.html
    https://issues.chromium.org/issues/497542537
    =C2=A0 Google--Chrome Use after free in XR in Google Chrome on Windows prio=
    r to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via=
    a crafted HTML page. (Chromium security severity: High) 2026-05-20 not yet=
    calculated CVE-2026-9118 [ https://www.cve.org/CVERecord?id=3DCVE-2026-911=
    8 ] https://chromereleases.googleblog.com/2026/05/stable-channel-update-for= -desktop_0841193308.html
    https://issues.chromium.org/issues/498702233
    =C2=A0 Google--Chrome Heap buffer overflow in WebRTC in Google Chrome on pr= ior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code i= nside a sandbox via a crafted HTML page. (Chromium security severity: High)=
    2026-05-20 not yet calculated CVE-2026-9119 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-9119 ] https://chromereleases.googleblog.com/2026/05/stable= -channel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/502661101
    =C2=A0 Google--Chrome Use after free in WebRTC in Google Chrome prior to 14= 8.0.7778.179 allowed a remote attacker to execute arbitrary code via a craf= ted HTML page. (Chromium security severity: High) 2026-05-20 not yet calcul= ated CVE-2026-9120 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9120 ] htt= ps://chromereleases.googleblog.com/2026/05/stable-channel-update-for-deskto= p_0841193308.html
    https://issues.chromium.org/issues/504620824
    =C2=A0 Google--Chrome Out of bounds read in GPU in Google Chrome on prior t=
    o 148.0.7778.179 allowed a remote attacker to potentially exploit heap corr= uption via a crafted HTML page. (Chromium security severity: Medium) 2026-0= 5-20 not yet calculated CVE-2026-9121 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-9121 ] https://chromereleases.googleblog.com/2026/05/stable-channe= l-update-for-desktop_0841193308.html https://issues.chromium.org/issues/488064108
    =C2=A0 Google--Chrome Out of bounds read in GPU in Google Chrome on Mac pri=
    or to 148.0.7778.179 allowed a remote attacker to obtain potentially sensit= ive information from process memory via a crafted HTML page. (Chromium secu= rity severity: Medium) 2026-05-20 not yet calculated CVE-2026-9122 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-9122 ] https://chromereleases.googleb= log.com/2026/05/stable-channel-update-for-desktop_0841193308.html https://issues.chromium.org/issues/489579953
    =C2=A0 Google--Chrome Heap buffer overflow in Chromecast in Google Chrome o=
    n Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker=
    to execute arbitrary code inside a sandbox via malicious network traffic. = (Chromium security severity: Medium) 2026-05-20 not yet calculated CVE-2026= -9123 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9123 ] https://chromere= leases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.= html
    https://issues.chromium.org/issues/495988507
    =C2=A0 Google--Chrome Insufficient validation of untrusted input in Input i=
    n Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who ha=
    d compromised the renderer process to leak cross-origin data via a crafted = HTML page. (Chromium security severity: Medium) 2026-05-20 not yet calculat=
    ed CVE-2026-9124 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9124 ] https= ://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_= 0841193308.html
    https://issues.chromium.org/issues/496375695
    =C2=A0 Google--Chrome Use after free in DOM in Google Chrome on prior to 14= 8.0.7778.179 allowed a remote attacker to execute arbitrary code inside a s= andbox via a crafted HTML page. (Chromium security severity: Medium) 2026-0= 5-20 not yet calculated CVE-2026-9126 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-9126 ] https://chromereleases.googleblog.com/2026/05/stable-channe= l-update-for-desktop_0841193308.html https://issues.chromium.org/issues/496280532
    =C2=A0 HP Inc--HP Linux Imaging and Printing Software A potential security = vulnerability has been identified in the HP Linux Imaging and Printing Soft= ware. This potential vulnerability may allow escalation of privileges and/o=
    r arbitrary code execution via an integer overflow in the hpcups processing=
    path when handling crafted print data. 2026-05-20 not yet calculated CVE-2= 026-8631 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8631 ] https://suppo= rt.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118
    =C2=A0 HP Inc--HP Linux Imaging and Printing Software A potential security = vulnerability has been identified in the HP Linux Imaging and Printing Soft= ware. This potential vulnerability may allow escalation of privileges and/o=
    r arbitrary code execution via operating system command injection. 2026-05-=
    20 not yet calculated CVE-2026-8632 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-8632 ] https://support.hp.com/us-en/document/ish_14942099-14942126-1= 6/hpsbpi04118
    =C2=A0 HP-- ENVY 5000 HP ENVY 5000 series printers VERBASPP1N003.2237A.00 d=
    o not properly manage concurrent TCP connections to port 9100 (JetDirect/RA=
    W printing). An unauthenticated remote attacker on the same network can est= ablish a persistent connection to port 9100 and send keep-alive packets, ca= using the printer's session threads to remain locked in a waiting state. Th=
    e firmware lacks connection timeouts and concurrent session limits, resulti=
    ng in a persistent Denial of Service (DoS) that renders the printer unrespo= nsive to all user commands and print jobs. Physical intervention (manual re= start) is required to restore functionality, and the attack can be immediat= ely re-initiated. 2026-05-22 not yet calculated CVE-2026-42626 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-42626 ] https://medium.com/@jacobmasse/hp= -envy-5000-printer-dos-vulnerability-8cae52c87b41
    =C2=A0 HSC--MailInspector v5.3.3-7 HSC MailInspector v5.3.3-7 contains a Lo= cal File Inclusion (LFI) vulnerability caused by improper control of user-s= upplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user= -controlled parameters that directly affect file access operations without = adequate validation, sanitization, or path restriction. This allows a remot=
    e attacker to exploit Path Traversal techniques to read arbitrary files fro=
    m the underlying operating system and application directories, leading to s= ensitive information disclosure. 2026-05-18 not yet calculated CVE-2026-299=
    62 [ https://www.cve.org/CVERecord?id=3DCVE-2026-29962 ] https://github.com= /sql3t0/cve-disclosures
    https://hsclabs.com/pt-br/mailinspector https://github.com/sql3t0/cve-disclosures/blob/main/01_-_CVE-2026-29962_LFI= %2BPath_Traversal.md
    =C2=A0 HSC--MailInspector v5.3.3-7 HSC MailInspector 5.3.3-7 has a Path Tra= versal vulnerability due to improper validation of user-supplied input in t=
    he /tap/dw.php endpoint. The text parameter is used to construct file paths=
    without adequate normalization or restriction to a safe base directory. A = remote attacker can exploit this flaw to access arbitrary files on the unde= rlying operating system, resulting in unauthorized disclosure of sensitive = information. 2026-05-18 not yet calculated CVE-2026-29963 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-29963 ] https://hsclabs.com/pt-br/mailinspecto=
    r/
    https://github.com/sql3t0/cve-disclosures https://github.com/sql3t0/cve-disclosures/blob/main/02_-_CVE-2026-29963_LFI= %2BPath_Traversal.md
    =C2=A0 HSC--MailInspector v5.3.3-7 HSC MailInspector v5.3.3-7 contains a Cr= oss-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to = improper neutralization of user-controlled input using alternate or obfusca= ted JavaScript syntax. The endpoint reflects unsanitized user input in HTTP=
    responses without adequate output encoding, allowing a remote attacker to = execute arbitrary JavaScript code in the context of a victim's browser. 202= 6-05-18 not yet calculated CVE-2026-29964 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-29964 ] https://hsclabs.com/pt-br/mailinspector/ https://github.com/sql3t0/cve-disclosures https://github.com/sql3t0/cve-disclosures/blob/main/03_-_CVE-2026-29964_XSS= .md
    =C2=A0 HSC--MailInspector v5.3.3-7 HSC MailInspector 5.3.3-7 is vulnerable =
    to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint du=
    e to improper neutralization of user-supplied input that uses alternate or = obfuscated JavaScript syntax. 2026-05-18 not yet calculated CVE-2026-29965 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-29965 ] https://hsclabs.com/p= t-br/mailinspector/
    https://github.com/sql3t0/cve-disclosures https://github.com/sql3t0/cve-disclosures/blob/main/04_-_CVE-2026-29965_XSS= .md
    =C2=A0 huggingface--huggingface/transformers A critical remote code executi=
    on vulnerability exists in all versions of the HuggingFace transformers lib= rary prior to version 5.3.0. The vulnerability allows an attacker to craft =
    a malicious `config.json` file containing the `_attn_implementation_interna=
    l` field set to an attacker-controlled HuggingFace Hub repository ID. When =
    a victim loads this model using the standard `AutoModelForCausalLM.from_pre= trained()` API, the library downloads and executes arbitrary Python code fr=
    om the attacker's repository with the victim's full OS privileges. This iss=
    ue arises due to unfiltered deserialization of configuration attributes, in= sufficient sanitization of internal fields, and unsandboxed execution of do= wnloaded kernels. The vulnerability bypasses the `trust_remote_code` securi=
    ty mechanism, is invisible to the victim, and exploits the standard documen= ted usage pattern, making it particularly severe. Users are advised to upgr= ade to version 5.3.0 or later to mitigate this issue. 2026-05-24 not yet ca= lculated CVE-2026-4372 [ https://www.cve.org/CVERecord?id=3DCVE-2026-4372 ]=
    https://huntr.com/bounties/1f693a6e-6836-4b8b-a0bd-ca036fba8884 https://github.com/huggingface/transformers/commit/a7f8e7ff37d87d1a1a0c8cf6= 07971c607741452f
    =C2=A0 InfoScale--CmdServer InfoScale CmdServer before 7.4.2 mishandles acc= ess control. 2026-05-20 not yet calculated CVE-2026-44926 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-44926 ] https://www.veritas.com/support/en_US/= doc/109864724-141543588-0/v141217547-141543588 https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNum= ber=3D1000766081&articleTitle=3DInfoScale_Command_Server_Security_Bulletin_= for_CVE_2026_44926
    =C2=A0 InfoScale--VIOM SQL injection in InfoScale VIOM before v9.1.3 allows=
    remote attackers to escalate privileges. 2026-05-20 not yet calculated CVE= -2026-44923 [ https://www.cve.org/CVERecord?id=3DCVE-2026-44923 ] https://w= ww.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-= 166757640 https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNum= ber=3D1000766080&articleTitle=3DInfoScale_Operations_Manager_IOM_web_applic= ation_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925 =C2=A0 InfoScale--VIOM InfoScale VIOM 9.1.3 allows XSS. 2026-05-20 not yet = calculated CVE-2026-44924 [ https://www.cve.org/CVERecord?id=3DCVE-2026-449=
    24 ] https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_t= ot_v118836641-166757640 https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNum= ber=3D1000766080&articleTitle=3DInfoScale_Operations_Manager_IOM_web_applic= ation_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925 =C2=A0 InfoScale--VIOM Cross-Site Request Forgery (CSRF) vulnerability in I= nfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the = user with an active session into clicking a malicious HTML link, which trig= gers unintended modifications on VIOM web application without the user's kn= owledge. 2026-05-20 not yet calculated CVE-2026-44925 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-44925 ] https://www.veritas.com/support/en_US/doc/= 120571566-166757640-0/viom_tot_v118836641-166757640 https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNum= ber=3D1000766080&articleTitle=3DInfoScale_Operations_Manager_IOM_web_applic= ation_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925 =C2=A0 Innoshop--Innoshop 0.6.0 An authorization vulnerability exists in In= noshop 0.6.0. After logging into the frontend, an attacker can directly acc= ess backend application interfaces, leading to further dangerous operations=
    . 2026-05-19 not yet calculated CVE-2026-39250 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-39250 ] https://www.innoshop.com/ https://gist.github.com/hkdmh/4af513ea7589212cb1d49bc5d972972e
    =C2=A0 Jaspersoft--JasperReports Library Community Edition Java Deserialisa= tion Vulnerability in Jaspersoft Reports Library leads to=C2=A0Remote Code = Execution (RCE), potentially allowing code execution on the affected system=
    2026-05-19 not yet calculated CVE-2026-6009 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-6009 ] https://community.jaspersoft.com/advisories/jasperso= ft-security-advisory-may-19-2026-jaspersoft-library-cve-2026-6009-r11/
    =C2=A0 JJNAPIORK--Catalyst::Plugin::Authentication Catalyst::Plugin::Authen= tication versions through 0.10024 for Perl is susceptible to timing attacks=
    . These versions use Perl's built-in eq comparison. Discrepencies in timing=
    could be used to guess the underlying hash or password. 2026-05-21 not yet=
    calculated CVE-2026-5091 [ https://www.cve.org/CVERecord?id=3DCVE-2026-509=
    1 ] https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_= 025/changes https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b051= 5f492257438cf07082acf1e10d06e8088a5e.patch
    =C2=A0 LalanaChami--Pharmacy Management System=C2=A0 The LalanaChami Pharma=
    cy Management System (commit 5c3d028) allows unauthenticated remote attacke=
    rs to escalate privileges by self-assigning an administrative role during r= egistration. The /api/user/signup endpoint fails to validate the role param= eter in the request body 2026-05-19 not yet calculated CVE-2026-31070 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-31070 ] https://github.com/LalanaC= hami/Pharmacy-Mangment-System/blob/5c3d02888631166649856f71d542387114b3010b= /backend/routes/user.js#L16 https://gist.github.com/nedlir/22bf6d1a3a07209be3e343744bc81d51
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net: qrtr: ns: Limit the maximum server registration per node = Current code does no bound checking on the number of servers added per node=
    . A malicious client can flood NEW_SERVER messages and exhaust memory. Fix = this issue by limiting the maximum number of server registrations to 256 pe=
    r node. If the NEW_SERVER message is received for an old port, then don't r= estrict it as it will get replaced. While at it, also rate limit the error = messages in the failure path of qrtr_ns_worker(). Note that the limit of 25=
    6 is chosen based on the current platform requirements. If requirement chan= ges in the future, this limit can be increased. 2026-05-19 not yet calculat=
    ed CVE-2026-43491 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43491 ] htt= ps://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7 https://git.kernel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b https://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d782ec02c https://git.kernel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sg= l() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when sub= tracting "lzeros" from the unsigned "nbytes". For this to happen, the scatt= erlist "sgl" needs to occupy more bytes than the "nbytes" parameter and the=
    first "nbytes + 1" bytes of the scatterlist must be zero. Under these cond= itions, the while loop iterating over the scatterlist will count more zeroe=
    s than "nbytes", subtract the number of zeroes from "nbytes" and cause the = underflow. When commit 2d4d1eea540b ("lib/mpi: Add mpi sgl helpers") origin= ally introduced the bug, it couldn't be triggered because all callers of mp= i_read_raw_from_sgl() passed a scatterlist whose length was equal to "nbyte= s". However since commit 63ba4d67594a ("KEYS: asymmetric: Use new crypto in= terface without scatterlists"), the underflow can now actually be triggered=
    . When invoking a KEYCTL_PKEY_ENCRYPT system call with a larger "out_len" t= han "in_len" and filling the "in" buffer with zeroes, crypto_akcipher_sync_= prep() will create an all-zero scatterlist used for both the "src" and "dst=
    " member of struct akcipher_request and thereby fulfil the conditions to tr= igger the bug: sys_keyctl() keyctl_pkey_e_d_s() asymmetric_key_eds_op() sof= tware_key_eds_op() crypto_akcipher_sync_encrypt() crypto_akcipher_sync_prep=
    () crypto_akcipher_encrypt() rsa_enc() mpi_read_raw_from_sgl() To the user = this will be visible as a DoS as the kernel spins forever, causing soft loc= kup splats as a side effect. Fix it. 2026-05-19 not yet calculated CVE-2026= -43492 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43492 ] https://git.ke= rnel.org/stable/c/2aa77a18dc7f2670497fe3ee5acbeda0b57659e5 https://git.kernel.org/stable/c/26d3a97ad46c7a9226ec04d4bf35bd4998a97d16 https://git.kernel.org/stable/c/8637dfb4c1d8a7026ef681f2477c6de8b71c4003 https://git.kernel.org/stable/c/30e513e755bb381afce6fb57cdc8694136193f22 https://git.kernel.org/stable/c/8c2f1288250a90a4b5cabed5d888d7e3aeed4035
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_= iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages = are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But=
    we fail to properly clear rm->data.op_nents. Later when rds_message_purge(=
    ) is called from rds_sendmsg() the cleanup loop iterates over the incorrect=
    ly non zero number of op_nents and frees them again. Fix this by properly r= esetting op_nents when it should be in rds_message_zcopy_from_user(). 2026-= 05-21 not yet calculated CVE-2026-43494 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-43494 ] https://git.kernel.org/stable/c/9115669faedccdda100428e= 2d26fd0aac8c50799 https://git.kernel.org/stable/c/0bbbff00a15b1df2cac9014d6cf4b6890f473353 https://git.kernel.org/stable/c/640e37f58f991546a87540d067279c2c1fa9fe51 https://git.kernel.org/stable/c/290e833d1acb1093bc121fcdc97f5e6161157479 https://git.kernel.org/stable/c/e174929793195e0cd6a4adb0cad731b39f9019b4
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net: wwan: t7xx: validate port_count against message length in=
    t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the modem-sup= plied port_count field as a loop bound over port_msg->data[] without checki=
    ng that the message buffer contains sufficient data. A modem sending port_c= ount=3D65535 in a 12-byte buffer triggers a slab-out-of-bounds read of up t=
    o 262140 bytes. Add a sizeof(*port_msg) check before accessing the port mes= sage header fields to guard against undersized messages. Add a struct_size(=
    ) check after extracting port_count and before the loop. In t7xx_parse_host= _rt_data(), guard the rt_feature header read with a remaining-buffer check = before accessing data_len, validate feat_data_len against the actual remain= ing buffer to prevent OOB reads and signed integer overflow on offset. Pass=
    msg_len from both call sites: skb->len at the DPMAIF path after skb_pull()=
    , and the validated feat_data_len at the handshake path. 2026-05-21 not yet=
    calculated CVE-2026-43495 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43= 495 ] https://git.kernel.org/stable/c/f94450ce5053b36002995b72d1fa1db3bb08c= 5bf
    https://git.kernel.org/stable/c/9855e063e063158cc5bded576382599dc3133202 https://git.kernel.org/stable/c/2b56d7903ab804481f5233a259d5f341e9fd513c https://git.kernel.org/stable/c/dd4f4c93c1488d7100b9964f2da4c8b3c29652f1 https://git.kernel.org/stable/c/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net/sched: sch_red: Replace direct dequeue call with peek and = qdisc_dequeue_peeked When red qdisc has children (eg qfq qdisc) whose peek(=
    ) callback is qdisc_peek_dequeued(), we could get a kernel panic. When the = parent of such qdiscs (eg illustrated in patch #3 as tbf) wants to retrieve=
    an skb from its child (red in this case), it will do the following: 1a. do=
    a peek() - and when sensing there's an skb the child can offer, then - the=
    child in this case(red) calls its child's (qfq) peek. qfq does the right t= hing and will return the gso_skb queue packet. Note: if there wasnt a gso_s=
    kb entry then qfq will store it there. 1b. invoke a dequeue() on the child = (red). And herein lies the problem. - red will call the child's dequeue() w= hich will essentially just try to grab something of qfq's queue. [ 78.66766= 8][ T363] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000= 004f] [ 78.667927][ T363] CPU: 1 UID: 0 PID: 363 Comm: ping Not tainted 7.1= .0-rc1-00033-g46f74a3f7d57-dirty #790 PREEMPT(full) [ 78.668263][ T363] Har= dware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 78.668486][ T363] RIP: 001= 0:qfq_dequeue+0x446/0xc90 [sch_qfq] [ 78.668718][ T363] Code: 54 c0 e8 dd 9=
    0 00 f1 48 c7 c7 e0 03 54 c0 48 89 de e8 ce 90 00 f1 48 8d 7b 48 b8 ff ff 3=
    7 00 48 89 fa 48 c1 e0 2a 48 c1 ea 03 <80> 3c 02 00 74 05 e8 ef a1 e1 f1 48=
    8b 7b 48 48 8d 54 24 58 48 8d [ 78.669312][ T363] RSP: 0018:ffff88810de573=
    e0 EFLAGS: 00010216 [ 78.669533][ T363] RAX: dffffc0000000000 RBX: 00000000= 00000000 RCX: 0000000000000000 [ 78.669790][ T363] RDX: 0000000000000009 RS=
    I: 0000000000000004 RDI: 0000000000000048 [ 78.670044][ T363] RBP: ffff8881= 10dc4000 R08: ffffffffb1b0885a R09: fffffbfff6ba9078 [ 78.670297][ T363] R1=
    0: 0000000000000003 R11: ffff888110e31c80 R12: 0000001880000000 [ 78.670560=
    ][ T363] R13: ffff888110dc4150 R14: ffff888110dc42b8 R15: 0000000000000200 =
    [ 78.670814][ T363] FS: 00007f66a8f09c40(0000) GS:ffff888163428000(0000) kn= lGS:0000000000000000 [ 78.671110][ T363] CS: 0010 DS: 0000 ES: 0000 CR0: 00= 00000080050033 [ 78.671324][ T363] CR2: 000055db4c6a30a8 CR3: 000000010da67= 000 CR4: 0000000000750ef0 [ 78.671585][ T363] PKRU: 55555554 [ 78.671713][ = T363] Call Trace: [ 78.671843][ T363] <TASK> [ 78.671936][ T363] ? __pfx_qf= q_dequeue+0x10/0x10 [sch_qfq] [ 78.672148][ T363] ? __pfx__printk+0x10/0x10=
    [ 78.672322][ T363] ? srso_alias_return_thunk+0x5/0xfbef5 [ 78.672496][ T3= 63] ? lockdep_hardirqs_on_prepare+0xa8/0x1a0 [ 78.672706][ T363] ? srso_ali= as_return_thunk+0x5/0xfbef5 [ 78.672875][ T363] ? trace_hardirqs_on+0x19/0x= 1a0 [ 78.673047][ T363] red_dequeue+0x65/0x270 [sch_red] [ 78.673217][ T363=
    ] ? srso_alias_return_thunk+0x5/0xfbef5 [ 78.673385][ T363] tbf_dequeue.col= d+0xb0/0x70c [sch_tbf] [ 78.673566][ T363] __qdisc_run+0x169/0x1900 The rig=
    ht thing to do in #1b is to grab the skb off gso_skb queue. This patchset f= ixes that issue by changing #1b to use qdisc_dequeue_peeked() method instea=
    d. 2026-05-21 not yet calculated CVE-2026-43496 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-43496 ] https://git.kernel.org/stable/c/36aa34f42cb6842c= f371f3a2d3e855d24fd57a50 https://git.kernel.org/stable/c/ce051eede433f876d322ac3550a36a3c6fc4c231 https://git.kernel.org/stable/c/8d09618840b99ef00154d3e731ce9b11e096196d https://git.kernel.org/stable/c/587dcf970a525f543d8b5855d9f37a4ca97b76ef https://git.kernel.org/stable/c/458d5615272d3de535748342eb68ca492343048c
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after= -free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebuffer pag=
    es to userspace but sets no vm_ops on the VMA. This means the kernel cannot=
    track active mmaps. When dlfb_realloc_framebuffer() replaces the backing b= uffer via FBIOPUT_VSCREENINFO, existing mmap PTEs are not invalidated. On U=
    SB disconnect, dlfb_ops_destroy() calls vfree() on the old pages while user= space PTEs still reference them, resulting in a use-after-free: the process=
    retains read/write access to freed kernel pages. Add vm_operations_struct = with open/close callbacks that maintain an atomic mmap_count on struct dlfb= _data. In dlfb_realloc_framebuffer(), check mmap_count and return -EBUSY if=
    the buffer is currently mapped, preventing buffer replacement while usersp= ace holds stale PTEs. Tested with PoC using dummy_hcd + raw_gadget USB devi=
    ce emulation. 2026-05-21 not yet calculated CVE-2026-43497 [ https://www.cv= e.org/CVERecord?id=3DCVE-2026-43497 ] https://git.kernel.org/stable/c/4f312= c30f0368e8d2a76aa650dff73f23490b5e7 https://git.kernel.org/stable/c/18dd358de72d57993422cbb5dfb29ccd74efe192 https://git.kernel.org/stable/c/da9b065cedfd3b574f229d5be594e6aa47a27ae6 https://git.kernel.org/stable/c/a2c53a3822ee26e8d758071815b9ed3bf6669fc1 https://git.kernel.org/stable/c/8de779dc40d35d39fa07387b6f921eb11df0f511
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: accel/ivpu: Disallow re-exporting imported GEM objects Prevent=
    re-exporting of imported GEM buffers by adding a custom prime_handle_to_fd=
    callback that checks if the object is imported and returns -EOPNOTSUPP if = so. Re-exporting imported GEM buffers causes loss of buffer flags settings,=
    leading to incorrect device access and data corruption. 2026-05-21 not yet=
    calculated CVE-2026-43498 [ https://www.cve.org/CVERecord?id=3DCVE-2026-43= 498 ] https://git.kernel.org/stable/c/3756043dd695bba34cc728cdc5688dcb49ac8= 043
    https://git.kernel.org/stable/c/7dd57d7a6350770dfc283287125c409e995200e0
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: rtmutex: Use waiter::task instead of current in remove_waiter(=
    ) remove_waiter() is used by the slowlock paths, but it is also used for pr= oxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_re= queue(). In the latter case waiter::task is not current, but remove_waiter(=
    ) operates on current for the dequeue operation. That results in several pr= oblems: 1) the rbtree dequeue happens without waiter::task::pi_lock being h= eld 2) the waiter task's pi_blocked_on state is not cleared, which leaves a=
    dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() op= erates on the wrong top priority waiter task Use waiter::task instead of cu= rrent in all related operations in remove_waiter() to cure those problems. =
    [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the cha= ngelog ] 2026-05-21 not yet calculated CVE-2026-43499 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-43499 ] https://git.kernel.org/stable/c/8a1fc8d698= ac5e5916e3082a0f74450d71f9611f https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166 https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2 https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11 https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grow=
    s ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps = the next segment into ipv6_hdr->daddr, recompresses, then pulls the old hea= der and pushes the new one plus the IPv6 header back. The recompressed head=
    er can be larger than the received one when the swap reduces the common-pre= fix length the segments share with daddr (CmprI=3D0, CmprE>0, seg[0][0] !=
    =3D daddr[0] gives the maximum +8 bytes). pskb_expand_head() was gated on s= egments_left =3D=3D 0, so on earlier segments the push consumed unchecked h= eadroom. Once skb_push() leaves fewer than skb->mac_len bytes in front of d= ata, skb_mac_header_rebuild()'s call to: skb_set_mac_header(skb, -skb->mac_= len); will store (data - head) - mac_len into the u16 mac_header field, whi=
    ch wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB=
    past skb->head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo wit=
    h a two segment type-3 SRH (CmprI=3D0, CmprE=3D15) reaches headroom 8 after=
    one pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by=
    expanding the head whenever the remaining room is less than the push size = plus mac_len, and request that much extra so the rebuilt MAC header fits af= terwards. 2026-05-21 not yet calculated CVE-2026-43501 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-43501 ] https://git.kernel.org/stable/c/8e8be6346= 5a5e80394c70324603dfea1bfdad48f https://git.kernel.org/stable/c/4babc2d9fda2df43823b85d08a0180b68f1b0854 https://git.kernel.org/stable/c/c261d07a80576dc8ccf394ef8f074f8c67a06b37 https://git.kernel.org/stable/c/7398ebefbfd4f8a31d4f665a4213302fa995494b https://git.kernel.org/stable/c/9e6bf146b55999a095bb14f73a843942456d1adc
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net/rds: handle zerocopy send cleanup before the message is qu= eued A zerocopy send can fail after user pages have been pinned but before = the message is attached to the sending socket. The purge path currently inf= ers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up =
    as if it owned normal payload pages. However, zerocopy ownership is really = determined by the presence of op_mmp_znotifier, regardless of whether the m= essage has reached the socket queue. Capture op_mmp_znotifier up front in r= ds_message_purge() and use it as the cleanup discriminator. If the message =
    is already associated with a socket, keep the existing completion path. Oth= erwise, drop the pinned page accounting directly and release the notifier b= efore putting the payload pages. This keeps early send failure cleanup cons= istent with the zerocopy lifetime rules without changing the normal queued = completion path. 2026-05-21 not yet calculated CVE-2026-43502 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-43502 ] https://git.kernel.org/stable/c/21= d70744e6d3bbf9293aa1ee6fba7c53ad75275e https://git.kernel.org/stable/c/3abc8983b2bae3f487f77d9da5527d7d6b210d46 https://git.kernel.org/stable/c/14ef6fd18db2494098b21e0471bf27a1d8e9993e https://git.kernel.org/stable/c/0f5c185fc79a59ee9991234dd6d2a3e5afa6e75b https://git.kernel.org/stable/c/44b550d88b267320459d518c0743a241ab2108fa
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net: skbuff: propagate shared-frag marker through frag-transfe=
    r helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) = fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when mov= ing frags from source to destination. __pskb_copy_fclone() defers the rest =
    of the shinfo metadata to skb_copy_header() after copying frag descriptors,=
    but that helper only carries over gso_{size,segs, type} and never touches = skb_shinfo()->flags; skb_shift() moves frag descriptors directly and leaves=
    flags untouched. As a result, the destination skb keeps a reference to the=
    same externally-owned or page-cache-backed pages while reporting skb_has_s= hared_frag() as false. The mismatch is harmful in any in-place writer that = uses skb_has_shared_frag() to decide whether shared pages must be detoured = through skb_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and =
    a single nft 'dup to <local>' rule -- or any other nf_dup_ipv4() / xt_TEE c= aller -- is enough to land a pskb_copy()'d skb in esp_input() with the mark=
    er stripped, letting an unprivileged user write into the page cache of a ro= ot-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_F= RAG on the destination whenever frag descriptors were actually moved from t=
    he source. skb_copy() and skb_copy_expand() share skb_copy_header() too but=
    linearize all paged data into freshly allocated head storage and emerge wi=
    th nr_frags =3D=3D 0, so skb_has_shared_frag() returns false on its own; th=
    ey need no change. The same omission exists in skb_gro_receive() and skb_gr= o_receive_list(). The former moves the incoming skb's frag descriptors into=
    the accumulator's last sub-skb via two paths (a direct frag-move loop and = the head_frag + memcpy path); the latter chains the incoming skb whole onto=
    p's frag_list. Downstream skb_segment() reads only skb_shinfo(p)->flags, a=
    nd skb_segment_list() reuses each sub-skb's shinfo as the nskb -- both p an=
    d lp must carry the marker. The same omission also exists in tcp_clone_payl= oad(), which builds an MTU probe skb by moving frag descriptors from skbs o=
    n sk_write_queue into a freshly allocated nskb. The helper falls into the s= ame family and warrants the same fix for consistency; no TCP TX-side in-pla=
    ce writer is currently known to reach a user page through this gap, but a f= uture consumer depending on the marker would regress silently. The same omi= ssion exists in skb_segment(): the per-iteration flag merge takes only head= _skb's flag, and the inner switch that rebinds frag_skb to list_skb on head= _skb-frags exhaustion does not fold the new frag_skb's flag into nskb. Fold=
    frag_skb's flag at both sites so segments drawing frags from frag_list mem= bers carry the marker. 2026-05-23 not yet calculated CVE-2026-43503 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-43503 ] https://git.kernel.org/stabl= e/c/fbeab9555564a1b98e8582cd106dfe46c4606991 https://git.kernel.org/stable/c/179f1852bdedc300e373e807cc102cd81feff196 https://git.kernel.org/stable/c/12401fcfb01f53ccc63ab0a3246570fe8f3105ee https://git.kernel.org/stable/c/989214c66884d70716d83dc1d0bf5e16287bf349 https://git.kernel.org/stable/c/fc6eb39c55e97df2f94ad974b8a5bbcd019da2c8 https://git.kernel.org/stable/c/ff375cc75f9167168db38e0464a482d5fbc8d81d https://git.kernel.org/stable/c/9bc9d6d6967a2239aa57af2aa53554eddd640d20 https://git.kernel.org/stable/c/48f6a5356a33dd78e7144ae1faef95ffc990aae0
    =C2=A0 Linux--Linux In the Linux kernel, the following vulnerability has be=
    en resolved: net: skbuff: preserve shared-frag marker during coalescing skb= _try_coalesce() can attach paged frags from @from to @to. If @from has SKBF= L_SHARED_FRAG set, the resulting @to skb can contain the same externally-ow= ned or page-cache-backed frags, but the shared-frag marker is currently los=
    t. That breaks the invariant relied on by later in-place writers. In partic= ular, ESP input checks skb_has_shared_frag() before deciding whether an unc= loned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has = moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() =
    as false and decrypt in place over page-cache backed frags. Propagate SKBFL= _SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom co=
    py path does not need the marker because it copies bytes into @to's linear = data rather than transferring frag descriptors. 2026-05-23 not yet calculat=
    ed CVE-2026-46300 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46300 ] htt= ps://git.kernel.org/stable/c/3599e6b3cc1ada96883d496a50a210d3afbb6987 https://git.kernel.org/stable/c/2f2b16022a2e10ca7bccfb98db5ed2ec0f72641c https://git.kernel.org/stable/c/9d3e5fd19fe1063bf607219e8562fbd567b8e8d5 https://git.kernel.org/stable/c/78bf6b6bb19541d19fbda6242e7cfe2c682763c0 https://git.kernel.org/stable/c/760e1addc27ba1a7beb4a0a7e8b3e9ec49e7a34e https://git.kernel.org/stable/c/3bd9e113d50034db99d7ef69fd8e5242d15e414a https://git.kernel.org/stable/c/3884358a9286b17f389a72b1426fc4547c23c111 https://git.kernel.org/stable/c/f84eca5817390257cef78013d0112481c503b4a3
    =C2=A0 LiteSpeed Technologies--cPanel Plugin LiteSpeed User-End cPanel Plug=
    in before 2.4.5 allows privilege escalation (possibly to root), as exploite=
    d in the wild in May 2026. Detection is best done via a command line of gre=
    p -rE "cpanel_jsonapi_func=3DredisAble" /var/cpanel/logs /usr/local/cpanel/= logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with=
    exploitation of the vulnerability. If there is output, we recommend you ex= amine the IP addresses in the list, determine if they are valid IP addresse=
    s, and if not, block them. To determine damage done, examine the system log=
    s for use by the detected IP addresses. The issue is related to mishandling=
    of Redis enable/disable features. The recommended minimum version is 2.4.7=
    . 2026-05-21 not yet calculated CVE-2026-48172 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-48172 ] https://www.litespeedtech.com/products/litespeed-= web-server/control-panel-support/cpanel https://www.litespeedtech.com/products/litespeed-web-server/control-panel-s= upport/release-log https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpa= nel-plugin/
    =C2=A0 lostisland--faraday Faraday is an HTTP client library abstraction la= yer that provides a common interface over many adapters. Versions 2.0.0 thr= ough 2.14.1 still allow protocol-relative host override when the request ta= rget is passed as a URI object (rather than a String) to Faraday::Connectio= n#build_exclusive_url. This bypasses the February 2026 fix for GHSA-33mh-26= 34-fwr2 and enables off-host request forgery: a request built from a fixed-= base Faraday::Connection can be redirected to an attacker-controlled host, = forwarding connection-scoped values such as Authorization headers and defau=
    lt query parameters. This issue has been fixed in version 2.14.3. 2026-05-1=
    9 not yet calculated CVE-2026-33637 [ https://www.cve.org/CVERecord?id=3DCV= E-2026-33637 ] https://github.com/lostisland/faraday/security/advisories/GH= SA-5rv5-xj5j-3484
    https://github.com/advisories/GHSA-33mh-2634-fwr2
    =C2=A0 LXQt--PCManFM-Qt An issue was discovered in all versions of PCManFM-=
    Qt starting from 1.1.0. When a regular file's path is passed as a URI in an=
    org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt del= egates to a different program (based on the file type) without user confirm= ation. This could be used to achieve code execution or circumvent network n= amespace restrictions. NOTE: those outcomes are potentially unwanted by mos=
    t users; however, the behavior of the product does comply with the applicab=
    le specification, and a simplistic solution (ensuring that the URI does not=
    name a regular file) may have adverse consequences for I/O. 2026-05-22 not=
    yet calculated CVE-2026-48700 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-48700 ] https://www.openwall.com/lists/oss-security/2026/05/20/2 https://www.openwall.com/lists/oss-security/2026/05/19/1 https://github.com/lxqt/pcmanfm-qt/releases
    =C2=A0 M-Files Corporation--M-Files Server Denial-of-service condition in M= -Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.=
    8 LTS SR3 allows an authenticated user to cause the MFserver process to cra=
    sh 2026-05-18 not yet calculated CVE-2026-0983 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-0983 ] https://empower.m-files.com/security-advisories/CV= E-2026-0983
    =C2=A0 mailcow--mailcow-dockerized mailcow-dockerized contains a stored cro= ss-site scripting vulnerability in the administrator Queue Manager. The Que=
    ue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies se= rver-controlled Postfix queue fields into DataTables rows, and renders seve= ral of those fields as HTML without adequate output encoding. This issue af= fects mailcow-dockerized: 2026-03b. 2026-05-20 not yet calculated CVE-2026-= 7460 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7460 ] https://fluidatta= cks.com/advisories/mojabi
    https://github.com/mailcow/mailcow-dockerized
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticat=
    ed user assigned the "add_profile_threshold" permission to create a global = profile despite not having manage_global_profile_threshold, by tampering wi=
    th the user_id parameter in a valid profile creation request. This issue ha=
    s been fixed in version 2.28.2. 2026-05-19 not yet calculated CVE-2026-3305=
    2 [ https://www.cve.org/CVERecord?id=3DCVE-2026-33052 ] https://github.com/= mantisbt/mantisbt/security/advisories/GHSA-68w5-w573-q2r8 https://github.com/mantisbt/mantisbt/commit/3f952e68fa864e0e60abc3e84adecf3= cfa84c75e
    https://mantisbt.org/bugs/view.php?id=3D36974
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnera= bility where insufficient access control checks in ProjectUsersAddCommand (= manage_proj_user_add.php) allow users having manage_project_threshold acces=
    s level (manager by default) to grant project-level administrator access to=
    any user (including themselves) in any Project they have manager rights in=
    . The normal project-user add form restricts the selectable access levels t=
    o the actor's own project role or below. However, the backend handler still=
    accepts a forged higher access_level value and writes it. The consequences=
    of the privilege escalation are slight, as having administrator access at = Project level is effectively not very different from being manager, and it = does not actually give administrator privileges on the whole MantisBT insta= nce. In particular, it does not let the upgraded user delete the Project or=
    grant them any access to global administrative functions such as managing = Users, Projects, Plugins, Custom Fields, etc. This issue has been fixed in = version 2.28.2. 2026-05-19 not yet calculated CVE-2026-34390 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-34390 ] https://github.com/mantisbt/mantisb= t/security/advisories/GHSA-frf7-jhp9-jxm6 https://github.com/mantisbt/mantisbt/commit/69e0180f180ed5acf48a8d281a73683= a7bf32461
    https://mantisbt.org/bugs/view.php?id=3D36995 https://mantisbt.org/bugs/view.php?id=3D37002
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability.=
    When cloning an issue originating from a Project other than the current on=
    e, the clone form (bug_report_page.php) prepends the source Project name be= fore the category selector without proper escaping, allowing an attacker ab=
    le to to inject HTML if they can set the Project's name (which typically re= quires manager or administrator access level). This issue has been resolved=
    in version 2.28.2. 2026-05-19 not yet calculated CVE-2026-34463 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-34463 ] https://github.com/mantisbt/man= tisbt/security/advisories/GHSA-fvjf-68wh-rwp2 https://github.com/mantisbt/mantisbt/commit/df22697ae497ddd93f3d9132fdf4979= db8d081cd
    https://mantisbt.org/bugs/view.php?id=3D36986
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Byp= ass through the private issue monitoring feature . Using a crafted POST req= uest to bug_monitor_add.php, a user with project-level access can add thems= elves as a monitor for a private issue they do not have access to. Despite = displaying an Access Denied error, the application accepts the request and = creates a monitor relationship for the private issue. Direct access to the = private issue remains blocked, but the user will receive email notification=
    s for updates, leading to disclosure of the private issue's metadata and co= ntent. This issue has been fixed in version 2.28.2. 2026-05-19 not yet calc= ulated CVE-2026-34579 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34579 ]=
    https://github.com/mantisbt/mantisbt/security/advisories/GHSA-ggw7-9675-6v=
    4v
    https://github.com/mantisbt/mantisbt/commit/0a93267deba445fb9d15250c16e6fdb= 1246ffa65
    https://mantisbt.org/bugs/view.php?id=3D36975
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and prior permit a user to list and download = their own attachments from an Issue created by another user even after it b= ecomes private, bypassing read access revocation. The loss of confidentiali=
    ty caused by this vulnerability is minimal, considering that only attachmen=
    ts previously uploaded by the user themselves remain accessible. This issue=
    has been fixed in version 2.82.2. 2026-05-19 not yet calculated CVE-2026-3= 4744 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34744 ] https://github.c= om/mantisbt/mantisbt/security/advisories/GHSA-rmp5-5jj7-gmvf https://github.com/mantisbt/mantisbt/commit/de7bdeec36de066235e38a77bf05691= 7d951c84d
    https://mantisbt.org/bugs/view.php?id=3D36977
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.28.1 and prior allow a bugnote author to access th=
    e note's Revisions page after losing access to the parent private issue. Th=
    is issue has been fixed in version 2.28.2. 2026-05-19 not yet calculated CV= E-2026-34970 [ https://www.cve.org/CVERecord?id=3DCVE-2026-34970 ] https://= github.com/mantisbt/mantisbt/security/advisories/GHSA-crmx-4p49-46m2 https://github.com/mantisbt/mantisbt/commit/71df1f67e05b2050cd4bd87839e6cc1= 3747cf03f
    https://mantisbt.org/bugs/view.php?id=3D36978
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user t=
    o inject arbitrary HTML by updating their account's font family. Upon explo= itation, an XSS payload would be reflected on every MantisBT page. Leveragi=
    ng another vulnerability (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacke=
    r could achieve account takeover. This issue has been fixed in version 2.28= .2. 2026-05-22 not yet calculated CVE-2026-40596 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-40596 ] https://github.com/mantisbt/mantisbt/security/a= dvisories/GHSA-j3v9-553h-x28j https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3 https://github.com/mantisbt/mantisbt/commit/9e8409cdd979eba86ef532756fc47c1= d8112d22d
    https://mantisbt.org/bugs/view.php?id=3D37011 https://mantisbt.org/bugs/view.php?id=3D37016
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HT=
    ML injection vulnerability, an attacker can bypass the Content Security Pol= icy's script-src directive by uploading a crafted attachment to any issue t= hat, when accessed via the file_download.php link, will be downloaded with =
    a valid JavaScript MIME type resulting in script execution. The uploaded pa= yload must be sniffed as a valid JavaScript MIME type by PHP finfo (see fil= e_create_finfo() API function). Non-JavaScript MIME types will not get impo= rted in a <script> tag by the browser, due to response header X-Content-Typ= e-Options being set to nosniff, which requires all imported JavaScript file=
    s to be a valid JavaScript MIME type. This issue has been fixed in version = 2.28.2. 2026-05-22 not yet calculated CVE-2026-40597 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-40597 ] https://github.com/mantisbt/mantisbt/securi= ty/advisories/GHSA-9c3j-xm6v-j7j3 https://github.com/mantisbt/mantisbt/commit/9e3bee2e7b909f4e3596985892b8bc8= bee9e0bfe
    https://mantisbt.org/bugs/view.php?id=3D37016
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. In versions 2.28.1 and below, improper escaping of the redire= ction page (retrieved from the request's Referer header) allows an attacker=
    to inject HTML. While this is generally not directly actionable as modern = browsers will URL-encode special characters, on some specific server config= urations this could poison the cache, leading to cross-site scripting. This=
    issue has been fixed in version 2.28.2. 2026-05-22 not yet calculated CVE-= 2026-40598 [ https://www.cve.org/CVERecord?id=3DCVE-2026-40598 ] https://gi= thub.com/mantisbt/mantisbt/security/advisories/GHSA-6jh4-47v2-4g37 https://github.com/mantisbt/mantisbt/commit/b1ebc57763f104eb5f541b7b4d1ce69= 48168abd9
    https://mantisbt.org/bugs/view.php?id=3D37017
    =C2=A0 mantisbt--mantisbt Mantis Bug Tracker (MantisBT) is an open source i= ssue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability=
    is caused by incorrect escaping of a saved filter's owner, allowing an att= acker to inject arbitrary HTML on systems where $g_show_user_realname =3D O=
    N. Note that By default, only users with Manager access level or above can = save their filters publicly. This issue has been fixed in version 2.28.2. I=
    f developers are unable to update immediately, they can work around this is= sue by preventing display of users' real names (set $g_ show_user_realname = =3D OFF; in configuration), and restricting the ability to store filters (s=
    et $g_stored_query_create_threshold / $g_stored_query_create_shared_thresho=
    ld to NOBODY). 2026-05-22 not yet calculated CVE-2026-40607 [ https://www.c= ve.org/CVERecord?id=3DCVE-2026-40607 ] https://github.com/mantisbt/mantisbt= /security/advisories/GHSA-f633-865q-2mhh https://github.com/mantisbt/mantisbt/commit/44f490bcf20fd491c1b8f3fc9dd041d= 8c2a30010
    https://mantisbt.org/bugs/view.php?id=3D37015
    =C2=A0 mermaid-js--mermaid Mermaid is a JavaScript tool that uses Markdown-= inspired text to create and modify diagrams and charts. Versions 10.9.5 and=
    prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS=
    injection through improper sanitization. The state diagram (and any other = diagram type that routes user-controlled style strings through the createCs= sStyles parser) captures classDef values using an unrestricted regex that m= atches everything up to a newline. That value then flows unsanitized throug=
    h addStyleClass() into createCssStyles() and is assigned to style.innerHTML=
    , so a closing brace (}) in the value terminates the generated CSS selector=
    and turns everything after it into a new CSS rule on the page. This enable=
    s page defacement, user tracking via url() callbacks, and DOM attribute exf= iltration. This issue has been fixed in versions 10.9.6 and 11.15.0. If dev= elopers are unable to immediately upgrade, they can work around this issue =
    by setting "securityLevel": "sandbox", which prevents the issue by renderin=
    g the mermaid diagram in a sandboxed <iframe>. 2026-05-22 not yet calculate=
    d CVE-2026-41148 [ https://www.cve.org/CVERecord?id=3DCVE-2026-41148 ] http= s://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r https://github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81ace= bee2859102 https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d= 7d90957a0f
    https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0 https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6 https://mermaid.js.org/config/schema-docs/config.html#securitylevel
    =C2=A0 mermaid-js--mermaid Mermaid is a JavaScript tool that uses Markdown-= inspired text to create and modify diagrams and charts. Versions 10.9.5 and=
    earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML=
    injection under the default configuration. Specifically, the classDef dire= ctive in Mermaid state diagrams permits DOM injection that escapes the SVG = context. However, <script> tags are stripped, which prevents cross-site scr= ipting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If = developers are unable to immediately upgrade, they can work around this iss=
    ue by setting "securityLevel": "sandbox", which prevents the issue by rende= ring the mermaid diagram in a sandboxed <iframe>. 2026-05-22 not yet calcul= ated CVE-2026-41149 [ https://www.cve.org/CVERecord?id=3DCVE-2026-41149 ] h= ttps://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235d= b4d01f4056 https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78d= c4d09ac4f3
    =C2=A0 misp--misp MISP's OIDC authentication plugin allowed automatic linki=
    ng of an OIDC identity to an existing local user account based on the email=
    claim when the local account had no stored sub value. Under insecure or un= trusted IdP configurations where email ownership is not enforced, an attack=
    er with a valid OIDC token could assert a victim's email address and authen= ticate as that user, leading to account takeover. 2026-05-20 not yet calcul= ated CVE-2026-9084 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9084 ] htt= ps://github.com/MISP/MISP/commit/71f5662c1b5886613d2cd5c72fd93bb4ca6fa172 =C2=A0 misp--misp A vulnerability was identified in the ShadowAttribute pro= posal creation workflow. The add action accepted user-controlled ShadowAttr= ibute request data without removing the id field before saving the record. = Because the underlying framework treats a supplied primary key as an instru= ction to update an existing record, an authenticated user able to submit sh= adow attribute proposals could provide the identifier of an existing Shadow= Attribute and cause that record to be updated instead of creating a new pro= posal. This can result in unauthorized modification of existing shadow attr= ibutes, potentially affecting proposals associated with events the user sho= uld not be able to alter. Depending on deployment configuration and accessi= ble API responses, the issue may also expose or move proposal data across e= vent contexts. The vulnerability is caused by trusting a client-supplied pr= imary key during object creation. The fix removes the id field from incomin=
    g ShadowAttribute data before processing, ensuring that the endpoint always=
    creates a new proposal rather than updating an existing one. This has been=
    fixed in MISP 2.5.38. 2026-05-20 not yet calculated CVE-2026-9136 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-9136 ] https://github.com/MISP/MISP/c= ommit/49911b1d4b6e4517d803e50e3d980aaa4d37c16d
    =C2=A0 misp--misp The CSP report endpoint intended to limit logged CSP repo= rts to 1 KB but incorrectly allowed reports up to 1 MB before truncation. O=
    n deployments where the endpoint is reachable by untrusted clients, this co= uld allow attackers to generate excessive log volume and contribute to reso= urce exhaustion or log flooding. 2026-05-20 not yet calculated CVE-2026-913=
    7 [ https://www.cve.org/CVERecord?id=3DCVE-2026-9137 ] https://github.com/M= ISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9
    =C2=A0 mlflow--mlflow/mlflow In MLflow version 3.9.0, the MLflow Assistant = feature introduced improper origin validation in its /ajax-api endpoints. T= his vulnerability allows a remote attacker to exploit cross-origin requests=
    from a malicious webpage to interact with the MLflow Assistant running on =
    a victim's local machine. By bypassing the loopback-only restriction, the a= ttacker can modify the Assistant's configuration to enable full access, whi=
    ch in turn allows the execution of arbitrary commands via the Claude Code s= ub-agent. This issue is resolved in version 3.10.0. 2026-05-19 not yet calc= ulated CVE-2026-2611 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2611 ] h= ttps://huntr.com/bounties/8462addd-b464-4a84-b6a2-5529604e6e5a https://github.com/mlflow/mlflow/commit/8f9c8a53af90842944101eb8b7d60706822= c81bc
    =C2=A0 mlflow--mlflow/mlflow In mlflow/mlflow versions up to 3.9.0, the `Se= archModelVersions` REST API endpoint and the `mlflowSearchModelVersions` Gr= aphQL query lack proper per-model authorization checks when basic authentic= ation is enabled. This allows any authenticated user to enumerate all model=
    versions across all registered models, regardless of their permission leve=
    l. The issue arises due to the absence of `SearchModelVersions` in the `BEF= ORE_REQUEST_VALIDATORS` and `AFTER_REQUEST_HANDLERS` for the REST API, and = its omission from `GraphQLAuthorizationMiddleware.PROTECTED_FIELDS` for Gra= phQL. This vulnerability can expose sensitive information such as model nam= es, version descriptions, source URIs, tags, and other metadata, potentiall=
    y revealing proprietary or confidential details in multi-tenant environment=
    s. The issue is resolved in version 3.10.0. 2026-05-21 not yet calculated C= VE-2026-2734 [ https://www.cve.org/CVERecord?id=3DCVE-2026-2734 ] https://h= untr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08 https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a1a67f8fc5e= f12c9
    =C2=A0 mlflow--mlflow/mlflow In mlflow/mlflow versions prior to 3.11.0, the=
    `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` cre= ates temporary directories with world-writable permissions (0o777), and the=
    `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.= py` creates directories with group-writable permissions (0o770). These inse= cure permissions allow local attackers to tamper with model artifacts, such=
    as cloudpickle-serialized Python objects, and achieve arbitrary code execu= tion when the tampered artifacts are deserialized via `cloudpickle.load()`.=
    This vulnerability is particularly critical in environments with shared NF=
    S mounts, such as Databricks, where NFS is enabled by default. The issue is=
    a continuation of the vulnerability class addressed in CVE-2025-10279, whi=
    ch was only partially fixed. 2026-05-18 not yet calculated CVE-2026-4137 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-4137 ] https://huntr.com/bounti= es/648dc30b-76c7-4433-86b8-f43d926fd8d6 https://github.com/mlflow/mlflow/commit/1dcbb0c2fbd1f446c328830e601ca13a282= 19b8a
    =C2=A0 ModelScope--ModelScope 1.25.0 An issue was discovered in ModelScope = 1.25.0 allowing attackers to execute arbitrary code via crafted module list=
    ed in the configuration file (dey_mini.yaml) under the key ['nnet']['module= ']. 2026-05-19 not yet calculated CVE-2025-51427 [ https://www.cve.org/CVER= ecord?id=3DCVE-2025-51427 ] https://github.com/modelscope/modelscope/issues= /1331
    https://github.com/modelscope/modelscope/pull/1333 https://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/CVE-2025-51= 427/CVE_2025_51427.md
    =C2=A0 Mozilla--Firefox Sandbox escape in Firefox and Firefox Focus for And= roid. This vulnerability was fixed in Firefox 151. 2026-05-19 not yet calcu= lated CVE-2026-8945 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8945 ] ht= tps://bugzilla.mozilla.org/show_bug.cgi?id=3D2003171 https://www.mozilla.org/security/advisories/mfsa2026-46/
    =C2=A0 Mozilla--Firefox Incorrect boundary conditions in the Audio/Video: W=
    eb Codecs component. This vulnerability was fixed in Firefox 151, Firefox E=
    SR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 202= 6-05-19 not yet calculated CVE-2026-8946 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8946 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2029070 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-47/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Use-after-free in the DOM: Bindings (WebIDL) compon= ent. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firef=
    ox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 2026-05-19 not yet = calculated CVE-2026-8947 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8947=
    ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2038439 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-47/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Same-origin policy bypass in the DOM: Networking co= mponent. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 2= 026-05-19 not yet calculated CVE-2026-8948 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-8948 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2038803 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Integer overflow in the Widget: Win32 component. Th=
    is vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird = 151, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-2026-8949 [ = https://www.cve.org/CVERecord?id=3DCVE-2026-8949 ] https://bugzilla.mozilla= .org/show_bug.cgi?id=3D1355639 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Same-origin policy bypass in the Networking: HTTP c= omponent. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, = Thunderbird 151, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-= 2026-8950 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8950 ] https://bugz= illa.mozilla.org/show_bug.cgi?id=3D1965430 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Spoofing issue in the Toolbar component in Firefox = for Android. This vulnerability was fixed in Firefox 151. 2026-05-19 not ye=
    t calculated CVE-2026-8951 [ https://www.cve.org/CVERecord?id=3DCVE-2026-89=
    51 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2018513 https://www.mozilla.org/security/advisories/mfsa2026-46/
    =C2=A0 Mozilla--Firefox Privilege escalation in the Application Update comp= onent. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 202= 6-05-19 not yet calculated CVE-2026-8952 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8952 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2021727 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Sandbox escape due to use-after-free in the Disabil= ity Access APIs component. This vulnerability was fixed in Firefox 151, Fir= efox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.1=
    1. 2026-05-19 not yet calculated CVE-2026-8953 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-8953 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D202= 9511
    https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-47/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Incorrect boundary conditions, integer overflow in = the Audio/Video component. This vulnerability was fixed in Firefox 151, Fir= efox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 2026-05-19 not ye=
    t calculated CVE-2026-8954 [ https://www.cve.org/CVERecord?id=3DCVE-2026-89=
    54 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2030747 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Privilege escalation in the DOM: Workers component.=
    This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbi=
    rd 151, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-2026-8955=
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-8955 ] https://bugzilla.mozi= lla.org/show_bug.cgi?id=3D2031064 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Integer overflow in the Networking: JAR component. = This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbir=
    d 151, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-2026-8956 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2026-8956 ] https://bugzilla.mozil= la.org/show_bug.cgi?id=3D2032427 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Privilege escalation in the Enterprise Policies com= ponent. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Th= underbird 151, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-20= 26-8957 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8957 ] https://bugzil= la.mozilla.org/show_bug.cgi?id=3D2033850 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Information disclosure, sandbox escape in the Secur= ity: Process Sandboxing component. This vulnerability was fixed in Firefox = 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 2026-05-1=
    9 not yet calculated CVE-2026-8958 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-8958 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2034713 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Sandbox escape due to incorrect boundary conditions=
    in the Widget: Win32 component. This vulnerability was fixed in Firefox 15=
    1, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 2026-05-19 = not yet calculated CVE-2026-8959 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-8959 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2034754 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Spoofing issue in WebExtensions. This vulnerability=
    was fixed in Firefox 151 and Thunderbird 151. 2026-05-19 not yet calculate=
    d CVE-2026-8960 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8960 ] https:= //bugzilla.mozilla.org/show_bug.cgi?id=3D1940116 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Spoofing issue in the Form Autofill component. This=
    vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 15=
    1, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-2026-8961 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-8961 ] https://bugzilla.mozilla.o= rg/show_bug.cgi?id=3D1962625 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Mitigation bypass in the DOM: Security component. T= his vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird=
    151, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-2026-8962 [=
    https://www.cve.org/CVERecord?id=3DCVE-2026-8962 ] https://bugzilla.mozill= a.org/show_bug.cgi?id=3D2004804 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Spoofing issue in the Web Speech component. This vu= lnerability was fixed in Firefox 151 and Thunderbird 151. 2026-05-19 not ye=
    t calculated CVE-2026-8963 [ https://www.cve.org/CVERecord?id=3DCVE-2026-89=
    63 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2021222 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Spoofing issue in the Popup Blocker component. This=
    vulnerability was fixed in Firefox 151 and Thunderbird 151. 2026-05-19 not=
    yet calculated CVE-2026-8964 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -8964 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2025170 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Information disclosure in the DOM: Security compone= nt. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 2026-0= 5-19 not yet calculated CVE-2026-8965 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-8965 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2025740 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Information disclosure in the IP Protection compone= nt. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 2026-0= 5-19 not yet calculated CVE-2026-8966 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-8966 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2025849 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Information disclosure in the Graphics: WebGPU comp= onent. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 202= 6-05-19 not yet calculated CVE-2026-8967 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-8967 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2027173 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Denial-of-service due to invalid pointer in the Aud= io/Video: Web Codecs component. This vulnerability was fixed in Firefox 151=
    , Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 2026-05-19 n=
    ot yet calculated CVE-2026-8968 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-8968 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2030467 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Mitigation bypass in the DOM: Security component. T= his vulnerability was fixed in Firefox 151 and Thunderbird 151. 2026-05-19 = not yet calculated CVE-2026-8969 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-8969 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2031123 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Privilege escalation in the Security component. Thi=
    s vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 1= 51, and Thunderbird 140.11. 2026-05-19 not yet calculated CVE-2026-8970 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-8970 ] https://bugzilla.mozilla.= org/show_bug.cgi?id=3D2032174 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Same-origin policy bypass in the Networking: JAR co= mponent. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 2= 026-05-19 not yet calculated CVE-2026-8971 [ https://www.cve.org/CVERecord?= id=3DCVE-2026-8971 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2032604 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Privilege escalation in the WebRTC: Audio/Video com= ponent. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 20= 26-05-19 not yet calculated CVE-2026-8972 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-8972 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2033275 https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Memory safety bugs present in Thunderbird 150. Some=
    of these bugs showed evidence of memory corruption and we presume that wit=
    h enough effort some of these could have been exploited to run arbitrary co= de. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 2026-0= 5-19 not yet calculated CVE-2026-8973 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-8973 ] Memory safety bugs fixed in Thunderbird 151 [ https://bugzi= lla.mozilla.org/buglist.cgi?bug_id=3D1362365%2C1860538%2C1929005%2C1983353%= 2C1998526%2C2023271%2C2023943%2C2024244%2C2024260%2C2024443%2C2024665%2C202= 4774%2C2024916%2C2025346%2C2025357%2C2025406%2C2025434%2C2025488%2C2025496%= 2C2025942%2C2025947%2C2025968%2C2026279%2C2027159%2C2027239%2C2027276%2C202= 7308%2C2027310%2C2027324%2C2027329%2C2027363%2C2027381%2C2027382%2C2027383%= 2C2028274%2C2028884%2C2029060%2C2029065%2C2029068%2C2029281%2C2029293%2C202= 9297%2C2029303%2C2029439%2C2029448%2C2029703%2C2029720%2C2029721%2C2029723%= 2C2029770%2C2029771%2C2029782%2C2029818%2C2029885%2C2030100%2C2030379%2C203= 0385%2C2030979%2C2031119%2C2031122%2C2034119%2C2034791%2C2035209%2C2036666%= 2C2037986 ]
    https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-50/
    =C2=A0 Mozilla--Firefox Memory safety bugs present in Thunderbird 140.10 an=
    d Thunderbird 150. Some of these bugs showed evidence of memory corruption = and we presume that with enough effort some of these could have been exploi= ted to run arbitrary code. This vulnerability was fixed in Firefox 151, Fir= efox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 2026-05-19 not ye=
    t calculated CVE-2026-8974 [ https://www.cve.org/CVERecord?id=3DCVE-2026-89=
    74 ] Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 [ h= ttps://bugzilla.mozilla.org/buglist.cgi?bug_id=3D1784128%2C1883230%2C198367= 7%2C2022390%2C2023116%2C2023657%2C2024255%2C2024418%2C2024441%2C2024447%2C2= 024966%2C2025412%2C2025467%2C2025940%2C2025950%2C2025956%2C2026284%2C202724= 7%2C2027255%2C2027288%2C2027306%2C2027322%2C2027332%2C2027333%2C2028266%2C2= 028292%2C2028319%2C2028526%2C2028870%2C2028876%2C2028882%2C2029062%2C202930= 9%2C2029414%2C2029422%2C2029428%2C2029447%2C2029732%2C2029785%2C2029793%2C2= 029813%2C2029899%2C2031028%2C2031457%2C2032039%2C2033610%2C2033854%2C203449= 8%2C2034628%2C2034978%2C2035966%2C2036668%2C2036905%2C2036930 ] https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox Memory safety bugs present in Thunderbird 140.10 an=
    d Thunderbird 150. Some of these bugs showed evidence of memory corruption = and we presume that with enough effort some of these could have been exploi= ted to run arbitrary code. This vulnerability was fixed in Firefox 151, Fir= efox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.1=
    1. 2026-05-19 not yet calculated CVE-2026-8975 [ https://www.cve.org/CVERec= ord?id=3DCVE-2026-8975 ] Memory safety bugs fixed in Thunderbird 140.11 and=
    Thunderbird 151 [ https://bugzilla.mozilla.org/buglist.cgi?bug_id=3D186019= 5%2C2029325%2C2029429%2C2029910%2C2035915%2C2038678%2C2038669 ] https://www.mozilla.org/security/advisories/mfsa2026-46/ https://www.mozilla.org/security/advisories/mfsa2026-47/ https://www.mozilla.org/security/advisories/mfsa2026-48/ https://www.mozilla.org/security/advisories/mfsa2026-50/ https://www.mozilla.org/security/advisories/mfsa2026-51/
    =C2=A0 Mozilla--Firefox for iOS Firefox for iOS hosted Reader mode on an un= authenticated local web server, allowing another application on the same de= vice to request arbitrary URLs and receive the response rendered with the s= igned-in user's cookies. This vulnerability was fixed in Firefox for iOS 15= 1.0. 2026-05-19 not yet calculated CVE-2026-8706 [ https://www.cve.org/CVER= ecord?id=3DCVE-2026-8706 ] https://bugzilla.mozilla.org/show_bug.cgi?id=3D2= 036618
    https://www.mozilla.org/security/advisories/mfsa2026-49/
    =C2=A0 ngrok--ngrok v4.3.3 and 5.0.0-beta.2 ngrok v4.3.3 and 5.0.0-beta.2 i=
    s vulnerable to Command Injection. 2026-05-18 not yet calculated CVE-2025-5= 7282 [ https://www.cve.org/CVERecord?id=3DCVE-2025-57282 ] https://www.npmj= s.com
    https://gist.github.com/Dremig/90c2a0a2f85b0921f10e0bb3192a0c23
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound 1.6.2 up to and including ver= sion 1.25.0 has a denial of service vulnerability when compiled with DNSCry=
    pt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbo= und's DNSCrypt packet reading procedure that may lead to heap overflow. A m= alicious actor can exploit the vulnerability with a single bad DNSCrypt que=
    ry that its decrypted plaintext consists entirely of '0x00' bytes and does = not contain the expected '0x80' marker. Unbound would then start reading mo=
    re bytes than necessary until it finds a non-'0x00' byte. Based on the unde= rlying memory allocator and the memory layout, it could lead to heap overfl=
    ow while reading followed by a crash. Likelihood of a crash is low, since i=
    t relies heavily on the underlying memory allocator and the memory layout. =
    If the heap overflow does not happen, Unbound's later packet checks will de=
    ny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading =
    in the given buffer space. 2026-05-20 not yet calculated CVE-2026-32792 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-32792 ] https://www.nlnetlabs.nl= /downloads/unbound/CVE-2026-32792.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound 1.19.1 up to and including ve= rsion 1.25.0 has a vulnerability in the DNSSEC validator that enables denia=
    l of service and possible remote code execution as a result of deep copying=
    a data structure and erroneously overwriting a destination pointer. An adv= ersary can exploit the vulnerability by controlling a malicious signed zone=
    and querying a vulnerable Unbound. When DS sub-queries need to suspend val= idation due to NSEC3 computational budget exhaustion (introduced in Unbound=
    1.19.1), Unbound deep-copies response messages to preserve them across mem= ory region teardown. A struct-assignment bug overwrites the destination's p= ointer with the source's pointer. After the sub-query region is freed, the = resumed validator dereferences this dangling pointer, triggering a crash or=
    potentially enabling arbitrary code execution. Unbound 1.25.1 contains a p= atch with a fix to preserve the correct pointer when deep copying the data = structure. 2026-05-20 not yet calculated CVE-2026-33278 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-33278 ] https://www.nlnetlabs.nl/downloads/unbou= nd/CVE-2026-33278.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound 1.16.2 up to and including ve= rsion 1.25.0 has a vulnerability of the 'ghost domain names' family of atta= cks that could extend the ghost domain window by up to one cached TTL confi= gured value. Similar to other 'ghost domain names' attacks, an adversary ne= eds to control a (ghost) zone and be able to query a vulnerable Unbound. A = single client NS query can cause Unbound to overwrite the cached expired pa= rent-side referral NS rrset with the child-side apex NS rrset and essential=
    ly extend the ghost domain window by up to one cached TTL configured value = ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is u= sed (non-default configuration), no client NS query is required since Unbou=
    nd implicitly performs that query. Unbound 1.25.1 contains a patch with a f=
    ix that does not allow extension of TTLs for (parent) NS records regardless=
    of their trust. 2026-05-20 not yet calculated CVE-2026-40622 [ https://www= .cve.org/CVERecord?id=3DCVE-2026-40622 ] https://www.nlnetlabs.nl/downloads= /unbound/CVE-2026-40622.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound up to and including version 1= .25.0 is vulnerable to a degradation of service attack related to parsing l= ong lists of incoming EDNS options. An adversary sending queries with too m= any EDNS options can hold Unbound threads hostage while they are parsing an=
    d creating internal data structures for the options. Coordinated attacks ca=
    n result in degradation and/or denial of service. Unbound 1.25.1 contains a=
    patch with a fix to limit acceptable incoming EDNS options (100). 2026-05-=
    20 not yet calculated CVE-2026-41292 [ https://www.cve.org/CVERecord?id=3DC= VE-2026-41292 ] https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41292.t=
    xt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound up to and including version 1= .25.0 has a vulnerability in the jostle logic that could defeat its purpose=
    and degrade resolution performance. Retransmits of the same query could re= new the age of slow running queries and not allow the jostle logic to see t= hem as aged and potential targets for replacement with new queries. An adve= rsary who can query a vulnerable Unbound and who can control a domain name = server that replies slowly and/or maliciously to Unbound's queries can expl= oit the vulnerability and degrade the resolution performance of Unbound. Wh=
    en Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic k= icks in. When a new query comes in, half of the available queries that are = also slow to resolve are candidates for replacement. The vulnerability then=
    happens because duplicate queries that need resolution would skew the agin=
    g result by using the timestamp of the latest duplicate query instead of th=
    e original one that started the resolution effort. Cache and local data res= ponse performance remains unaffected. Coordinated attacks could raise this =
    to a denial of resolution service. Unbound 1.25.1 contains a patch with a f=
    ix to attach an initial, non-updatable start time for incoming queries that=
    allow the jostle logic to work as intended. 2026-05-20 not yet calculated = CVE-2026-42534 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42534 ] https:= //www.nlnetlabs.nl/downloads/unbound/CVE-2026-42534.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound up to and including version 1= .25.0 has a vulnerability in the DNSSEC validator where the code path to co= nsult the negative cache for DS records does not take into account the limi=
    t on NSEC3 hash calculations introduced in 1.19.1. This leads to degradatio=
    n of service during the attack. An adversary that controls a DNSSEC signed = zone can exploit this by signing NSEC3 records with acceptably high iterati= ons for child delegations and querying a vulnerable Unbound. Unbound will k= eep performing the allowed hash calculations on the NSEC3 records and will = not limit the work by the mitigation introduced in 1.19.1. As a side effect=
    , a global lock for the negative cache will be held for the duration of the=
    hashing, blocking other threads that need to consult the negative cache. C= oordinated attacks could raise the vulnerability to denial of service. Unbo= und 1.25.1 contains a patch with a fix to bound the vulnerable code path wi=
    th the existing limit for NSEC3 hash calculations. 2026-05-20 not yet calcu= lated CVE-2026-42923 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42923 ] = https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42923.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound 1.14.0 up to and including ve= rsion 1.25.0 has a vulnerability that results in heap overflow when encodin=
    g multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the r= eply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses'=
    (default)) need to be enabled for the vulnerability to be exploited. An ad= versary who can query Unbound can exploit the vulnerability by attaching mu= ltiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query=
    . A flaw in the size calculation of the EDNS field truncates the correct va= lue which allows the encoder to overflow the available space when writing. = Those two combined lead to a heap overflow write of Unbound controlled data=
    and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-d= uplicate the EDNS options and a fix to prevent truncation of the EDNS field=
    size calculation. 2026-05-20 not yet calculated CVE-2026-42944 [ https://w= ww.cve.org/CVERecord?id=3DCVE-2026-42944 ] https://www.nlnetlabs.nl/downloa= ds/unbound/CVE-2026-42944.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound up to and including version 1= .25.0 has a denial of service vulnerability in the DNSSEC validator that ca=
    n lead to a crash given malicious upstream replies. When Unbound constructs=
    chase-reply messages for validation, the code uses the wrong counter to ca= lculate write offsets for ADDITIONAL section rrsets. DNAME duplication coul=
    d increase the ANSWER section count and authority filtering could decrease = the AUTHORITY section count and create an uninitialized array slot. Combini=
    ng these two, the validator later dereferences this uninitialized pointer, = causing an immediate process crash. An adversary controlling a DNSSEC-signe=
    d domain can trigger this bug with a single query by configuring a DNAME ch= ain with unsigned CNAMEs and a response containing unsigned AUTHORITY recor=
    ds alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patc=
    h with a fix to use the proper counters to calculate the write offsets. 202= 6-05-20 not yet calculated CVE-2026-42959 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-42959 ] https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42= 959.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound up to and including version 1= .25.0 is vulnerable to poisoning via promiscuous records for the authority = section. Promiscuous RRSets that complement DNS replies in the authority se= ction can be used to trick Unbound to cache such records. If an adversary i=
    s able to attach such records in a reply (i.e., spoofed packet, fragmentati=
    on attack) he would be able to poison Unbound's cache. A malicious actor ca=
    n exploit the possible poisonous effect by injecting RRSets other than NS t= hat are also accompanied by address records in a reply, for example MX. Thi=
    s could be achieved by trying to spoof a reply packet or fragmentation atta= cks. Unbound would then accept the relative address records in the addition=
    al section and cache them if the authority RRSet has enough trust at this p= oint, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains =
    a patch with a fix that disregards address records from the additional sect= ion if they are not explicitly relevant only to authority NS records, mitig= ating the possible poison effect. This is a complement fix to CVE-2025-1141=
    1. 2026-05-20 not yet calculated CVE-2026-42960 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-42960 ] https://www.nlnetlabs.nl/downloads/unbound/CVE-2= 026-42960.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound up to and including version 1= .25.0 has a vulnerability when handling replies with very large RRsets that=
    Unbound needs to perform name compression for. Malicious upstream response=
    s with very large RRsets with records that don't share a suffix above the r= oot can cause Unbound to spend a considerable time applying name compressio=
    n to downstream replies. This can lead to degraded performance and eventual=
    ly denial of service in well orchestrated attacks. An adversary can exploit=
    the vulnerability by querying Unbound for the specially crafted contents o=
    f a malicious zone with very large RRsets. Before Unbound replies to the qu= ery it will try to apply name compression which was an unbounded operation = that could lock the CPU until the whole packet was complete. A compression = limit was introduced in 1.21.1 for this but it didn't account for the case = where records would not share any suffix above the root. That causes Unboun=
    d to go in a different code path because of the compression tree lookup fai= lure and eventually not increment the compression counter for those operati= ons. Unbound 1.25.1 contains a patch with a fix that increments the compres= sion counter regardless of the compression tree lookup. This is a complemen=
    t fix to CVE-2024-8508. 2026-05-20 not yet calculated CVE-2026-44390 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-44390 ] https://www.nlnetlabs.nl/do= wnloads/unbound/CVE-2026-44390.txt
    =C2=A0 NLnet Labs--Unbound NLnet Labs Unbound 1.14.0 up to and including ve= rsion 1.25.0 has a locking inconsistency vulnerability that when certain co= nditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/= 'rpz-nsdname' triggers) it could result in heap use-after-free and eventual=
    crash. An adversary can exploit the vulnerability if conditions are first = met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-ns= ip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ = files do not trigger the vulnerability. If the timing is right and an XFR h= appens at the same time another thread needs to read that RPZ zone, the rea= der may not hold the lock long enough and the thread applying the XFR may f= ree objects that the reader is about to walk causing the use-after-free. Un= bound 1.25.1 contains a patch with a fix to the locking code. 2026-05-20 no=
    t yet calculated CVE-2026-44608 [ https://www.cve.org/CVERecord?id=3DCVE-20= 26-44608 ] https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44608.txt
    =C2=A0 NOVUS -- AirGate 4G Incorrect access control in the /uci/get/ endpoi=
    nt of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to=
    obtain administrator credentials via a crafted POST request. 2026-05-18 no=
    t yet calculated CVE-2023-24215 [ https://www.cve.org/CVERecord?id=3DCVE-20= 23-24215 ] http://airgate.com
    http://novus.com https://github.com/sql3t0/cve-disclosures/blob/main/00_-_CVE-2023-24215.md =C2=A0 Offline Hospital Management System--Offline Hospital Management Syst=
    em 5.3.0 Offline Hospital Management System 5.3.0 allows remote code execut= ion due to an improper Electron renderer configuration. The application ena= bles Node.js integration while disabling context isolation, allowing JavaSc= ript executed in the renderer process to access Node.js APIs and execute ar= bitrary operating system commands. 2026-05-18 not yet calculated CVE-2026-2= 6462 [ https://www.cve.org/CVERecord?id=3DCVE-2026-26462 ] https://sourcefo= rge.net/projects/hospital-management-system/files/ https://medium.com/@husaainpalh/remote-code-execution-in-offline-hospital-m= anagement-system-cve-2026-26462-bc7ac54314c4
    =C2=A0 OpENer--OpENer v2.3-558-g1e99582 OpENer v2.3-558-g1e99582 contains a=
    n out-of-bounds read vulnerability in the Common Packet Format (CPF) parser=
    , specifically in CreateCommonPacketFormatStructure() in source/src/enet_en= cap/cpf.c. A crafted ENIP/CPF message can supply an attacker-controlled ite= m_count value that is not consistently validated against the remaining data= _length of the CPF slice 2026-05-18 not yet calculated CVE-2026-38719 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-38719 ] https://github.com/EIPStac= kGroup/OpENer
    https://github.com/EIPStackGroup/OpENer/issues/558
    =C2=A0 Perforce--P4 (Helix Core) A Remote Code Execution vulnerability in P=
    4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, h=
    as been fixed to address potential security risks. 2026-05-18 not yet calcu= lated CVE-2026-6902 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6902 ] ht= tps://portal.perforce.com/s/cve/a91Qi000002zJB3IAM/code-injection-in-perfor= ce-helix-core
    =C2=A0 phenixdigital--phoenix_storybook Authorization Bypass Through User-C= ontrolled Key vulnerability in phenixdigital phoenix_storybook allows cross= -session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixS= torybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storyboo= k/live/story/component_iframe_live.ex reads a PubSub topic directly from pa= rams["topic"] and broadcasts {:component_iframe_pid, self()} on it with no = check that the topic belongs to the requesting session. The shared PhoenixS= torybook.PubSub is used to coordinate playground LiveViews with their ifram= es: a playground subscribes to a session-specific topic and uses the receiv=
    ed iframe pid to direct subsequent control messages (variation state, theme=
    switches, extra-assign payloads) via send/2. Because the iframe trusts the=
    query parameter, an attacker who loads /storybook/iframe/<story>?topic=3D<= victim_topic> causes their iframe process pid to be announced on the victim=
    's topic. The victim's playground then addresses its private messages to th=
    e attacker's iframe process. This issue affects phoenix_storybook from 0.4.=
    0 before 1.1.0. 2026-05-20 not yet calculated CVE-2026-47068 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-47068 ] https://github.com/phenixdigital/ph= oenix_storybook/security/advisories/GHSA-mrhx-6pw9-q5fh https://cna.erlef.org/cves/CVE-2026-47068.html https://osv.dev/vulnerability/EEF-CVE-2026-47068 https://github.com/phenixdigital/phoenix_storybook/commit/6ee03f1c738d4436d= de1b066cf65c80663d489f5
    =C2=A0 phenixdigital--phoenix_storybook Code Injection vulnerability in phe= nixdigital phoenix_storybook allows unauthenticated remote code execution v=
    ia unsanitized attribute value interpolation in HEEx template generation. T=
    he psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.Pla= ygroundPreviewLive':handle_event/3 accepts arbitrary attribute names and va= lues from unauthenticated clients. These values are passed to 'Elixir.Phoen= ixStorybook.Helpers.ExtraAssignsHelpers':handle_set_variation_assign/3, whi=
    ch stores them verbatim. When rendering, 'Elixir.PhoenixStorybook.Rendering= .ComponentRenderer':attributes_markup/1 interpolates binary attribute value=
    s directly into a HEEx template string as name=3D"<val>" without escaping d= ouble quotes or HEEx expression delimiters. An attacker can supply a value = containing a closing quote followed by a HEEx expression block (e.g. foo" i= njected=3D{EXPR} bar=3D"), which causes EXPR to be treated as an inline Eli= xir expression. The resulting template is compiled via EEx.compile_string/2=
    and executed via Code.eval_quoted_with_env/3 with full Kernel imports and =
    no sandbox, giving the attacker arbitrary code execution on the server. Thi=
    s issue affects phoenix_storybook from 0.5.0 before 1.1.0. 2026-05-20 not y=
    et calculated CVE-2026-8467 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8= 467 ] https://github.com/phenixdigital/phoenix_storybook/security/advisorie= s/GHSA-55hg-8qxv-qj4p
    https://cna.erlef.org/cves/CVE-2026-8467.html https://osv.dev/vulnerability/EEF-CVE-2026-8467 https://github.com/phenixdigital/phoenix_storybook/commit/56ab8464d4375fa52= db806148a06cce126ad481d
    =C2=A0 phenixdigital--phoenix_storybook Allocation of Resources Without Lim= its or Throttling vulnerability in phenixdigital phoenix_storybook allows u= nauthenticated denial-of-service via BEAM atom table exhaustion. Multiple L= iveView event handlers convert user-supplied event parameter strings to ato=
    ms using String.to_atom/1 without validation: 'Elixir.PhoenixStorybook.Extr= aAssignsHelpers':handle_set_variation_assign/3 interns every key of the psb= -assign params map; 'Elixir.PhoenixStorybook.ExtraAssignsHelpers':handle_to= ggle_variation_assign/3 interns the "attr" value from psb-toggle events; 'E= lixir.PhoenixStorybook.ExtraAssignsHelpers':to_variation_id/2 interns eleme= nts of "variation_id"; and 'Elixir.PhoenixStorybook.ExtraAssignsHelpers':to= _value/4 interns raw string values for attributes declared as :atom or :boo= lean. BEAM atoms are never garbage-collected, so each unique attacker-contr= olled string is a permanent allocation. Once the atom table ceiling (~1,048= ,576 atoms) is reached, the entire BEAM node aborts, taking down all applic= ations running on it. This issue affects phoenix_storybook from 0.2.0 befor=
    e 1.1.0. 2026-05-20 not yet calculated CVE-2026-8469 [ https://www.cve.org/= CVERecord?id=3DCVE-2026-8469 ] https://github.com/phenixdigital/phoenix_sto= rybook/security/advisories/GHSA-833p-95jq-929q https://cna.erlef.org/cves/CVE-2026-8469.html https://osv.dev/vulnerability/EEF-CVE-2026-8469 https://github.com/phenixdigital/phoenix_storybook/commit/96d524690af0fe197= a49f60d18e564a620b9ef81
    =C2=A0 prefecthq--prefecthq/prefect A vulnerability in the `GitHubRepositor=
    y` block of the `prefect-github` integration in Prefect version 3.6.18 allo=
    ws an attacker to inject arbitrary git command-line options via the `refere= nce` field. The `reference` field is concatenated directly into a `git clon=
    e` command string without proper sanitization, and then parsed by `shlex.sp= lit()`. This enables injection of options such as `-c`, leading to potentia=
    l Server-Side Request Forgery (SSRF), credential theft, or remote code exec= ution (RCE). The vulnerability affects both the `aget_directory()` and `get= _directory()` methods in `src/integrations/prefect-github/prefect_github/re= pository.py`. This issue does not affect the GitLab and BitBucket integrati= ons, which use a safer list-based command construction approach. 2026-05-24=
    not yet calculated CVE-2026-3515 [ https://www.cve.org/CVERecord?id=3DCVE-= 2026-3515 ] https://huntr.com/bounties/f3b048b8-7f4e-45ef-a5a7-cb841c39acde =C2=A0 PrestaShop--upsshipping module An issue in prestashop upsshipping al=
    l versions through at least 2.4.0 allows a remote attacker to obtain sensit= ive information via the /modules/upsshipping/logs/, and /modules/upsshippin= g/lib/UPSBaseApi.php components 2026-05-18 not yet calculated CVE-2026-3907=
    9 [ https://www.cve.org/CVERecord?id=3DCVE-2026-39079 ] https://labs.esokia= .com/cve/cve-2026-39079/
    =C2=A0 Rocket.Chat--Rocket.Chat The /api/v1/autotranslate.translateMessage = endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.=
    8, and <7.10.12 allows any authenticated user to retrieve the full content =
    of any message from any room (private groups, direct messages, channels) by=
    simply providing the target message ID. The endpoint fetches the message v=
    ia Messages.findOneById(messageId) with no room access check (canAccessRoom= IdAsync is never called), returning the complete IMessage object including = message text, sender info, room ID, timestamps, and markdown content. 2026-= 05-19 not yet calculated CVE-2026-32994 [ https://www.cve.org/CVERecord?id= =3DCVE-2026-32994 ] https://hackerone.com/reports/3713682
    =C2=A0 RRWO--Crypt::SaltedHash Crypt::SaltedHash versions through 0.09 for = Perl generate insecure random values for salts. These versions use the buil= t-in rand function, which is predictable and unsuitable for cryptography. 2= 026-05-20 not yet calculated CVE-2026-47372 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-47372 ] https://metacpan.org/release/RRWO/Crypt-SaltedHash-0= .10/changes https://github.com/robrwo/perl-Crypt-SaltedHash/commit/9b68437d2cd420b819b3= a795474c3870338d38d5.patch
    =C2=A0 RRWO--Crypt::SaltedHash Crypt::SaltedHash versions through 0.09 for = Perl is susceptible to timing attacks. These versions use Perl's built-in e=
    q comparison. Discrepencies in timing could be used to guess the underlying=
    hash. 2026-05-20 not yet calculated CVE-2026-47373 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-47373 ] https://metacpan.org/release/RRWO/Crypt-Salt= edHash-0.10/changes https://github.com/robrwo/perl-Crypt-SaltedHash/commit/c07bfc5c23185b066723= 3d0f2e1252d81f1f027a.patch
    =C2=A0 RRWO--Net::Statsd::Lite Net::Statsd::Lite versions through 0.10.0 fo=
    r Perl allowed metric injections. The values from the set_add method were n=
    ot checked for newlines, colons or pipes. Metrics generated from untrusted = sources could inject additional statsd metrics. Note that version 0.9.0 fix=
    ed a similar issue CVE-2026-46719 for metric names. 2026-05-18 not yet calc= ulated CVE-2026-8788 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8788 ] h= ttps://metacpan.org/release/RRWO/Net-Statsd-Lite-v0.10.1/changes https://www.cve.org/CVERecord?id=3DCVE-2026-46719
    =C2=A0 ScadaBR--ScadaBR In ScadaBR version 1.2.0, a Missing Authentication = for Critical Function vulnerability could allow an unauthenticated attacker=
    to send a HTTP GET requests to the SCADA system and inject arbitrary senso=
    r readings. 2026-05-19 not yet calculated CVE-2026-8602 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2026-8602 ] https://www.cisa.gov/news-events/ics-advi= sories/icsa-26-139-03
    =C2=A0 ScadaBR--ScadaBR In ScadaBR version 1.2.0, an OS Command Injection v= ulnerability could allow an attacker to execute commands as root on the SCA=
    DA system. 2026-05-19 not yet calculated CVE-2026-8603 [ https://www.cve.or= g/CVERecord?id=3DCVE-2026-8603 ] https://www.cisa.gov/news-events/ics-advis= ories/icsa-26-139-03
    =C2=A0 ScadaBR--ScadaBR In ScadaBR version 1.2.0, a CSRF vulnerability coul=
    d allow an attacker to trigger any authenticated action through a victim's = session by luring any logged-in user to a malicious webpage. 2026-05-19 not=
    yet calculated CVE-2026-8604 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -8604 ] https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03
    =C2=A0 ScadaBR--ScadaBR In ScadaBR version 1.2.0, a Use of Hard-Coded Crede= ntials vulnerability could allow an attacker to access the SCADA system as = admin. 2026-05-19 not yet calculated CVE-2026-8605 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-8605 ] https://www.cisa.gov/news-events/ics-advisorie= s/icsa-26-139-03
    =C2=A0 scalar--astro v0.1.13 scalar/astro v0.1.13 was discovered to contain=
    an arbitrary file upload vulnerability in the the scalar_url query paramet=
    er of the Scalar Proxy endpoint. This vulnerability allows attackers to exe= cute arbitrary code via uploading a crafted SVG file. 2026-05-19 not yet ca= lculated CVE-2026-30117 [ https://www.cve.org/CVERecord?id=3DCVE-2026-30117=
    ] https://github.com/prassan10/XSS-Open-Redirect-via-scalar_url
    =C2=A0 scalar--astro v0.1.13 scalar/astro v0.1.13 was discovered to contain=
    a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of = the Scalar Proxy endpoint. This vulnerability allows unauthenticated attack= ers to force the backend server to send HTTP requests to attacker-controlle=
    d URLs, leading to authentication cookies and headers exposure and possible=
    privilege escalation. 2026-05-19 not yet calculated CVE-2026-30118 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-30118 ] https://github.com/prassan10= /ssrf-zero-click-ato-scalar
    =C2=A0 SGLang--SGLang SGLangs multimodal generation runtime scheduler's ROU= TER socket binds to 0.0.0.0 by default and contains a sink that calls pickl= e.loads() on incoming messages, enabling RCE when exposed to the internet. = 2026-05-18 not yet calculated CVE-2026-7301 [ https://www.cve.org/CVERecord= ?id=3DCVE-2026-7301 ] https://github.com/sgl-project/sglang/tree/main/pytho= n/sglang
    https://antiproof.ai/blog/three-rces-in-sglang/
    =C2=A0 SGLang--SGLang SGLangs multimodal generation runtime is vulnerable t=
    o an unauthenticated path traversal vulnerability, allowing an attacker to = write arbitrary files anywhere the server process has write access, by incl= uding ../ sequences in the upload filename when sent to specific endpoints.=
    2026-05-18 not yet calculated CVE-2026-7302 [ https://www.cve.org/CVERecor= d?id=3DCVE-2026-7302 ] https://github.com/sgl-project/sglang/tree/main/pyth= on/sglang
    https://antiproof.ai/blog/three-rces-in-sglang/
    =C2=A0 SGLang--SGLang SGLangs multimodal generation runtime is vulnerable t=
    o unauthenticated remote code execution when the --enable-custom-logit-proc= essor option is enabled, as Python objects loaded via dill.loads() will be = deserialized without validation. 2026-05-18 not yet calculated CVE-2026-730=
    4 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7304 ] https://github.com/s= gl-project/sglang/tree/main/python/sglang https://antiproof.ai/blog/three-rces-in-sglang/
    =C2=A0 Siber Systems, Inc.--Android App "RoboForm Password Manager" Android=
    App "RoboForm Password Manager" provided by Siber Systems, Inc. handles An= droid intents without sufficient URL validation, user confirmation nor noti= fication. If a URL to some malicious web page is given through an intent, R= oboForm may silently download files without user confirmation nor notificat= ion. 2026-05-20 not yet calculated CVE-2026-47782 [ https://www.cve.org/CVE= Record?id=3DCVE-2026-47782 ] https://play.google.com/store/apps/details?id= =3Dcom.siber.roboform
    https://www.roboform.com/news-android
    https://jvn.jp/en/vu/JVNVU93461473/
    =C2=A0 simplesamlphp--simplesamlphp-module-casserver SimpleSAMLphp-casserve=
    r is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp = module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a ur=
    l query parameter to redirect to. casserver treats that url as trusted, and=
    either (depending on configuration) redirects the browser there, or shows =
    a "you've been logged out" page with a link to continue to that url. Impact=
    ed configs include 'enable_logout' =3D> true, and 'skip_logout_page' -> tru=
    e. This issue has been resolved in versions 6.3.1 and 7.0.0. 2026-05-18 not=
    yet calculated CVE-2025-65954 [ https://www.cve.org/CVERecord?id=3DCVE-202= 5-65954 ] https://github.com/simplesamlphp/simplesamlphp-module-casserver/s= ecurity/advisories/GHSA-cvrm-5hp6-h523 https://github.com/simplesamlphp/simplesamlphp-module-casserver/commit/0462= f50f00b3bb300d83067d11b74146a57bb8e0 https://github.com/simplesamlphp/simplesamlphp-module-casserver/commit/fb6c= 6f1c7b9e757c93c5c306e1d36405e64f6dc5
    =C2=A0 Six Apart Ltd.--Movable Type Missing authorization vulnerability exi= sts in Movable Type. Under certain conditions, when a user without administ= rator privileges signs in to the product, unintended update processing may =
    be executed. 2026-05-20 not yet calculated CVE-2026-44392 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-44392 ] https://movabletype.org/news/2026/05/m= t-908-released.html https://www.sixapart.jp/movabletype/news/2026/05/20-1100.html https://jvn.jp/en/jp/JVN66473735/
    =C2=A0 Sparx Systems--Enterprise Architect Sparx Enterprise Architect softw= are has a security feature that limits user's actions to those specified in=
    the role. An authenticated attacker can modify the Enterprise Architect cl= ient behavior (e.g. using a debugger) and log in as any other user or admin= istrator - then it is possible to do every possible change to the repositor=
    y. The vendor was notified early about this vulnerability, but didn't respo=
    nd with the details of vulnerability or vulnerable version range. Only vers= ion 17.1 and below were tested and confirmed as vulnerable, other versions = were not tested and might also be vulnerable. 2026-05-19 not yet calculated=
    CVE-2026-42098 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42098 ] https= ://cert.pl/en/posts/2026/05/CVE-2026-42096 https://sparxsystems.com/products/ea/ https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html https://efigo.pl/blog/CVE-2026-42096/
    =C2=A0 Sparx Systems--Pro Cloud Server Sparx Pro Cloud Server is vulnerable=
    to Broken Access Control within communication with the database. Due to la=
    ck of permission checks, any low privileged user can run arbitrary SQL quer= ies within database user context. The vendor was notified early about this = vulnerability, but didn't respond with the details of vulnerability or vuln= erable version range. Only version 6.1 (build 167) and below were tested an=
    d confirmed as vulnerable, other versions were not tested and might also be=
    vulnerable. 2026-05-19 not yet calculated CVE-2026-42096 [ https://www.cve= .org/CVERecord?id=3DCVE-2026-42096 ] https://cert.pl/en/posts/2026/05/CVE-2= 026-42096
    https://sparxsystems.com/products/procloudserver/ https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html https://efigo.pl/blog/CVE-2026-42096/
    =C2=A0 Sparx Systems--Pro Cloud Server Sparx Pro Cloud Server=C2=A0requires=
    authentication based on requested URL. An=C2=A0attacker can omit the "mode=
    l" query parameter and send the model name only in the binary blob in POST = request=C2=A0allowing SQL query execution without authentication. The vendo=
    r was notified early about this vulnerability, but didn't respond with the = details of vulnerability or vulnerable version range. Only version 6.1 (bui=
    ld 167) and below were tested and confirmed as vulnerable, other versions w= ere not tested and might also be vulnerable. 2026-05-19 not yet calculated = CVE-2026-42097 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42097 ] https:= //cert.pl/en/posts/2026/05/CVE-2026-42096 https://sparxsystems.com/products/procloudserver/ https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html https://efigo.pl/blog/CVE-2026-42096/
    =C2=A0 Sparx Systems--Pro Cloud Server Sparx Pro Cloud Server is vulnerable=
    to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. Th=
    e application downloads the properties of the object pointed by guid parame= ter and saves loaded content in current location=C2=A0(__DIR__)=C2=A0under = the specified name. An attacker with repository access can control both the=
    filename and file contents, allowing the creation of a malicious PHP file =
    in a current directory. Although the file is deleted after processing, a ra=
    ce condition exists: if the response transmission is delayed (e.g., via a l= arge file or slow client connection), the file remains accessible. During t= his window, the attacker can issue a second request to execute the maliciou=
    s PHP file, resulting in remote code execution. The vendor was notified ear=
    ly about this vulnerability, but didn't respond with the details of vulnera= bility or vulnerable version range. Only version 6.1 (build 167) and below = were tested and confirmed as vulnerable, other versions were not tested and=
    might also be vulnerable. 2026-05-19 not yet calculated CVE-2026-42099 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-42099 ] https://cert.pl/en/posts= /2026/05/CVE-2026-42096
    https://sparxsystems.com/products/procloudserver/ https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html https://efigo.pl/blog/CVE-2026-42096/
    =C2=A0 Sparx Systems--Pro Cloud Server Improper Handling of Syntactically I= nvalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) a= ttack to be executed by=C2=A0sending an specially crafted SQL query. This c= auses the Pro Cloud Server service to terminate unexpectedly.=C2=A0 The ven= dor was notified early about this vulnerability, but didn't respond with th=
    e details of vulnerability or vulnerable version range. Only version 6.1 (b= uild 167) and below were tested and confirmed as vulnerable, other versions=
    were not tested and might also be vulnerable. 2026-05-19 not yet calculate=
    d CVE-2026-42100 [ https://www.cve.org/CVERecord?id=3DCVE-2026-42100 ] http= s://cert.pl/en/posts/2026/05/CVE-2026-42096 https://sparxsystems.com/products/procloudserver/ https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html https://efigo.pl/blog/CVE-2026-42096/
    =C2=A0 strukturag--libheif libheif is a HEIF and AVIF file format decoder a=
    nd encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file wher=
    e the saiz box declares more samples than actually exist in the track's chu=
    nk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAu= xInfoReader constructor. The SampleAuxInfoReader constructor iterates over = saiz->get_num_samples() samples but doesn't validate that this count is con= sistent with the number of chunks in the chunks vector. When saiz declares = more samples than the chunks cover, the loop increments current_chunk past = chunks.size(), causing an out-of-bounds read on the chunks vector. The vuln= erability is triggered during file parsing (heif_context_read_from_file) wi= thout any additional user interaction. Any application using libheif to ope=
    n untrusted HEIF files is affected. This issue has been fixed in version 1.= 22.0. 2026-05-22 not yet calculated CVE-2026-41071 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-41071 ] https://github.com/strukturag/libheif/securit= y/advisories/GHSA-xj92-xjff-h8w3 https://github.com/strukturag/libheif/releases/tag/v1.22.0
    =C2=A0 TCHATZI--Authen::TOTP Authen::TOTP versions before 0.1.1 for Perl ge= nerate secrets using rand. Secrets were generated using Perl's built-in ran=
    d function, which is predictable and unsuitable for security usage. 2026-05= -21 not yet calculated CVE-2026-46473 [ https://www.cve.org/CVERecord?id=3D= CVE-2026-46473 ] https://metacpan.org/release/TCHATZI/Authen-TOTP-0.1.1/cha= nges https://github.com/tchatzi/Authen-TOTP/commit/d04f30cc6538d77fc6b6d550da450= cf3017b8561.patch
    =C2=A0 The Qt Company--Qt An Uncontrolled Search Path Element vulnerability=
    in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix=
    ) allows a local attacker to load a rogue CA certificate as a trusted syste=
    m authority via a crafted certificate file placed in the application's work= ing directory. 2026-05-19 not yet calculated CVE-2025-14575 [ https://www.c= ve.org/CVERecord?id=3DCVE-2025-14575 ] Gerrit: QSslCertificate::fromPath = =C3=A2=E2=82=AC=E2=80=9D reject empty path strings (Qt 6.9.2+) [ https://co= dereview.qt-project.org/c/qt/qtbase/+/642967 ]
    =C2=A0 Thermo Fisher--Scientific Torrent Suite Dx Thermo Fisher Scientific = Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability th=
    at may allow an authenticated user with limited access privileges to gain u= nauthorized administrator-level privileges through exploitation of specific=
    system interfaces. 2026-05-18 not yet calculated CVE-2026-41085 [ https://= www.cve.org/CVERecord?id=3DCVE-2026-41085 ] https://thermofisher.com https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/TorrentSu= iteDxSoftware_v5_14_2.pdf
    =C2=A0 tinyMQTT--tinyMQTT In tinyMQTT commit 6226ade15bd4f97be2d196352e64d= d10937c1962 (2024-02-18), the broker mishandles protocol violations during = CONNECT packet parsing. When receiving a CONNECT packet with a zero-length = Client ID while CleanSession is set to 0, the broker correctly replies with=
    a CONNACK return code 0x02 (Identifier Rejected) but fails to explicitly c= lose the TCP connection. Since the surrounding connection teardown logic is=
    not guaranteed to execute, each such invalid CONNECT attempt leaves the un= derlying socket open. Repeated attempts cause server-side resource exhausti=
    on due to accumulating file descriptors and memory usage, potentially resul= ting in denial of service. 2026-05-18 not yet calculated CVE-2025-56352 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2025-56352 ] https://github.com/JustD= oIt0910/tinyMQTT/issues/19
    =C2=A0 TODDR--Template::Plugin::HTML Template::Plugin::HTML versions throug=
    h 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter=
    function did not escape single quotes. HTML attributes inside of single qu= otes could be have code injected. For example, the variable "var" in <a id= =3D'ref' title=3D'[% var | html %]'> would not be properly escaped. An atta= cker could insert some limited HTML and JavaScript, for example, var =3D " =
    ' onclick=3D'while (true) { alert(1) }'" Note that arbitrary HTML and JavaS= cript would be difficult to inject, because angle brackets, ampersands and = double-quotes would still be escaped. 2026-05-19 not yet calculated CVE-202= 6-5090 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5090 ] https://github.= com/abw/Template2/issues/327 https://github.com/abw/Template2/pull/337/changes/11c78a7a771d4af505efeb754= a0b8775689c2eae
    =C2=A0 TP-Link Systems Inc.--Archer AX72 (SG) v1.0 In the web management in= terface of Archer AX72 (SG) v1, the network diagnostic feature improperly h= andles invalid user input, resulting in limited exposure of diagnostic comm= and usage information.=C2=A0 An authenticated attacker with administrative = privileges could exploit this issue to confirm the presence of the diagnost=
    ic utility and view its valid command-line syntax and options.=C2=A0 The ex= posed information is limited in scope and does not include sensitive system=
    data. 2026-05-19 not yet calculated CVE-2026-5511 [ https://www.cve.org/CV= ERecord?id=3DCVE-2026-5511 ] https://www.tp-link.com/sg/support/download/ar= cher-ax72/#Firmware
    https://www.tp-link.com/us/support/faq/5096/
    =C2=A0 TP-Link Systems Inc.--Archer RE650 v1 An authentication logic vulner= ability in multiple TP-Link range extenders allows an unauthenticated attac= ker on an adjacent network to manipulate a login parameter and reset the ad= ministrator password due to insufficient validation. Successful exploitatio=
    n allows an attacker to obtain full administrative control of the affected = device, potentially impacting on confidentiality, integrity, and availabili= ty. 2026-05-22 not yet calculated CVE-2026-3294 [ https://www.cve.org/CVERe= cord?id=3DCVE-2026-3294 ] https://www.tp-link.com/en/support/download/re650= /v1/#Firmware
    https://www.tp-link.com/us/support/download/re650/v1/#Firmware https://www.tp-link.com/us/support/download/re305/v1/#Firmware https://www.tp-link.com/en/support/download/re305/v1/#Firmware https://www.tp-link.com/us/support/download/re360/v1/#Firmware https://www.tp-link.com/en/support/download/re360/v1/#Firmware https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware https://www.tp-link.com/en/support/download/re580d/#Firmware https://www.tp-link.com/us/support/download/re580d/#Firmware https://www.tp-link.com/us/support/faq/5101/
    =C2=A0 Trend Micro, Inc.--TrendAI Apex One (Mac) An origin validation error=
    vulnerability in the Trend Micro Apex One (mac) agent iCore service could = allow a local attacker to escalate privileges on affected installations. Pl= ease note: an attacker must first obtain the ability to execute low-privile= ged code on the target system in order to exploit this vulnerability. The f= ollowing information is provided as informational only for CVE references, =
    as these were addressed already via ActiveUpdate/SaaS updates in mid to lat=
    e 2025 (SaaS 2507 & 2005 Yearly Release). 2026-05-21 not yet calculated CVE= -2025-71214 [ https://www.cve.org/CVERecord?id=3DCVE-2025-71214 ] https://s= uccess.trendmicro.com/en-US/solution/KA-0022458 https://www.zerodayinitiative.com/advisories/ZDI-26-139/
    =C2=A0 Trend Micro, Inc.--TrendAI Apex One (Mac) A time-of-check time-of-us=
    e vulnerability in the Trend Micro Apex One (mac) agent iCore service signa= ture verification could allow a local attacker to escalate privileges on af= fected installations. Please note: an attacker must first obtain the abilit=
    y to execute low-privileged code on the target system in order to exploit t= his vulnerability. The following information is provided as informational o= nly for CVE references, as these were addressed already via ActiveUpdate/Sa=
    aS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release). 2026-05-2=
    1 not yet calculated CVE-2025-71215 [ https://www.cve.org/CVERecord?id=3DCV= E-2025-71215 ] https://success.trendmicro.com/en-US/solution/KA-0022458 https://www.zerodayinitiative.com/advisories/ZDI-26-141/
    =C2=A0 Trend Micro, Inc.--TrendAI Apex One (Mac) A time-of-check time-of-us=
    e vulnerability in the Trend Micro Apex One (mac) agent cache mechanism cou=
    ld allow a local attacker to escalate privileges on affected installations.=
    Please note: an attacker must first obtain the ability to execute low-priv= ileged code on the target system in order to exploit this vulnerability. Th=
    e following information is provided as informational only for CVE reference=
    s, as these were addressed already via ActiveUpdate/SaaS updates in mid to = late 2025 (SaaS 2507 & 2005 Yearly Release). 2026-05-21 not yet calculated = CVE-2025-71216 [ https://www.cve.org/CVERecord?id=3DCVE-2025-71216 ] https:= //success.trendmicro.com/en-US/solution/KA-0022458 https://www.zerodayinitiative.com/advisories/ZDI-26-142/
    =C2=A0 Trend Micro, Inc.--TrendAI Apex One (Mac) An origin validation error=
    vulnerability in the Trend Micro Apex One (mac) agent self-protection mech= anism could allow a local attacker to escalate privileges on affected insta= llations. Please note: an attacker must first obtain the ability to execute=
    low-privileged code on the target system in order to exploit this vulnerab= ility. The following information is provided as informational only for CVE = references, as these were addressed already via ActiveUpdate/SaaS updates i=
    n mid to late 2025 (SaaS 2507 & 2005 Yearly Release). 2026-05-21 not yet ca= lculated CVE-2025-71217 [ https://www.cve.org/CVERecord?id=3DCVE-2025-71217=
    ] https://success.trendmicro.com/en-US/solution/KA-0022458 https://www.zerodayinitiative.com/advisories/ZDI-26-143/
    =C2=A0 Trimble--SketchUp A cross-site scripting (XSS) vulnerability in Sket= chUp 2026's Dynamic Components feature allows remote code execution and loc=
    al file exfiltration through maliciously crafted SKP files. The vulnerabili=
    ty stems from improper input sanitization in the component options window, = enabling attackers to execute arbitrary system commands and read local file=
    s without user interaction by exploiting an embedded Internet Explorer 11 b= rowser. 2026-05-22 not yet calculated CVE-2026-9264 [ https://www.cve.org/C= VERecord?id=3DCVE-2026-9264 ] https://trust.trimble.com/?tcuUid=3D52252bc0-= c196-4b1f-9f13-4e4c9ba247d9
    =C2=A0 TYPO3--Extension "Address List" The AddressRepository::getSqlQuery()=
    method constructs a database query without properly sanitizing user input,=
    leading to SQL Injection. The method is not invoked anywhere within the ex= tension itself and therefore poses no direct risk in a default installation=
    . However, custom extensions that call this method with untrusted input wou=
    ld expose the site to SQL injection. 2026-05-19 not yet calculated CVE-2026= -8827 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8827 ] https://typo3.or= g/security/advisory/typo3-ext-sa-2026-012
    =C2=A0 TYPO3--Extension "Content Element Selector" The extension passes an = attacker-controlled cookie directly to PHP's unserialize() without safely p= rocessing the input. A remote, unauthenticated attacker can supply a crafte=
    d serialized payload to trigger PHP Object Injection, leading to Remote Cod=
    e Execution on the TYPO3 server. Exploitation requires the content element =
    to be configured with "Persistent Mode: Static" in the plugin settings. 202= 6-05-19 not yet calculated CVE-2026-46725 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-46725 ] https://typo3.org/security/advisory/typo3-ext-sa-2026-= 013
    =C2=A0 TYPO3--Extension "Faceted Search" The OOXML parsing of the file inde= xer does not disable external entity resolution. A crafted xlsx or pptx doc= ument placed in an indexed directory can cause local files to be read or ou= tbound HTTP requests to be performed, with the retrieved content being writ= ten to the search index. 2026-05-19 not yet calculated CVE-2026-46722 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-46722 ] https://typo3.org/security= /advisory/typo3-ext-sa-2026-011
    =C2=A0 TYPO3--Extension "Faceted Search" The additional_tables configuratio=
    n of the page and tt_content indexers accepts arbitrary table and field nam= es. A backend user with permission to edit indexer configurations can copy = sensitive data from internal TYPO3 tables into the search index. 2026-05-19=
    not yet calculated CVE-2026-46723 [ https://www.cve.org/CVERecord?id=3DCVE= -2026-46723 ] https://typo3.org/security/advisory/typo3-ext-sa-2026-011
    =C2=A0 TYPO3--Extension "Faceted Search" The file indexer does not normaliz=
    e the configured directory path. A backend user with permission to edit ind= exer configurations can index documents from arbitrary locations on the ser= ver file system through path traversal sequences. 2026-05-19 not yet calcul= ated CVE-2026-46724 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46724 ] h= ttps://typo3.org/security/advisory/typo3-ext-sa-2026-011
    =C2=A0 TYPO3--Extension "Frontend User Registration" The create and edit fl= ows do not restrict which user properties may be submitted and do not enfor=
    ce access control on the frontend user group assignment. As a result, an at= tacker can assign an arbitrary frontend user group to a newly registered or=
    edited account, gaining unauthorized access to content and functionality r= estricted to privileged frontend user groups. 2026-05-19 not yet calculated=
    CVE-2026-46721 [ https://www.cve.org/CVERecord?id=3DCVE-2026-46721 ] https= ://typo3.org/security/advisory/typo3-ext-sa-2026-009
    =C2=A0 TYPO3--Extension "News system" The extension fails to properly sanit= ize user input before using it in a database query. As a result, an unauthe= nticated attacker can inject arbitrary SQL through a URL parameter on pages=
    using the "Date Menu of news articles" plugin. Exploitation requires the "= Date Menu of news articles" plugin to be in use and the TypoScript/Plugin s= etting disableOverrideDemand not to be enabled. 2026-05-19 not yet calculat=
    ed CVE-2026-8726 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8726 ] https= ://typo3.org/security/advisory/typo3-ext-sa-2026-010
    =C2=A0 TYPO3--Extension "Site Crawler" The Crawler extension passes the X-T= 3Crawler-Meta response header from crawled URLs directly to PHP's unseriali= ze(). An attacker controlling a crawled endpoint can inject arbitrary seria= lized PHP objects, leading to Remote Code Execution on the TYPO3 server. Ex= ploitation requires administrative privileges to configure a crawler-enable=
    d page and trigger the crawl via a Scheduler task. 2026-05-19 not yet calcu= lated CVE-2026-8727 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8727 ] ht= tps://typo3.org/security/advisory/typo3-ext-sa-2026-008
    =C2=A0 Unknown--Ajax Load More The Ajax Load More WordPress plugin before 7= .8.4 does not sanitise and escape a parameter before outputting it back in = the page, leading to a Reflected Cross-Site Scripting which could be used a= gainst high privilege users such as admin 2026-05-18 not yet calculated CVE= -2026-6495 [ https://www.cve.org/CVERecord?id=3DCVE-2026-6495 ] https://wps= can.com/vulnerability/c52f28c5-547d-48ae-89dd-edcdaeadcec5/
    =C2=A0 Unknown--Autoptimize The Autoptimize WordPress plugin before 3.1.15,=
    Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plu= gin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Script= ing (XSS) due to a predictable replacement hash used during the HTML minifi= cation process and abusing a regular expression. This allows an attacker to=
    inject arbitrary HTML attributes in the final HTML output by anticipating = the placeholder format. 2026-05-18 not yet calculated CVE-2026-3220 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-3220 ] https://wpscan.com/vulnerabil= ity/3ceabf11-23cd-4c38-ba14-014348b0ff2d/
    =C2=A0 Unknown--Decent Comments The Decent Comments WordPress plugin before=
    3.0.2 does not restrict access to comment author email addresses and post = author email addresses via its REST API endpoint, allowing unauthenticated = attackers to enumerate registered user email addresses. 2026-05-20 not yet = calculated CVE-2026-7385 [ https://www.cve.org/CVERecord?id=3DCVE-2026-7385=
    ] https://wpscan.com/vulnerability/1c5949d0-cf50-45d3-a7e2-2f94cdb42405/ =C2=A0 Unknown--Email Encoder The Email Encoder WordPress plugin before 2.4=
    .7 does not escape email addresses retrieved via user input, allowing unaut= henticated attackers to perform Stored XSS attacks 2026-05-20 not yet calcu= lated CVE-2026-5776 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5776 ] ht= tps://wpscan.com/vulnerability/00c0b9f7-c559-463e-80ae-97d99e0ef99f/
    =C2=A0 Unknown--Feeds for YouTube (YouTube video, channel, and gallery plug= in) The Feeds for YouTube (YouTube video, channel, and gallery plugin) Word= Press plugin before 2.6.4 is vulnerable to unauthorized modification of the=
    Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress p= lugin before 2.6.4's license key due to a missing capability check on the '= actions' function. This makes it possible for subscribers and above delete = the license key. 2026-05-18 not yet calculated CVE-2026-1631 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-1631 ] https://wpscan.com/vulnerability/b19= 596c2-69bc-4e15-8632-eb80f4577e3c/
    =C2=A0 Unknown--Fortis for WooCommerce The Fortis for WooCommerce WordPress=
    plugin before 1.3.1 may leak sensitive API keys to unauthenticated attacke= rs, allowing them to query Fortis' API and retrieve sensitive customer info= rmation, like past orders, PII, etc. 2026-05-19 not yet calculated CVE-2025= -15609 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15609 ] https://wpscan= .com/vulnerability/220f72ea-e3b4-44c9-8c9b-15662aebb6cb/
    =C2=A0 Unknown--WP Maps The WP Maps WordPress plugin before 4.9.3 does not = properly sanitize a parameter before using it in a file path, allowing auth= enticated users to perform Local File Inclusion attacks. 2026-05-18 not yet=
    calculated CVE-2026-6381 [ https://www.cve.org/CVERecord?id=3DCVE-2026-638=
    1 ] https://wpscan.com/vulnerability/18b36672-58d7-44fa-b653-b728e9ef257a/ =C2=A0 Unknown--WP Photo Album Plus The WP Photo Album Plus WordPress plugi=
    n before 9.1.11.001 does not properly sanitize and escape a parameter befor=
    e using it in a SQL query, allowing unauthenticated users to perform SQL in= jection attacks. 2026-05-18 not yet calculated CVE-2026-6379 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-6379 ] https://wpscan.com/vulnerability/60b= 88fd2-4048-4773-b319-63caaf5bd8eb/
    =C2=A0 vaadin--flow A possible information disclosure vulnerability exists =
    in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full s=
    et of environment variables in build logs whenever the frontend build proce=
    ss exits with a non-zero status. Because the build environment may contain = credentials supplied as secrets, any failed frontend build can expose those=
    secrets in clear text in CI logs and archived build artifacts. Users of af= fected versions should apply the following mitigation or upgrade. Releases = that have fixed this issue include: Product version Vaadin 23.0.0 - 23.6.9 = Vaadin 24.0.0 - 24.9.16 Vaadin 24.10.0 - 24.10.3 Vaadin 25.0.0 - 25.0.10 Va= adin 25.1.0 - 25.1.4 Mitigation Upgrade to 23.6.10 Upgrade to 24.9.17 or ne= wer Upgrade to 24.10.4 or newer Upgrade to 25.0.11 or newer Upgrade to 25.1=
    .5 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer = supported and you should update either to the latest 23, 24, or 25 version.=
    ArtifactsMaven coordinatesVulnerable versionsFixed versioncom.vaadin:flow-= plugin-base23.0.0 - 23.6.10=C3=A2=E2=80=B0=C2=A523.6.11com.vaadin:flow-plug= in-base24.0.0 - 24.9.17=C3=A2=E2=80=B0=C2=A524.9.18com.vaadin:flow-plugin-b= ase24.10.0 - 24.10.3=C3=A2=E2=80=B0=C2=A524.10.4com.vaadin:flow-plugin-base= 25.0.0 - 25.0.11=C3=A2=E2=80=B0=C2=A525.0.12com.vaadin:flow-plugin-base25.1=
    .0 - 25.1.4=C3=A2=E2=80=B0=C2=A525.1.5com.vaadin:flow-maven-plugin23.0.0 - = 23.6.10=C3=A2=E2=80=B0=C2=A523.6.11com.vaadin:flow-maven-plugin24.0.0 - 24.= 9.17=C3=A2=E2=80=B0=C2=A524.9.18com.vaadin:flow-maven-plugin24.10.0 - 24.10= .3=C3=A2=E2=80=B0=C2=A524.10.4com.vaadin:flow-maven-plugin25.0.0 - 25.0.11= =C3=A2=E2=80=B0=C2=A525.0.12com.vaadin:flow-maven-plugin25.1.0 - 25.1.4=C3= =A2=E2=80=B0=C2=A525.1.5com.vaadin:flow-gradle-plugin24.0.0 - 24.9.17=C3=A2= =E2=80=B0=C2=A524.9.18com.vaadin:flow-gradle-plugin24.10.0 - 24.10.3=C3=A2= =E2=80=B0=C2=A524.10.4com.vaadin:flow-gradle-plugin25.0.0 - 25.0.11=C3=A2= =E2=80=B0=C2=A525.0.12com.vaadin:flow-gradle-plugin25.1.0 - 25.1.4=C3=A2=E2= =80=B0=C2=A525.1.5 2026-05-19 not yet calculated CVE-2026-7860 [ https://ww= w.cve.org/CVERecord?id=3DCVE-2026-7860 ] https://vaadin.com/security/cve-20= 26-7860
    https://github.com/vaadin/flow/pull/24219
    =C2=A0 vifm--vifm vifm is vulnerable to a heap buffer overflow during the h= istory merge process when saving the state file (vifminfo.json). This flaw = occurs because the application lacks a runtime check on the length of histo=
    ry entries in release builds, potentially allowing a crafted long path or c= ommand in the history to cause memory corruption or application crashes. Re= leases from 0.12.1 to=C2=A00.14.3 (including) are considered vulnerable. Th=
    is issue was fixed in commit 23063c7 2026-05-22 not yet calculated CVE-2026= -8997 [ https://www.cve.org/CVERecord?id=3DCVE-2026-8997 ] https://cert.pl/= en/posts/2026/05/CVE-2026-8997 https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5b779f6910d =C2=A0 WineHQ--Wine Wine ships a .desktop file that registers itself as a M= IME handler for EXE files and several other Windows executable file types. =
    In some configurations, handling of an EXE file causes that file to be blin= dly executed with the permissions of the invoker. This allows escaping Flat= pak and Snap sandboxes, because MIME handlers are not intended for use by c= ode interpreters and loaders. NOTE: some parties feel that this is not a bu=
    g to be addressed in Wine, because there is no known solution that avoids a=
    severe loss of usability (Wine could be a binfmt-misc handler, but binfmt-= misc does not exist on all platforms supported by Wine). 2026-05-24 not yet=
    calculated CVE-2026-48831 [ https://www.cve.org/CVERecord?id=3DCVE-2026-48= 831 ] https://bugs.winehq.org/show_bug.cgi?id=3D59767 https://www.openwall.com/lists/oss-security/2026/05/19/1
    =C2=A0 Xen--Xen Any guest can cause xenstored to crash by issuing a XS_RESE= T_WATCHES command within a transaction due to an assert() triggering. In ca=
    se xenstored was built with NDEBUG #defined nothing bad will happen, as ass= ert() is doing nothing in this case. Note that the default is not to define=
    NDEBUG for xenstored builds even in release builds of Xen. 2026-05-19 not = yet calculated CVE-2026-23557 [ https://www.cve.org/CVERecord?id=3DCVE-2026= -23557 ] https://xenbits.xenproject.org/xsa/advisory-484.html
    =C2=A0 Xen--Xen The adjustments made for XSA-379 as well as those subsequen= tly becoming XSA-387 still left a race window, when a HVM or PVH guest does=
    a grant table version change from v2 to v1 in parallel with mapping the st= atus page(s) via XENMEM_add_to_physmap. Some of the status pages may then b=
    e freed while mappings of them would still be inserted into the guest's sec= ondary (P2M) page tables. 2026-05-19 not yet calculated CVE-2026-23558 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-23558 ] https://xenbits.xenprojec= t.org/xsa/advisory-486.html
    =C2=A0 xwiki--xwiki-commons XWiki Platform is a generic wiki platform. Vers= ions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to re=
    ad configuration files by using URLs such as http://localhost:8080/bin/ssx/= Main/WebHome?resource=3D/../../WEB-INF/xwiki.cfg&minify=3Dfalse, leading to=
    Path Traversal. The vulnerability is can be exploited via resources parame= ter the ssx and jsx endpoints by using leading slashes. This issue has been=
    patched in 18.1.0-rc-1, 17.10.3, 17.4.9, 16.10.17. 2026-05-20 not yet calc= ulated CVE-2026-23734 [ https://www.cve.org/CVERecord?id=3DCVE-2026-23734 ]=
    https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-xq3r-2qv5-= vqqm https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d6= 72df64429bf
    https://jira.xwiki.org/browse/XCOMMONS-3547
    =C2=A0 xwiki--xwiki-platform XWiki Platform is a generic wiki platform offe= ring runtime services for applications built on top of it. XWiki Platform i=
    s a generic wiki platform. In versions prior to 18.1.0-rc-1, 17.10.3, 17.4.=
    9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import witho=
    ut performing any authentication or authorization checks, allowing an unaut= henticated attacker to create or update documents in the target wiki. This = vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 a=
    nd 18.1.0-rc-1. 2026-05-20 not yet calculated CVE-2026-33137 [ https://www.= cve.org/CVERecord?id=3DCVE-2026-33137 ] https://github.com/xwiki/xwiki-plat= form/security/advisories/GHSA-qrvh-r3f2-9h4r https://github.com/xwiki/xwiki-platform/commit/4b7b95b79256374d487e9ece1dc4= 8f527966990f
    https://jira.xwiki.org/browse/XWIKI-23953
    =C2=A0 Zenshin--hitarth-gg An OS command injection vulnerability in the /st= ream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote = attackers to execute arbitrary commands via the url parameter. 2026-05-19 n=
    ot yet calculated CVE-2026-37281 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-37281 ] https://github.com/hitarth-gg/zenshin https://github.com/hitarth-gg/zenshin/commit/7d31c6edfbac978f0ad44c66d761ba= b9dcd2fa27
    https://gist.github.com/MitruStefan/cf016709252aabbec7f95b7a70e0cfba
    =C2=A0 zephyrproject-rtos--Zephyr A bitwise shift vulnerability in Zephyr's=
    PTP subsystem allows a remote attacker to cause undefined behavior and pot= ential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT messa=
    ge to set an unvalidated negative log_announce_interval value in the port's=
    data set. When a subsequent PTP_MSG_ANNOUNCE message is processed, port_ti= mer_set_timeout_random computes a timeout as NSEC_PER_SEC >> -log_seconds; =
    if the attacker-supplied value is sufficiently negative (e.g., -127), the s= hift amount exceeds the 64-bit integer width, triggering undefined behavior=
    in C. This can cause a system crash via a compiler-generated illegal instr= uction trap on some architectures, or produce an erroneous zero timeout lea= ding to resource starvation loops or other logical errors. 2026-05-22 not y=
    et calculated CVE-2026-5072 [ https://www.cve.org/CVERecord?id=3DCVE-2026-5= 072 ] https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA= -3v98-458v-388r
    =C2=A0 =C2=A0LalanaChami--Pharmacy Management System API endpoints in Lalan= aChami Pharmacy Management System (commit 5c3d028) lack authentication midd= leware. Unauthenticated remote attackers can exploit this to dump all user = records (including bcrypt password hashes) via /api/user/getUserData, modif=
    y drug inventory, and access private medical prescription data via /api/doc= torOder. 2026-05-19 not yet calculated CVE-2026-31071 [ https://www.cve.org= /CVERecord?id=3DCVE-2026-31071 ] https://github.com/LalanaChami/Pharmacy-Ma= ngment-System/tree/5c3d02888631166649856f71d542387114b3010b/backend/routes https://gist.github.com/nedlir/bc8ad4693c53256819280e8f5de49286
    =C2=A0 =C2=A0Panabit--PAP-XM320 A command injection vulnerability exists in=
    Panabit PAP-XM320 up to and including V7.7. The web management interface i= nvokes the backend helper /usr/sbin/pappiw and passes user-controlled param= eters to it. The helper performs unsafe argument processing using eval, whi=
    ch allows command injection when attacker-controlled input is included in t=
    he arguments. As a result, an authenticated remote attacker with access to = the management interface may execute arbitrary shell commands. 2026-05-19 n=
    ot yet calculated CVE-2026-36827 [ https://www.cve.org/CVERecord?id=3DCVE-2= 026-36827 ] https://www.panabit.com/ https://secreu.notion.site/CVE-2026-36827-3652c0ab46158036a888ef4a12b104bf =C2=A0 =C2=A0Panabit--PAP-XM320 A command injection vulnerability exists in=
    the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includ= ing v7.7. The CGI component allows authenticated users to execute arbitrary=
    shell commands with root privileges via the action=3Druncmd parameter. 202= 6-05-19 not yet calculated CVE-2026-36828 [ https://www.cve.org/CVERecord?i= d=3DCVE-2026-36828 ] https://www.panabit.com/ https://secreu.notion.site/CVE-2026-36828-3652c0ab461580f28f50ddc37ce4e1d6 =C2=A0 =C2=A0Panabit--PAP-XM320 An authentication bypass vulnerability exis=
    ts in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.=
    7. The server validates session cookies using a filesystem existence check = based on a user-controlled cookie value without proper sanitization, allowi=
    ng directory traversal and bypass of authentication. 2026-05-19 not yet cal= culated CVE-2026-36829 [ https://www.cve.org/CVERecord?id=3DCVE-2026-36829 =
    ] https://www.panabit.com/ https://secreu.notion.site/CVE-2026-36829-3652c0ab461580e19704e87b18865714 =C2=A0 =C2=A0Uncrustify-- Uncrustify Buffer Overflow vulnerability in Uncru= stify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in com= mit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cau=
    se a denial of service via the check_template.cpp, check_template function,=
    tokenize_cleanup function, uncrustify executable components 2026-05-21 not=
    yet calculated CVE-2026-36189 [ https://www.cve.org/CVERecord?id=3DCVE-202= 6-36189 ] https://github.com/uncrustify/uncrustify%2Chttps://github.com/unc= rustify/uncrustify/issues/4636%2C https://github.com/uncrustify/uncrustify/pull/4641 https://gist.github.com/Criticayon/5da6d6c9cf068e494347c659d01982a9
    =C2=A0=20

    Back to top [ #top ]

    body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
    : normal; font-style: normal; color: #333333; }=20

    Having trouble viewing this message?=C2=A0View it as a webpage [ https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/4190013 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]

    You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [ https://www.cisa.gov ] (CISA)
    Manage Subscriptions [ https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [ https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]

    Connect with CISA:=20
    Facebook [ https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [ https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [ https://Instagram.com/cisag=
    ov ]=C2=A0 |=C2=A0 LinkedIn [ https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]

    ________________________________________________________________________

    This email was sent to cisa@toolazy.synchro.net using GovDelivery Communica= tions Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency=
    =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ = https://subscriberhelp.granicus.com/ ]=20
    body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
    y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}

    --===============5510240496706666731==
    Content-Type: text/html; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns=3D"http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
    <title> Vulnerability Summary for the Week of May 18, 2026
    </title>


    </head>
    <body style=3D"">

    <table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
    align=3D"center">
    <tr>
    <td>

    <!--[if (gte mso 9)|(IE)]>
    <table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
    <![endif]-->
    <a name=3D"gd_top" id=3D"gd_top"></a>

    =20



    <p><img src=3D"https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
    <p>You are subscribed to Vulnerability Bulletins for Cybersecurity and In= frastructure Security Agency. This information has recently been updated an=
    d is now available.</p>
    <p>The CISA Vulnerability Bulletin provides a summary of new vulnerabilitie=
    s that have been recorded in the past week. In some cases, the vulnerabilit= ies in the bulletin may not yet have assigned CVSS scores.</p> <p>Vulnerabilities are based on the=C2=A0<a href=3D"https://www.cve.org/" t= arget=3D"_blank" class=3D"ext" data-extlink=3D"" rel=3D"noopener">Common Vu= lnerabilities and Exposures</a>=C2=A0(CVE) vulnerability naming standard an=
    d are organized according to severity, determined by the=C2=A0<a href=3D"ht= tps://www.cve.org/about/relatedefforts" target=3D"_blank" rel=3D"noopener">= Common Vulnerability Scoring System</a>=C2=A0(CVSS) standard. The division =
    of high, medium, and low severities correspond to the following scores:</p>


    <strong>High</strong>: vulnerabilities with a CVSS base score of 7.0=E2=80= =9310.0</li>

    <strong>Medium</strong>: vulnerabilities with a CVSS base score of 4.0=E2= =80=936.9</li>

    <strong>Low</strong>: vulnerabilities with a CVSS base score of 0.0=E2=80= =933.9</li>
    </ul>
    <p>Entries may include additional information provided by organizations and=
    efforts sponsored by CISA. This information may include identifying inform= ation, values, definitions, and related links. Patch information is provide=
    d when available. Please note that some of the information in the bulletin =
    is compiled from external, open-source reports and is not a direct result o=
    f CISA analysis.</p>
    <div class=3D"rss_item" style=3D"margin-bottom: 2em;">
    <div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
    n: 0 0 0.3em; padding: 0;"><a href=3D"https://www.cisa.gov/news-events/bull= etins/sb26-145" target=3D"_blank" title=3D"Vulnerability Summary for the We=
    ek of May 18, 2026" rel=3D"noopener">Vulnerability Summary for the Week of = May 18, 2026</a></div>
    <div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">05/26/2026 12:15 PM EDT</div> <div class=3D"rss_description" style=3D"margin: 0 0 0.3em; padding: 0;">
    <div id=3D"high_v">
    <h2 id=3D"high_v_title">High Vulnerabilities</h2>
    <table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"High Vulnerabilities">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">10-Strike--Network Inventory Explorer</td> <td>10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer=
    overflow vulnerability in the registration key input field that allows loc=
    al attackers to execute arbitrary code by triggering a structured exception=
    handler overwrite. Attackers can craft a malicious registration key string=
    with 4188 bytes of padding followed by SEH chain values and shellcode, the=
    n paste it into the registration dialog to achieve code execution with appl= ication privileges.</td>
    <td>2026-05-23</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25344" target=3D= "_blank" rel=3D"noopener">CVE-2018-25344</a></td>
    </tr>

    <td class=3D"vendor-product">10-Strike--Network Scanner</td>
    <td>10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerab= ility in the host name field that allows attackers to bypass SafeSEH protec= tions and execute arbitrary code. Attackers can craft a malicious payload i=
    n the host name or address field and trigger the vulnerability through the = Trace route or System information functions to achieve code execution.</td> <td>2026-05-23</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25345" target=3D= "_blank" rel=3D"noopener">CVE-2018-25345</a></td>
    </tr>

    <td class=3D"vendor-product">10Web--Form Maker</td>
    <td>WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vu= lnerabilities that allow authenticated attackers to manipulate database que= ries by injecting SQL code through the FormMakerSQLMapping and generete_csv=
    actions. Attackers can submit POST requests with malicious SQL payloads in=
    the name and search_labels parameters to extract, modify, or escalate priv= ileges within the WordPress database.</td>
    <td>2026-05-23</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25346" target=3D= "_blank" rel=3D"noopener">CVE-2018-25346</a></td>
    </tr>

    <td class=3D"vendor-product">acyba--AcyMailing An Ultimate Newsletter Plugi=
    n and Marketing Automation Solution for WordPress</td>
    <td>The AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation=
    Solution for WordPress plugin for WordPress is vulnerable to Missing Autho= rization in versions up to, and including, 10.8.2. This is due to the plugi=
    n not properly verifying that a user is authorized to perform an action. Th=
    is makes it possible for authenticated attackers, with subscriber-level acc= ess and above, to modify privileged AcyMailing configuration, export subscr= iber secret keys, and chain these actions into administrator account takeov=
    er when a target administrator email address is known.</td>
    <td>2026-05-20</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5200" target=3D"= _blank" rel=3D"noopener">CVE-2026-5200</a></td>
    </tr>

    <td class=3D"vendor-product">Alinto--SOGo Webmail</td>
    <td>SOGo versions 5.12.7 and prior contains a SQL injection vulnerability i=
    n the Access Control List management functionality that allows authenticate=
    d users to extract arbitrary data from the database by injecting SQL subque= ries through the uid parameter of the addUserInAcls endpoint. Attackers can=
    inject malicious SQL code to write extracted data into the sogo_acl table = and retrieve it through the /acls API, establishing an out-of-band data exf= iltration channel.</td>
    <td>2026-05-18</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8851" target=3D"= _blank" rel=3D"noopener">CVE-2026-8851</a></td>
    </tr>

    <td class=3D"vendor-product">Audiograbber--Audiograbber</td>
    <td>Audiograbber 1.83 contains a local buffer overflow vulnerability that a= llows attackers to execute arbitrary code by exploiting structured exceptio=
    n handling mechanisms. Attackers can craft malicious input in the Interpret=
    or Album fields that triggers a buffer overflow, overwriting SEH pointers = and executing injected shellcode with application privileges.</td> <td>2026-05-23</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25355" target=3D= "_blank" rel=3D"noopener">CVE-2018-25355</a></td>
    </tr>

    <td class=3D"vendor-product">AWS--Amazon Braket Python SDK</td>
    <td>Insecure deserialization in the job results processing component in Ama= zon Braket SDK before=C2=A01.117.0 might allow a remote authenticated user = with S3 write access to the job output bucket to achieve arbitrary code exe= cution on any machine that processes job results. We recommend you upgrade =
    to amazon-braket-sdk version 1.117.0 or later.</td>
    <td>2026-05-22</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9291" target=3D"= _blank" rel=3D"noopener">CVE-2026-9291</a></td>
    </tr>

    <td class=3D"vendor-product">AWS--Amazon Redshift connector for Python</td> <td>Unsafe use of Python's eval() on server-received data in the vector_in(=
    ) function in amazon-redshift-python-driver before 2.1.14 allows a rogue se= rver or man-in-the-middle actor to execute arbitrary code on the client. To=
    remediate this issue, users should upgrade to version 2.1.14.</td> <td>2026-05-18</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8838" target=3D"= _blank" rel=3D"noopener">CVE-2026-8838</a></td>
    </tr>

    <td class=3D"vendor-product">AWS--Kiro CLI</td>
    <td>Missing input source validation in the tool authorization prompt in Kir=
    o CLI before 1.28.0 allows a local attacker to execute arbitrary tools, inc= luding shell commands, without user approval by crafting content that is pi= ped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version = 1.28.0 or later.</td>
    <td>2026-05-22</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9255" target=3D"= _blank" rel=3D"noopener">CVE-2026-9255</a></td>
    </tr>

    <td class=3D"vendor-product">AWS--RabbitMQ AWS</td>
    <td>Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws = before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by t=
    he PUT /api/aws/arn/validate validation endpoint might allow remote authent= icated users to perform arbitrary file reads on any file accessible to the = RabbitMQ process. To remediate this issue, customers should upgrade to vers= ion 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connect= ions, we also recommend rotating any associated private certificate keys.</=

    <td>2026-05-20</td>
    <td>7.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9133" target=3D"= _blank" rel=3D"noopener">CVE-2026-9133</a></td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the pr= eview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) a= llows unauthenticated users to achieve Server-Side Request Forgery (SSRF) b=
    y supplying a custom typebot definition with server-side code blocks. The f= etch function exposed inside the isolated-vm sandbox calls Node.js native f= etch without the SSRF validation (validateHttpReqUrl) that protects the HTT=
    P Request block. This bypasses all SSRF mitigations added after GHSA-8gq9-r= w7v-3jpr. Exploitation of this unauthenticated SSRF vulnerability can lead =
    to cloud credential theft, internal network access and data exfiltration fo=
    r any self-hosted Typebot deployments and hosted services. This issue has b= een fixed in version 3.16.0.</td>
    <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33712" target=3D= "_blank" rel=3D"noopener">CVE-2026-33712</a></td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the Ra= tingButton component in the embed package renders the user-controlled custo= mIcon.svg field directly via Solid's innerHTML directive without any saniti= zation, even though DOMPurify is already a dependency and is used elsewhere=
    in the codebase (e.g., StreamingBubble.tsx). Because rating blocks are not=
    flagged as isUnsafe by the import sanitizer and the builder preview render=
    s bots inline on the builder's own origin (builder.typebot.io) under a CSP = permitting 'unsafe-inline', a malicious imported or collaborator-crafted ty= pebot can execute arbitrary HTML/JS in the builder's authenticated context,=
    bypassing the Web Worker sandbox that protects Script blocks during previe=
    w. This allows session hijacking and privilege escalation within the builde=
    r application. This issue has been fixed in version 3.16.0.</td> <td>2026-05-22</td>
    <td>8.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28445" target=3D= "_blank" rel=3D"noopener">CVE-2026-28445</a></td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF pr= otection for Webhook / HTTP Request blocks validates only the URL string, b= locked hostname literals, and literal IP formats. It does not resolve DNS b= efore allowing the request. As a result, a hostname such as ssrf-repro.exam= ple that resolves to 127.0.0.1, 169.254.169.254, or RFC1918/private space p= asses validation and is later fetched by the backend HTTP client. This enab= les server-side request forgery to loopback, cloud metadata, and private ne= twork targets. This issue has been resolved in version 3.16.0.</td> <td>2026-05-22</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34207" target=3D= "_blank" rel=3D"noopener">CVE-2026-34207</a></td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an=
    SSRF via Open Redirect Bypass as the HTTP Request block and Code block val= idate the initial request URL via validateHttpReqUrl() to block private IPs=
    and cloud metadata hostnames. However, the HTTP clients (ky and fetch) fol= low 302 redirects without re-validating the redirect destination. An authen= ticated user can point a bot block to an attacker-controlled server that re= sponds with a redirect to an internal IP, causing the Typebot server to rea=
    ch internal services. An authenticated Typebot user can reach AWS metadata = (169.254.169.254), private subnets, and container-internal services. Exploi= table to extract cloud IAM credentials or probe internal APIs inaccessible = from the internet. This issue has been fixed in version 3.16.0.</td> <td>2026-05-22</td>
    <td>7.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39965" target=3D= "_blank" rel=3D"noopener">CVE-2026-39965</a></td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fi=
    x for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Executi=
    on and API Authorization Bypass") is incomplete. While the builder's getCre= dentials tRPC endpoint was patched with workspace membership checks, the bo= t-engine runtime still allows any authenticated user to use credentials fro=
    m any workspace via the preview chat endpoint. The bot-engine's getCredenti= als() utility function uses a falsy check (if (workspaceId &amp;&amp; ...))=
    for workspace ownership validation. Since the preview endpoint accepts a c= lient-controlled workspaceId field and the Zod schema allows empty strings,=
    an attacker can supply workspaceId: "" to bypass credential ownership veri= fication entirely. Exploitation can result in credential exfiltration, exte= rnal service abuse, financial damage and a data breach.</td> <td>2026-05-22</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39968" target=3D= "_blank" rel=3D"noopener">CVE-2026-39968</a></td>
    </tr>

    <td class=3D"vendor-product">Basamak Information Technology Consulting and = Organization Trade Ltd. Co.--DernekWeb</td>
    <td>Improper neutralization of input during web page generation ('cross-sit=
    e scripting') vulnerability in Basamak Information Technology Consulting an=
    d Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue affec=
    ts DernekWeb: through 30122025.</td>
    <td>2026-05-18</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7498" target=3D"= _blank" rel=3D"noopener">CVE-2026-7498</a></td>
    </tr>

    <td class=3D"vendor-product">Behance--Smartshop</td>
    <td>Smartshop 1 contains a SQL injection vulnerability that allows unauthen= ticated attackers to execute arbitrary SQL queries by injecting malicious c= ode through the id parameter. Attackers can send GET requests to category.p=
    hp with UNION-based SQL injection payloads in the id parameter to extract s= ensitive database information including usernames and other data.</td> <td>2026-05-23</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25340" target=3D= "_blank" rel=3D"noopener">CVE-2018-25340</a></td>
    </tr>

    <td class=3D"vendor-product">Behance--Smartshop</td>
    <td>Smartshop 1 contains a SQL injection vulnerability that allows unauthen= ticated attackers to execute arbitrary SQL queries by injecting malicious c= ode through the id parameter. Attackers can send GET requests to product.ph=
    p with union-based SQL injection payloads in the id parameter to extract se= nsitive database information including usernames and database names.</td> <td>2026-05-23</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25341" target=3D= "_blank" rel=3D"noopener">CVE-2018-25341</a></td>
    </tr>

    <td class=3D"vendor-product">Behance--Smartshop</td>
    <td>Smartshop 1 contains a time-based blind SQL injection vulnerability tha=
    t allows unauthenticated attackers to manipulate database queries by inject= ing SQL code through the 'searched' parameter in search.php. Attackers can = send GET requests with malicious SQL payloads like SLEEP commands to extrac=
    t sensitive database information including product details and system data.= </td>
    <td>2026-05-23</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25342" target=3D= "_blank" rel=3D"noopener">CVE-2018-25342</a></td>
    </tr>

    <td class=3D"vendor-product">BerriAI--litellm</td>
    <td>LiteLLM prior to 1.83.14 allows an authenticated internal_user to creat=
    e API keys with access to routes that their role does not permit. When gene= rating a key, the allowed_routes field is stored without verifying that the=
    specified routes fall within the user's own permissions. A key created wit=
    h access to admin-only routes can then be used to reach those routes succes= sfully, bypassing the role-based access controls that would otherwise block=
    the request, enabling full privilege escalation from internal_user to prox= y_admin.</td>
    <td>2026-05-21</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47101" target=3D= "_blank" rel=3D"noopener">CVE-2026-47101</a></td>
    </tr>

    <td class=3D"vendor-product">BerriAI--litellm</td>
    <td>LiteLLM prior to 1.83.10 allows a user to modify their own user_role vi=
    a the /user/update endpoint. While the endpoint correctly restricts users t=
    o updating only their own account, it does not restrict which fields may be=
    changed. A user who can reach this endpoint can set their role to proxy_ad= min, gaining full administrative access to LiteLLM including all users, tea= ms, keys, models, and prompt history. Users with the org_admin role have le= gitimate access to this endpoint and can exploit this vulnerability without=
    chaining any additional flaw.</td>
    <td>2026-05-21</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47102" target=3D= "_blank" rel=3D"noopener">CVE-2026-47102</a></td>
    </tr>

    <td class=3D"vendor-product">Besen--BS20 EV Charging Station</td>
    <td>A weakness has been identified in Besen BS20 EV Charging Station up to = 20260426. Affected by this issue is some unknown functionality of the compo= nent OTA Update Installation Handler. This manipulation causes improper aut= horization. The attack is possible to be carried out remotely. A high degre=
    e of complexity is needed for the attack. The exploitation is known to be d= ifficult. The original disclosure mentions, that "[t]hese vulnerabilities h= ave been reported to Besen and we have received their acknowlegement that t= hey are reviewing this as of April 2026."</td>
    <td>2026-05-24</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9397" target=3D"= _blank" rel=3D"noopener">CVE-2026-9397</a></td>
    </tr>

    <td class=3D"vendor-product">bestpractical--rt</td>
    <td>RT is an open source, enterprise-grade issue and ticket tracking system=
    . Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injec= tion vulnerability. An authenticated user can craft input that is incorpora= ted into database queries without proper validation, potentially allowing t= hem to read or modify data in the RT database. This issue has been fixed in=
    versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately=
    , they can temporarily work around this issue by restricting RT account acc= ess to trusted users.</td>
    <td>2026-05-22</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41075" target=3D= "_blank" rel=3D"noopener">CVE-2026-41075</a></td>
    </tr>

    <td class=3D"vendor-product">bestpractical--rt</td>
    <td>RT is an open source, enterprise-grade issue and ticket tracking system=
    . Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an au= thentication bypass vulnerability in RT installations that use LDAP/AD for = user authentication. Under certain LDAP server configurations, an attacker = may be able to authenticate as any LDAP-backed RT user without supplying va= lid credentials. This issue has been fixed in versions 5.0.10 and 6.0.3. If=
    developers are unable to upgrade immediately, they can temporarily work ar= ound this issue by reviewing their LDAP server's authentication policy to e= nsure it rejects unauthenticated bind attempts. Upgrading RT remains the re= commended fix.</td>
    <td>2026-05-22</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41076" target=3D= "_blank" rel=3D"noopener">CVE-2026-41076</a></td>
    </tr>

    <td class=3D"vendor-product">bestpractical--rt</td>
    <td>RT is an open source, enterprise-grade issue and ticket tracking system=
    . Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) = vulnerability. An attacker who can induce a logged-in RT user to visit a ma= licious web page can trigger arbitrary state-changing actions in RT on that=
    user's behalf. This issue has been fixed in version 6.0.3.</td> <td>2026-05-22</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41074" target=3D= "_blank" rel=3D"noopener">CVE-2026-41074</a></td>
    </tr>

    <td class=3D"vendor-product">Beyaz Computer Software Design Industry and Tr= ade Ltd. Co.--CityPLus</td>
    <td>Improper neutralization of input during web page generation ('cross-sit=
    e scripting') vulnerability in Beyaz Computer Software Design Industry and = Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects CityPLus: = before V24.29750.1.0.</td>
    <td>2026-05-20</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5783" target=3D"= _blank" rel=3D"noopener">CVE-2026-5783</a></td>
    </tr>

    <td class=3D"vendor-product">beycanpress--Account Switcher</td>
    <td>The Account Switcher plugin for WordPress is vulnerable to Privilege Es= calation in all versions up to, and including, 1.0.2. This is due to the `r= ememberLogin` REST API endpoint using a loose comparison (`!=3D` instead of=
    `!=3D=3D`) for secret validation at `app/RestAPI.php:111`, combined with n=
    o validation that the secret is non-empty. When a target user has never use=
    d the "Remember me" feature, their `asSecret` user meta does not exist, cau= sing `get_user_meta()` to return an empty string. An attacker can send an e= mpty `secret` parameter, which passes the comparison (`'' !=3D ''` is `fals= e`), and the endpoint then calls `wp_set_auth_cookie()` for the target user=
    . Additionally, all REST routes use `permission_callback =3D&gt; '__return_= true'` with no capability checks. This makes it possible for authenticated = attackers, with Subscriber-level access and above, to switch to any user ac= count including Administrator, ultimately granting themselves full administ= rative privileges.</td>
    <td>2026-05-20</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6456" target=3D"= _blank" rel=3D"noopener">CVE-2026-6456</a></td>
    </tr>

    <td class=3D"vendor-product">Cisco--Cisco Secure Workload</td>
    <td>A vulnerability in the&amp;nbsp;access validation of internal REST APIs=
    of Cisco Secure Workload could allow an unauthenticated, remote attacker t=
    o access site resources with the privileges of the&amp;nbsp;Site Admin role=
    . This vulnerability is due to insufficient validation and authentication w= hen accessing REST API endpoints. An attacker could exploit this vulnerabil= ity if they are able to send a crafted API request to an affected endpoint.=
    A successful exploit could allow the attacker to read sensitive informatio=
    n and make configuration changes across tenant boundaries with the privileg=
    es of the&amp;nbsp;Site Admin user.&amp;nbsp;</td>
    <td>2026-05-20</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20223" target=3D= "_blank" rel=3D"noopener">CVE-2026-20223</a></td>
    </tr>

    <td class=3D"vendor-product">ConnectWise--Automate</td>
    <td>The ConnectWise Automate=C3=A2=E2=80=9E=C2=A2 Agent does not fully veri=
    fy the authenticity of components obtained during plugin loading and self-u= pdate operations. This issue is addressed in Automate 2026.5.</td> <td>2026-05-21</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9089" target=3D"= _blank" rel=3D"noopener">CVE-2026-9089</a></td>
    </tr>

    <td class=3D"vendor-product">constantcontact--Creative Mail Easier WordPres=
    s &amp; WooCommerce Email Marketing</td>
    <td>The Creative Mail - Easier WordPress &amp; WooCommerce Email Marketing = plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid'=
    parameter in all versions up to, and including, 1.6.9. This is due to insu= fficient escaping on the user supplied parameter and lack of sufficient pre= paration on the existing SQL query in the `has_checkout_consent()` method. = This makes it possible for unauthenticated attackers to append additional S=
    QL queries into already existing queries that can be used to extract sensit= ive information from the database.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3985" target=3D"= _blank" rel=3D"noopener">CVE-2026-3985</a></td>
    </tr>

    <td class=3D"vendor-product">contest-gallery--Contest Gallery Upload &amp; = Vote Photos, Media, Sell with PayPal &amp; Stripe</td>
    <td>The Contest Gallery plugin for WordPress is vulnerable to SQL Injection=
    via the 'form_input' parameter in versions up to, and including, 28.1.6. T= his is due to insufficient escaping on the user supplied parameter and lack=
    of sufficient preparation on the existing SQL query inside the unauthentic= ated 'post_cg_gallery_form_upload' AJAX action (specifically the 'cb' branc=
    h of the included users-upload-check.php, where $f_input_id is concatenated=
    unquoted into 'SELECT Field_Content FROM ... WHERE id =3D $f_input_id'). T=
    he endpoint is gated only by a public frontend nonce ('cg1l_action' / 'cg_n= once') that is exposed in the page source of any public gallery page. This = makes it possible for unauthenticated attackers to append additional SQL qu= eries into already existing queries that can be used to extract sensitive i= nformation from the database.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8912" target=3D"= _blank" rel=3D"noopener">CVE-2026-8912</a></td>
    </tr>

    <td class=3D"vendor-product">cssigniterteam--AudioIgniter Music Player</td> <td>The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct = Object Reference in versions up to, and including, 2.0.2. This is due to th=
    e handle_playlist_endpoint() function (hooked to template_redirect) accepti=
    ng a user-controlled playlist ID via the audioigniter_playlist_id query var=
    or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist tr= ack data without performing any authentication, capability, or post_status = check - only the post_type is validated. This makes it possible for unauthe= nticated attackers to view track metadata (titles, artists, audio URLs, buy=
    links, download URLs, and cover images) of any playlist on the site, inclu= ding those in draft, private, pending, or trash status.</td> <td>2026-05-22</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8679" target=3D"= _blank" rel=3D"noopener">CVE-2026-8679</a></td>
    </tr>

    <td class=3D"vendor-product">Ctrlpanel-gg--panel</td>
    <td>CtrlPanel is open-source billing software for hosting providers. In ver= sions 1.1.1 and prior, the web-based installer (public/installer/index.php)=
    is vulnerable to unauthenticated Remote Code Execution (RCE) because it pe= rforms the install.lock check only after including and executing form handl=
    er files, leaving installer endpoints reachable on already-installed instan= ces. The handlers also pass unsanitized user input directly into shell comm= ands, allowing an attacker to submit crafted requests that execute arbitrar=
    y commands on the server. The vulnerability stems from two combined weaknes= ses: (1) premature form handler execution before the lock file gate, and (2=
    ) unsafe use of user input in shell command construction. This issue is rep= orted to be actively exploited in the wild. The issue has been fixed in ver= sion 1.2.0.</td>
    <td>2026-05-19</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34234" target=3D= "_blank" rel=3D"noopener">CVE-2026-34234</a></td>
    </tr>

    <td class=3D"vendor-product">Ctrlpanel-gg--panel</td>
    <td>CtrlPanel is open-source billing software for hosting providers. Versio=
    ns 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerabilit=
    y in the ticket reply notification system. Unsanitized reply content ($newm= essage) is stored directly in database notification payloads and later rend= ered unescaped via Blade's {!! !!} syntax in the recipient's browser. The f= law exists in both App\Notifications\Ticket\Admin\AdminReplyNotification (t= riggered when a user replies, targeting admins) and App\Notifications\Ticke= t\User\ReplyNotification (triggered when an admin replies, targeting users)=
    , allowing arbitrary JavaScript execution in the victim's session context. =
    A low-privileged attacker can exploit this to hijack admin sessions, harves=
    t credentials via fake login prompts or keyloggers, and escalate privileges=
    by performing administrative actions on the victim's behalf. The reverse p= ath also enables a malicious or compromised admin to target regular users i=
    n the same manner. This issue has been fixed in version 1.2.0.</td> <td>2026-05-19</td>
    <td>8.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34241" target=3D= "_blank" rel=3D"noopener">CVE-2026-34241</a></td>
    </tr>

    <td class=3D"vendor-product">Ctrlpanel-gg--panel</td>
    <td>CtrlPanel is open-source billing software for hosting providers. Versio=
    ns 1.1.1 and prior contains a broken access control vulnerability where mul= tiple admin controllers enforce permission checks on form display methods b=
    ut omit equivalent checks on the corresponding write methods, allowing any = authenticated user to bypass RBAC via direct POST/PATCH requests. Controlle=
    rs missing checks on write methods store() and update() include Application= ApiController (admin.api.write), CouponController (admin.coupons.write), Pa= rtnerController (admin.partners.write), ShopProductController (admin.store.= write), UsefulLinkController (admin.useful_links.write), and VoucherControl= ler (admin.voucher.write); ProductController (admin.products.edit), ServerC= ontroller (write/change_owner/change_identifier), and UserController (write= /change_email/change_credits/change_username/change_password/change_role/ch= ange_referral/change_ptero/change_serverlimit) are missing checks on update=
    () only, and ActivityLogController exposed empty stub store()/update() meth= ods that silently accepted any request. An authenticated attacker without a= dmin write privileges can issue API credentials, generate unlimited coupons=
    and vouchers, assign arbitrary partner commission and discount rates, alte=
    r shop product pricing and limits, reassign server ownership or identifiers=
    , and modify user accounts including roles, credits, passwords, and linked = Pterodactyl IDs to achieve full privilege escalation, as well as abuse logB= ackIn() without the login_as permission to interfere with admin impersonati=
    on sessions. This issue has been fixed in version 1.2.0.</td> <td>2026-05-19</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34358" target=3D= "_blank" rel=3D"noopener">CVE-2026-34358</a></td>
    </tr>

    <td class=3D"vendor-product">D-Link--DIR-601</td>
    <td>D-Link DIR601 2.02NA contains a credential disclosure vulnerability tha=
    t allows unauthenticated attackers to retrieve sensitive configuration data=
    by manipulating the table_name parameter in POST requests. Attackers can s= end requests to /my_cgi.cgi with table_name values like admin_user, wireles= s_settings, and wireless_security to extract administrative credentials and=
    wireless network keys in clear text.</td>
    <td>2026-05-23</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25358" target=3D= "_blank" rel=3D"noopener">CVE-2018-25358</a></td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) an Exposure=
    of Information Through Directory Listing vulnerability. An unauthenticated=
    attacker with remote access could potentially exploit this vulnerability, = leading to Information exposure.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32750" target=3D= "_blank" rel=3D"noopener">CVE-2025-32750</a></td>
    </tr>

    <td class=3D"vendor-product">Digital Operations Services Inc.--WifiBurada</=

    <td>Exposure of private personal information to an unauthorized actor, Insu= fficiently Protected Credentials vulnerability in Digital Operations Servic=
    es Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBur= ada: through 21052026.=C2=A0NOTE: The vendor was contacted early about this=
    disclosure but did not respond in any way.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-13477" target=3D= "_blank" rel=3D"noopener">CVE-2025-13477</a></td>
    </tr>

    <td class=3D"vendor-product">Divi Engine--Divi Form Builder</td>
    <td>The Divi Form Builder plugin for WordPress is vulnerable to privilege e= scalation in versions up to, and including, 5.1.2. This is due to the plugi=
    n accepting a user-controlled 'role' parameter from POST data during user r= egistration without validating it against the form's configured default_use= r_role setting. This makes it possible for unauthenticated attackers to cre= ate administrator accounts by tampering with the role parameter during regi= stration.</td>
    <td>2026-05-21</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5118" target=3D"= _blank" rel=3D"noopener">CVE-2026-5118</a></td>
    </tr>

    <td class=3D"vendor-product">Docker--Docker Desktop</td>
    <td>The vllm-metal inference backend in Docker Model Runner on macOS uncond= itionally sets trust_remote_code=3DTrue when loading model tokenizers, and = runs without sandboxing. This causes transformers.AutoTokenizer.from_pretra= ined() to import and execute arbitrary Python files included in any model p= ulled from an OCI registry, resulting in arbitrary code execution on the Do= cker host as the Docker Desktop user when inference is triggered. Any conta= iner on the Docker network can trigger this by calling the model-runner.doc= ker.internal API to pull a malicious model and request inference.</td> <td>2026-05-22</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5817" target=3D"= _blank" rel=3D"noopener">CVE-2026-5817</a></td>
    </tr>

    <td class=3D"vendor-product">Docker--Docker Desktop</td>
    <td>The MLX inference backend in Docker Model Runner on macOS uses the MLX-=
    LM library, which unconditionally imports and executes arbitrary Python fil=
    es from model directories via the model_file configuration field in config.= json. When a model's config.json specifies a model_file pointing to a Pytho=
    n file, MLX-LM uses importlib to load and execute it with no trust_remote_c= ode gate or equivalent safety check. The MLX backend runs without sandboxin=
    g, resulting in arbitrary code execution on the Docker host as the Docker D= esktop user. Any container on the Docker network can trigger this by callin=
    g the model-runner.docker.internal API to pull a malicious model from an at= tacker-controlled OCI registry and request inference.</td>
    <td>2026-05-22</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5843" target=3D"= _blank" rel=3D"noopener">CVE-2026-5843</a></td>
    </tr>

    <td class=3D"vendor-product">Docker--Docker Desktop</td>
    <td>The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolat= ion (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socke=
    t mounts from containers are denied unless explicitly allowed via the admin= -settings configuration. However, the --use-api-socket flag adds the Docker=
    socket mount via the HostConfig.Mounts field rather than the HostConfig.Bi= nds field. The ECI enforcement in the Docker Desktop API proxy only inspect=
    ed Binds, allowing the mount to pass unchecked. This grants a container ful=
    l access to the Docker Engine socket and, if the host user has logged in to=
    container registries, their authentication credentials. A local attacker w= ith the ability to run Docker CLI commands can exploit this to escape ECI r= estrictions, access the Docker Engine, and potentially escalate privileges.= </td>
    <td>2026-05-22</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6406" target=3D"= _blank" rel=3D"noopener">CVE-2026-6406</a></td>
    </tr>

    <td class=3D"vendor-product">Dokploy--dokploy</td>
    <td>Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions=
    0.26.6 and below have OS command injection through the appName parameter. =
    3 chained issues cause this problem: inadequate input sanitization, lack of=
    schema validation and direct shell interpolation. User-controlled applicat= ion names are passed through inadequate sanitization (cleanAppName function=
    only replaces spaces and converts to lowercase) before being interpolated = directly into shell commands executed via execAsync() and execAsyncRemote()=
    . An authenticated attacker can inject shell metacharacters (e.g., ;, $(), = backticks, |, &amp;) in the appName field during application creation, whic=
    h are then executed with server-level privileges when service operations (s= tart, stop, remove, scale) are triggered. This issue has been resolved in v= ersion 0.26.7.</td>
    <td>2026-05-18</td>
    <td>9.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27130" target=3D= "_blank" rel=3D"noopener">CVE-2026-27130</a></td>
    </tr>

    <td class=3D"vendor-product">Dolibarr--Dolibarr ERP CRM</td>
    <td>Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability t= hat allows unauthenticated attackers to execute arbitrary code by injecting=
    PHP code through the db_name parameter. Attackers can send a POST request =
    to install/step1.php with malicious PHP code in the db_name parameter, then=
    execute commands via the check.php endpoint using the cmd GET parameter.</=

    <td>2026-05-23</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25357" target=3D= "_blank" rel=3D"noopener">CVE-2018-25357</a></td>
    </tr>

    <td class=3D"vendor-product">Drupal--Drupal core</td>
    <td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
    L Injection') vulnerability in Drupal Drupal core allows SQL Injection. Thi=
    s issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before = 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0=
    before 11.2.12, from 11.3.0 before 11.3.10.</td>
    <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9082" target=3D"= _blank" rel=3D"noopener">CVE-2026-9082</a></td>
    </tr>

    <td class=3D"vendor-product">DumbWareio--DumbAssets</td>
    <td>DumbAssets through 1.0.11 contains a path traversal vulnerability in th=
    e POST /api/delete-file endpoint and filesToDelete array parameters that al= lows unauthenticated attackers to delete arbitrary files by supplying ../ s= equences that bypass directory boundary validation. Attackers can exploit t=
    he optional and disabled-by-default authentication control to traverse outs= ide the intended application directory and delete critical files such as se= rver.js or package.json, causing complete denial of service.</td> <td>2026-05-18</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45230" target=3D= "_blank" rel=3D"noopener">CVE-2026-45230</a></td>
    </tr>

    <td class=3D"vendor-product">Eclipse Foundation--Eclipse Glassfish</td>
    <td>An authenticated Remote Code Execution (RCE) vulnerability was identifi=
    ed in GlassFish's Administration Console. A user with access to the panel c=
    an send crafted requests that allow the execution of arbitrary operating sy= stem commands with the privileges of the application service user.</td> <td>2026-05-19</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2586" target=3D"= _blank" rel=3D"noopener">CVE-2026-2586</a></td>
    </tr>

    <td class=3D"vendor-product">Eclipse Foundation--Eclipse Glassfish</td>
    <td>A critical Remote Code Execution (RCE) vulnerability was identified in = the server-side template rendering mechanism used by the Glassfish gadget h= andler. The application processes .xml files and evaluates user-supplied va= lues within a context where Expression Language (EL) "expressions" are proc= essed without proper sanitization or escaping. By injecting expressions suc=
    h as #{7*7}, the server returns 49, confirming server-side EL evaluation. T= his issue allows a remote attacker to fully compromise the underlying host,=
    enabling capabilities as reading/modifying data, executing arbitrary comma= nds, persistence, and lateral movement.</td>
    <td>2026-05-19</td>
    <td>9.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2587" target=3D"= _blank" rel=3D"noopener">CVE-2026-2587</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A flaw has been found in Edimax BR-6428NS 1.10. This affects the functi=
    on formL2TPSetup of the file /goform/formL2TPSetup of the component POST Re= quest Handler. This manipulation of the argument L2TPUserName causes buffer=
    overflow. It is possible to initiate the attack remotely. The exploit has = been published and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way.</td>
    <td>2026-05-18</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8775" target=3D"= _blank" rel=3D"noopener">CVE-2026-8775</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerabi= lity affects the function formPPTPSetup of the file /goform/formPPTPSetup o=
    f the component POST Request Handler. Such manipulation of the argument ppt= pUserName leads to buffer overflow. It is possible to launch the attack rem= otely. The exploit has been disclosed to the public and may be used. The ve= ndor was contacted early about this disclosure but did not respond in any w= ay.</td>
    <td>2026-05-18</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8776" target=3D"= _blank" rel=3D"noopener">CVE-2026-8776</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted e= lement is the function formWanTcpipSetup of the file /goform/formWanTcpipSe= tup of the component POST Request Handler. Such manipulation of the argumen=
    t pppUserName leads to buffer overflow. It is possible to launch the attack=
    remotely. The exploit is publicly available and might be used. The vendor = was contacted early about this disclosure but did not respond in any way.</=

    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9294" target=3D"= _blank" rel=3D"noopener">CVE-2026-9294</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A security flaw has been discovered in Edimax BR-6428NS 1.10. This affe= cts the function formWirelessTbl of the file /goform/formWirelessTbl of the=
    component POST Request Handler. Performing a manipulation of the argument = vapurl results in buffer overflow. The attack can be initiated remotely. Th=
    e exploit has been released to the public and may be used for attacks. The = vendor was contacted early about this disclosure but did not respond in any=
    way.</td>
    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9295" target=3D"= _blank" rel=3D"noopener">CVE-2026-9295</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A security vulnerability has been detected in Edimax BR-6675nD 1.12. Af= fected is the function formL2TPSetup of the file /goform/formL2TPSetup of t=
    he component POST Request Handler. Such manipulation of the argument L2TPUs= erName leads to buffer overflow. The attack can be launched remotely. The e= xploit has been disclosed publicly and may be used. The vendor was contacte=
    d early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9380" target=3D"= _blank" rel=3D"noopener">CVE-2026-9380</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this=
    vulnerability is the function formPPPoESetup of the file /goform/formPPPoE= Setup of the component POST Request Handler. Performing a manipulation of t=
    he argument pppUserName results in buffer overflow. The attack may be initi= ated remotely. The exploit is now public and may be used. The vendor was co= ntacted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9381" target=3D"= _blank" rel=3D"noopener">CVE-2026-9381</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue =
    is the function formPPTPSetup of the file /goform/formPPTPSetup of the comp= onent POST Request Handler. Executing a manipulation of the argument pptpUs= erName can lead to buffer overflow. The attack may be launched remotely. Th=
    e exploit has been published and may be used. The vendor was contacted earl=
    y about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9382" target=3D"= _blank" rel=3D"noopener">CVE-2026-9382</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerabili=
    ty affects the function formsetPPPoE of the file /goform/formsetPPPoE of th=
    e component POST Request Handler. Performing a manipulation of the argument=
    pppUserName results in buffer overflow. It is possible to initiate the att= ack remotely. The exploit is now public and may be used. The vendor was con= tacted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9399" target=3D"= _blank" rel=3D"noopener">CVE-2026-9399</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is th=
    e function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the c= omponent POST Request Handler. The manipulation of the argument pppUserName=
    leads to buffer overflow. The attack can be initiated remotely. The exploi=
    t has been disclosed to the public and may be used. The vendor was contacte=
    d early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9401" target=3D"= _blank" rel=3D"noopener">CVE-2026-9401</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted e= lement is the function formWlSiteSurvey of the file /goform/formWlSiteSurve=
    y of the component POST Request Handler. This manipulation of the argument = selSSID causes buffer overflow. The attack may be initiated remotely. The e= xploit has been publicly disclosed and may be utilized. The vendor was cont= acted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9403" target=3D"= _blank" rel=3D"noopener">CVE-2026-9403</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A security vulnerability has been detected in Edimax EW-7438RPn up to 1= .31. The impacted element is an unknown function of the file /goform/formWp= sStart of the component webs. Such manipulation of the argument pinCode/wla= n-url leads to stack-based buffer overflow. The attack can be executed remo= tely. The exploit has been disclosed publicly and may be used. The vendor w=
    as contacted early about this disclosure but did not respond in any way.</t=

    <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9344" target=3D"= _blank" rel=3D"noopener">CVE-2026-9344</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affe= cts the function formWizSurvey of the file /goform/formWizSurvey of the com= ponent webs. Performing a manipulation of the argument ssid/manualssid/ip/m= ask/gateway results in buffer overflow. The attack is possible to be carrie=
    d out remotely. The exploit is now public and may be used. The vendor was c= ontacted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9345" target=3D"= _blank" rel=3D"noopener">CVE-2026-9345</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the=
    function formWirelessTbl of the file /goform/formWirelessTbl of the compon= ent webs. Executing a manipulation of the argument submit-url can lead to b= uffer overflow. The attack may be performed from remote. The exploit has be=
    en published and may be used. The vendor was contacted early about this dis= closure but did not respond in any way.</td>
    <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9346" target=3D"= _blank" rel=3D"noopener">CVE-2026-9346</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by = this vulnerability is an unknown functionality of the file /goform/mp of th=
    e component webs. The manipulation of the argument webs results in stack-ba= sed buffer overflow. It is possible to launch the attack remotely. The expl= oit has been made public and could be used. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
    <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9348" target=3D"= _blank" rel=3D"noopener">CVE-2026-9348</a></td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affecte=
    d by this issue is the function formwlencrypt24g of the file /goform/formwl= encrypt24g of the component POST Request Handler. The manipulation of the a= rgument key1 results in buffer overflow. The attack can be launched remotel=
    y. The exploit has been released to the public and may be used for attacks.=
    The vendor was contacted early about this disclosure but did not respond i=
    n any way.</td>
    <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9360" target=3D"= _blank" rel=3D"noopener">CVE-2026-9360</a></td>
    </tr>

    <td class=3D"vendor-product">edmonparker--Read More &amp; Accordion</td> <td>The Read More &amp; Accordion plugin for WordPress is vulnerable to Pri= vilege Escalation in all versions up to, and including, 3.5.7. This is due =
    to the 'RadMoreAjax::importData' function not restricting which database ta= bles can be written to during import and not properly validating the import=
    ed data. This makes it possible for authenticated attackers, with permissio=
    n granted by the site owner through the plugin's role settings, to insert a= rbitrary rows into the 'wp_users' and 'wp_usermeta' tables, including the '= wp_capabilities' field, allowing them to create a new administrator account=
    and gain administrator access to the site.</td>
    <td>2026-05-20</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7467" target=3D"= _blank" rel=3D"noopener">CVE-2026-7467</a></td>
    </tr>

    <td class=3D"vendor-product">F5--NGINX JavaScript</td>
    <td>NGINX JavaScript has a vulnerability when the js_fetch_proxy=C2=A0direc= tive is configured with at least one client-controlled NGINX variable (for = example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch(=
    ) operation from NGINX JavaScript. An unauthenticated attacker can exploit = this vulnerability by sending crafted HTTP requests. This may cause a heap = buffer overflow in the NGINX worker process leading to a restart. Additiona= lly, attackers can execute code on systems with Address Space Layout Random= ization (ASLR) disabled or when the attacker can bypass ASLR. Note: Softwar=
    e versions which have reached End of Technical Support (EoTS) are not evalu= ated.</td>
    <td>2026-05-19</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8711" target=3D"= _blank" rel=3D"noopener">CVE-2026-8711</a></td>
    </tr>

    <td class=3D"vendor-product">F5--NGINX Plus</td>
    <td>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_r= ewrite_module module. This vulnerability exists when a rewrite directive us=
    es a regex pattern with distinct, overlapping Perl-Compatible Regular Expre= ssion (PCRE) captures (for example, ^/((.*))$) and a replacement string tha=
    t references multiple such captures (for example, $1$2) in a redirect or ar= guments context. An unauthenticated attacker along with conditions beyond t= heir control can exploit this vulnerability by sending crafted HTTP request=
    s. This may cause a heap buffer overflow in the NGINX worker process leadin=
    g to a restart. Additionally, attackers can execute code on systems with Ad= dress Space Layout Randomization (ASLR) disabled or when the attacker can b= ypass ASLR. Note: Software versions which have reached End of Technical Sup= port (EoTS) are not evaluated.</td>
    <td>2026-05-22</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9256" target=3D"= _blank" rel=3D"noopener">CVE-2026-9256</a></td>
    </tr>

    <td class=3D"vendor-product">FunnelKit--Funnel Builder for WooCommerce Chec= kout</td>
    <td>Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a mi= ssing authorization vulnerability in the public checkout endpoint that allo=
    ws unauthenticated attackers to invoke internal methods and write arbitrary=
    data to the plugin's External Scripts global setting. Attackers can inject=
    malicious JavaScript through the External Scripts setting that executes in=
    the browsers of all checkout page visitors.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47100" target=3D= "_blank" rel=3D"noopener">CVE-2026-47100</a></td>
    </tr>

    <td class=3D"vendor-product">Gmission--Web Fax</td>
    <td>Improper input validation, Unrestricted upload of file with dangerous t= ype vulnerability in Gmission Web Fax allows Remote Code Inclusion. This is= sue affects Web Fax: from 3.0 before 3.1.</td>
    <td>2026-05-21</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9157" target=3D"= _blank" rel=3D"noopener">CVE-2026-9157</a></td>
    </tr>

    <td class=3D"vendor-product">GNU--GNU SASL</td>
    <td>In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference aff= ecting both clients and servers, via a known token with no accompanying =3D=
    character. This occurs in lib/digest-md5/getsubopt.c.</td>
    <td>2026-05-24</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48829" target=3D= "_blank" rel=3D"noopener">CVE-2026-48829</a></td>
    </tr>

    <td class=3D"vendor-product">goauthentik--authentik</td>
    <td>authentik is an open-source identity provider. Versions 2025.12.4 and p= rior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authent= ication Bypass through SAML NameID XML Comment Injection. Due to how authen= tik extracted the NameID value from a SAML assertion, it was possible for a=
    n attacker to trick authentik into only seeing a part of the NameID value, = potentially allowing an attacker to gain access to other accounts. This iss=
    ue could be exploited on an authentik instance with a SAML Source, where th=
    e attacker had an account on the SAML Source and the ability to modify thei=
    r NameID value (commonly username or E-mail), and XML Signing was enabled. = The attacker could modify the SAML assertion given to authentik by injectin=
    g a comment within the NameID value, which effectively truncated the NameID=
    value to the snippet before the comment, and gave the attacker access to a=
    ny user account. This issue has been fixed in versions 2025.12.5 and 2026.2= .3.</td>
    <td>2026-05-20</td>
    <td>8.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40165" target=3D= "_blank" rel=3D"noopener">CVE-2026-40165</a></td>
    </tr>

    <td class=3D"vendor-product">goauthentik--authentik</td>
    <td>authentik is an open-source identity provider. In versions prior to 202= 5.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}=
    / API allows a caller with change_user on a target user to assign arbitrary=
    groups through UserSerializer, including groups with is_superuser=3DTrue, = without requiring enable_group_superuser, leading to privilege escalation. = This bypasses the stricter permission model enforced in group-management pa= ths and enables delegated user-management permissions to escalate target us= ers to administrator-equivalent privilege. Users with permissions to update=
    groups or permissions to update users are able to add themselves or other = users they have permissions on to users which have superuser permissions. T= his issue has been fixed in versions 22025.12.5 and 2026.2.3.</td> <td>2026-05-22</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40172" target=3D= "_blank" rel=3D"noopener">CVE-2026-40172</a></td>
    </tr>

    <td class=3D"vendor-product">H3C--Magic B0</td>
    <td>A vulnerability was found in H3C Magic B0 up to 100R002. This affects t=
    he function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a man= ipulation of the argument param results in buffer overflow. The attack may =
    be initiated remotely. The exploit has been made public and could be used. = The vendor was contacted early about this disclosure but did not respond in=
    any way.</td>
    <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9393" target=3D"= _blank" rel=3D"noopener">CVE-2026-9393</a></td>
    </tr>

    <td class=3D"vendor-product">harmistechnology--Ek Rishta</td>
    <td>Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerabilit=
    y that allows unauthenticated attackers to manipulate database queries by i= njecting SQL code through the cid parameter. Attackers can send GET request=
    s to the user_detail view with malicious cid values containing SQL commands=
    to extract sensitive database information.</td>
    <td>2026-05-23</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25348" target=3D= "_blank" rel=3D"noopener">CVE-2018-25348</a></td>
    </tr>

    <td class=3D"vendor-product">harmistechnology--EkRishta</td>
    <td>Joomla! Component EkRishta 2.10 contains an error-based SQL injection v= ulnerability that allows unauthenticated attackers to execute arbitrary SQL=
    queries by injecting malicious code into the username parameter. Attackers=
    can submit POST requests to the login endpoint with SQL injection payloads=
    in the username field to extract database information including user crede= ntials and system details.</td>
    <td>2026-05-23</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25351" target=3D= "_blank" rel=3D"noopener">CVE-2018-25351</a></td>
    </tr>

    <td class=3D"vendor-product">hestiacp--hestiacp</td>
    <td>HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnera= bility in the web terminal component caused by a session format mismatch be= tween PHP and Node.js that allows unauthenticated remote attackers to achie=
    ve root-level code execution. Attackers can inject crafted data into HTTP h= eaders that are processed by the PHP session handler but incorrectly deseri= alized by the Node.js web terminal component as trusted session values, res= ulting in arbitrary command execution on systems with the web terminal feat= ure enabled.</td>
    <td>2026-05-19</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43633" target=3D= "_blank" rel=3D"noopener">CVE-2026-43633</a></td>
    </tr>

    <td class=3D"vendor-product">hestiacp--hestiacp</td>
    <td>HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerabil= ity that allows unauthenticated remote attackers to bypass authentication s= ecurity controls by supplying an arbitrary IP address in the CF-Connecting-=
    IP HTTP header without verifying the request originated from Cloudflare's n= etwork. Attackers can exploit this to circumvent fail2ban brute-force prote= ction, bypass per-user IP allowlists, and poison authentication audit logs =
    by spoofing trusted IP addresses on each request.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43634" target=3D= "_blank" rel=3D"noopener">CVE-2026-43634</a></td>
    </tr>

    <td class=3D"vendor-product">Honeywell International Inc.--Control Network = Module (CNM)</td>
    <td>Honeywell Control Network Module (CNM)=C2=A0contains command injection = vulnerability in the web interface. An attacker could exploit this vulnerab= ility via command delimiters, potentially resulting in Remote Code Executio=
    n (RCE).</td>
    <td>2026-05-21</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5433" target=3D"= _blank" rel=3D"noopener">CVE-2026-5433</a></td>
    </tr>

    <td class=3D"vendor-product">iina--iina</td>
    <td>IINA before 1.4.3 contains a user-assisted command execution vulnerabil= ity that allows remote attackers to execute arbitrary commands by supplying=
    malicious mpv_-prefixed query parameters through the iina://open custom UR=
    L scheme handler. Attackers can deliver a crafted URL via a browser that pa= sses unvalidated mpv_options/input-commands parameters into the mpv runtime=
    , causing arbitrary command execution as the current macOS user upon approv=
    al of the browser protocol prompt without requiring a valid media file.</td=

    <td>2026-05-21</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47114" target=3D= "_blank" rel=3D"noopener">CVE-2026-47114</a></td>
    </tr>

    <td class=3D"vendor-product">ISC--BIND 9</td>
    <td>BIND servers that are configured to use TKEY-based authentication via G= SS-API tokens are vulnerable to excessive memory consumption when receiving=
    and processing maliciously-constructed packets. Typically these servers wi=
    ll be found in Active Directory integrated DNS deployments and/or Kerberos-= secured DNS environments. This issue affects BIND 9 versions 9.0.0 through = 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.2= 1.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.= 9-S1 through 9.20.22-S1.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3039" target=3D"= _blank" rel=3D"noopener">CVE-2026-3039</a></td>
    </tr>

    <td class=3D"vendor-product">ISC--BIND 9</td>
    <td>A use-after-free vulnerability exists within the DNS-over-HTTPS impleme= ntation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 = through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 t= hrough 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.</td> <td>2026-05-20</td>
    <td>7.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3593" target=3D"= _blank" rel=3D"noopener">CVE-2026-3593</a></td>
    </tr>

    <td class=3D"vendor-product">ISC--BIND 9</td>
    <td>Multiple flaws have been identified in `named` related to the handling =
    of DNS messages whose CLASS is not Internet (`IN`) - for example, `CHAOS` o=
    r `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in = the question section. Specially crafted requests reaching the affected code=
    paths - recursion, dynamic updates (`UPDATE`), zone change notifications (= `NOTIFY`), or processing of `IN`-specific record types in non-`IN` data - c=
    an cause assertion failures in `named`. This issue affects BIND 9 versions = 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.2= 1.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.= 48-S1, and 9.20.9-S1 through 9.20.22-S1.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5946" target=3D"= _blank" rel=3D"noopener">CVE-2026-5946</a></td>
    </tr>

    <td class=3D"vendor-product">ISC--BIND 9</td>
    <td>Undefined behavior may result due to a race condition leading to a use-= after-free violation. If BIND receives an incoming DNS message signed with = SIG(0), it begins work to validate that signature. If, during that validati= on, the "recursive-clients" limit is reached (as would occur during a query=
    flood), and that same DNS message is discarded per the limit, there is a b= rief window of time while the SIG(0) validation may attempt to read the now= -discarded DNS message. This issue affects BIND 9 versions 9.20.0 through 9= .20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 ve= rsions 9.18.28 through 9.18.49 and 9.18.28-S1 through 9.18.49-S1 are NOT af= fected.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5947" target=3D"= _blank" rel=3D"noopener">CVE-2026-5947</a></td>
    </tr>

    <td class=3D"vendor-product">itsourcecode--Electronic Judging System</td>
    <td>A vulnerability has been found in itsourcecode Electronic Judging Syste=
    m 1.0. This affects an unknown part of the file /intrams/admin/login.php. T=
    he manipulation of the argument Username leads to sql injection. Remote exp= loitation of the attack is possible. The exploit has been disclosed to the = public and may be used.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9383" target=3D"= _blank" rel=3D"noopener">CVE-2026-9383</a></td>
    </tr>

    <td class=3D"vendor-product">ItzCrazyKns--Vane</td>
    <td>A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerabil= ity affects unknown code of the file src/app/api/providers/route.ts of the = component Model Provider API. This manipulation of the argument baseURL cau= ses server-side request forgery. Remote exploitation of the attack is possi= ble. The exploit has been published and may be used. The project was inform=
    ed of the problem early through an issue report but has not responded yet.<=

    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9372" target=3D"= _blank" rel=3D"noopener">CVE-2026-9372</a></td>
    </tr>

    <td class=3D"vendor-product">ivanti--Secure Access Client</td>
    <td>An improper certificate validation vulnerability in Ivanti Secure Acces=
    s Client before 22.8R6 allows a remote unauthenticated attacker to execute = arbitrary code.</td>
    <td>2026-05-22</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8992" target=3D"= _blank" rel=3D"noopener">CVE-2026-8992</a></td>
    </tr>

    <td class=3D"vendor-product">jarrodwatts--claude-hud</td>
    <td>Claude HUD through 0.0.12, patched in commit 234d9aa, contains a comman=
    d injection vulnerability that allows local attackers to execute arbitrary = commands by manipulating the COMSPEC environment variable. Attackers can se=
    t COMSPEC to an arbitrary binary path before claude-hud performs its versio=
    n check, causing execFile() to execute the attacker-supplied executable wit=
    h cmd.exe arguments, resulting in arbitrary code execution on Windows syste= ms.</td>
    <td>2026-05-18</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47092" target=3D= "_blank" rel=3D"noopener">CVE-2026-47092</a></td>
    </tr>

    <td class=3D"vendor-product">kovidgoyal--kitty</td>
    <td>Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and be= low, the handle_compose_command() function in kitty/graphics.c performs bou= nds validation on composition offsets using unsigned 32-bit arithmetic that=
    is subject to integer wrapping, potentially leading to Heap Buffer Over-Re= ad/Write. An attacker who can write escape sequences to a kitty terminal (e= .g., via a malicious file, SSH login banner, or piped content) can supply c= rafted x_offset/y_offset values that pass the bounds check after wrapping b=
    ut cause massive out-of-bounds heap memory access in compose_rectangles(). =
    No user interaction is required. No non-default configuration is required. = The attacker only needs the ability to produce output in a kitty terminal w= indow. This issue has been fixed in version 0.47.0.</td>
    <td>2026-05-19</td>
    <td>9.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33642" target=3D= "_blank" rel=3D"noopener">CVE-2026-33642</a></td>
    </tr>

    <td class=3D"vendor-product">kovidgoyal--kitty</td>
    <td>Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below=
    contain a heap buffer overflow in load_image_data() that allows any proces=
    s which can write to the terminal's stdin to crash kitty immediately. The v= ulnerability is triggered by a single APC graphics protocol command with a = PNG format declaration (f=3D100) whose payload exceeds twice the initial bu= ffer capacity. The overflow is attacker-controlled in both length and conte= nt, causing DoS and potentially escalation to RCE itself. This issue has be=
    en fixed in version 0.47.0.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33633" target=3D= "_blank" rel=3D"noopener">CVE-2026-33633</a></td>
    </tr>

    <td class=3D"vendor-product">langgenius--dify</td>
    <td>Dify version 1.14.1 and prior contains an authorization bypass vulnerab= ility that allows authenticated editor users to set and enable trace config= urations for any application regardless of tenant ownership. Attackers can = exploit missing tenant ownership checks in the trace configuration endpoint=
    s to redirect all messages and responses from victim applications to attack= er-controlled LLM trace providers. NOTE: Dify Cloud allows unauthenticated = free self-registration, making account creation trivially accessible to any=
    attacker.</td>
    <td>2026-05-18</td>
    <td>7.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41947" target=3D= "_blank" rel=3D"noopener">CVE-2026-41947</a></td>
    </tr>

    <td class=3D"vendor-product">langgenius--dify</td>
    <td>Dify version 1.14.1 and prior contain a path traversal vulnerability th=
    at allows authenticated users to manipulate requests forwarded to the Plugi=
    n Daemon's internal REST API by exploiting insufficient URL path sanitizati= on. Attackers can traverse out of their authorized tenant path using unenco= ded dot sequences in task identifiers or manipulated filename parameters to=
    access internal endpoints such as debug interfaces, requiring only knowled=
    ge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated fre=
    e self-registration, making account creation trivially accessible to any at= tacker.</td>
    <td>2026-05-18</td>
    <td>7.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41948" target=3D= "_blank" rel=3D"noopener">CVE-2026-41948</a></td>
    </tr>

    <td class=3D"vendor-product">laurent22--joplin</td>
    <td>Joplin is an open source note-taking and to-do application that organis=
    es notes and lists into notebooks. Versions prior to 3.5.7 contain a path t= raversal vulnerability in the importer which allows overwriting arbitrary f= iles on disk. The OneNote converter does not sanitize the names of embedded=
    files before writing them to disk. As a result, it's possible for an attac= ker to create a malicious .one file that includes file names containing ../= ../, that are then interpreted as part of the target path when extracting a= ttachments from the .one file. This issue has been patched in version 3.5.7= .</td>
    <td>2026-05-18</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22810" target=3D= "_blank" rel=3D"noopener">CVE-2026-22810</a></td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can=
    return EBUSY. Handle them by checking for that value and filtering out EIN= PROGRESS notifications.</td>
    <td>2026-05-19</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43493" target=3D= "_blank" rel=3D"noopener">CVE-2026-43493</a></td>
    </tr>

    <td class=3D"vendor-product">LizardByte--Sunshine</td>
    <td>Sunshine is a self-hosted game stream host for Moonlight. In versions p= rior to 2026.516.143833, the client-certificate authentication can be bypas= sed because of how OpenSSL verification results are handled. In src/crypto.= cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT= _LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as=
    success. This can allow an untrusted certificate to pass authentication an=
    d access protected HTTPS endpoints. This issue has been fixed in version 20= 26.516.143833.</td>
    <td>2026-05-22</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32253" target=3D= "_blank" rel=3D"noopener">CVE-2026-32253</a></td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to check integration URL fo=
    r path traversal which allows an malicious authenticated user to call an ar= bitrary API via system admin Mattermost auth token using via path traversal=
    in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640</td> <td>2026-05-21</td>
    <td>8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4858" target=3D"= _blank" rel=3D"noopener">CVE-2026-4858</a></td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to sanitize sensitive configuration fields before = including them in support packet generation, which allows a Mattermost Syst=
    em Admin or any party with access to a support packet to obtain sensitive c= redentials in plaintext via downloading a support packet from the System Co= nsole.. Mattermost Advisory ID: MMSA-2026-00607</td>
    <td>2026-05-18</td>
    <td>8.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6346" target=3D"= _blank" rel=3D"noopener">CVE-2026-6346</a></td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to properly validate msgpac= k-encoded WebSocket frames before memory allocation which allows an unauthe= nticated remote attacker to crash the server process and cause a full servi=
    ce outage for all users via a crafted binary WebSocket message sent to the = public WebSocket endpoint.. Mattermost Advisory ID: MMSA-2026-00647</td> <td>2026-05-22</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5740" target=3D"= _blank" rel=3D"noopener">CVE-2026-5740</a></td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to sanitize sensitive configuration fields in the = Mattermost Calls plugin which allows an attacker with access to a support p= acket to obtain TURN server credentials via the plaintext values present in=
    the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-0060= 5</td>
    <td>2026-05-18</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6347" target=3D"= _blank" rel=3D"noopener">CVE-2026-6347</a></td>
    </tr>

    <td class=3D"vendor-product">MediaArea--MediaInfoLib</td>
    <td>MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vul= nerability</td>
    <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22554" target=3D= "_blank" rel=3D"noopener">CVE-2026-22554</a></td>
    </tr>

    <td class=3D"vendor-product">MediaArea--MediaInfoLib</td>
    <td>MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow v= ulnerability</td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28764" target=3D= "_blank" rel=3D"noopener">CVE-2026-28764</a></td>
    </tr>

    <td class=3D"vendor-product">memcached--memcached</td>
    <td>In memcached before 1.6.42, username data for SASL password database au= thentication has a timing side channel because a loop exits as soon as a va= lid username is found by sasl_server_userdb_checkpass.</td>
    <td>2026-05-20</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47783" target=3D= "_blank" rel=3D"noopener">CVE-2026-47783</a></td>
    </tr>

    <td class=3D"vendor-product">memcached--memcached</td>
    <td>In memcached before 1.6.42, password data for SASL password database au= thentication has a timing side channel because memcmp is used by sasl_serve= r_userdb_checkpass.</td>
    <td>2026-05-20</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47784" target=3D= "_blank" rel=3D"noopener">CVE-2026-47784</a></td>
    </tr>

    <td class=3D"vendor-product">Mesalvo--Meona Client Launcher Component</td> <td>Improper Control of Generation of Code ('Code Injection') vulnerability=
    in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component=
    enables code execution on other users' systems.=C2=A0This issue affects Me= ona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Co= mponent: through 2025.04 5+323020.</td>
    <td>2026-05-20</td>
    <td>9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22314" target=3D= "_blank" rel=3D"noopener">CVE-2026-22314</a></td>
    </tr>

    <td class=3D"vendor-product">Mesalvo--Meona Client Launcher Component</td> <td>Improper Access Control vulnerability in Mesalvo Meona Client Launcher = Component, Mesalvo Meona Server Component enables a normal user gaining acc= ess to the admin panel.=C2=A0This issue affects Meona Client Launcher Compo= nent: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 = 5+323020.</td>
    <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-0856" target=3D"= _blank" rel=3D"noopener">CVE-2026-0856</a></td>
    </tr>

    <td class=3D"vendor-product">Mesalvo--Meona Client Launcher Component</td> <td>Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client La= uncher Component, Mesalvo Meona Server Component enables the export=C2=A0 o=
    f user data, including cleartext passwords, via the SQL editor.=C2=A0This i= ssue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; = Meona Server Component: through 2025.04 5+323020.</td>
    <td>2026-05-20</td>
    <td>7.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22315" target=3D= "_blank" rel=3D"noopener">CVE-2026-22315</a></td>
    </tr>

    <td class=3D"vendor-product">metaphorcreations--Ditty Responsive News Ticke= rs, Sliders, and Lists</td>
    <td>The Ditty - Responsive News Tickers, Sliders, and Lists plugin for Word= Press is vulnerable to authorization bypass in all versions up to, and incl= uding, 3.1.65. This is due to the plugin not properly verifying that a user=
    is authorized to perform an action. This makes it possible for unauthentic= ated attackers to retrieve the full item content of non-public Dittys - inc= luding drafts, pending, scheduled, and disabled entries - by enumerating in= teger post IDs against the ditty_init AJAX endpoint. Unlike the non-AJAX in= it() counterpart, init_ajax() does not verify that the requested Ditty has =
    a 'publish' post status before loading and returning its items, allowing co= ntent that administrators explicitly withheld from public view to be extrac= ted.</td>
    <td>2026-05-22</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9011" target=3D"= _blank" rel=3D"noopener">CVE-2026-9011</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Azure Local</td>
    <td>Improper authentication in Azure Local Disconnected Operations allows a=
    n unauthorized attacker to elevate privileges over a network.</td> <td>2026-05-18</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42822" target=3D= "_blank" rel=3D"noopener">CVE-2026-42822</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Azure Orbital Spatio</td> <td>Unrestricted upload of file with dangerous type in Azure Orbital Spatio=
    allows an unauthorized attacker to execute code over a network.</td> <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40412" target=3D= "_blank" rel=3D"noopener">CVE-2026-40412</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Azure Privileged Identity Managemen=
    t (PIM)</td>
    <td>Authorization bypass through user-controlled key in Azure Privileged Id= entity Management (PIM) allows an authorized attacker to elevate privileges=
    over a network.</td>
    <td>2026-05-22</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35430" target=3D= "_blank" rel=3D"noopener">CVE-2026-35430</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Azure Resource Manager</td> <td>Improper authentication in Azure Resource Manager (ARM) allows an unaut= horized attacker to elevate privileges over a network.</td>
    <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47280" target=3D= "_blank" rel=3D"noopener">CVE-2026-47280</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Azure Stack HCI</td>
    <td>Improper input validation in Azure Compute Gallery allows an authorized=
    attacker to disclose information over a network.</td>
    <td>2026-05-22</td>
    <td>7.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-26147" target=3D= "_blank" rel=3D"noopener">CVE-2026-26147</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Azure Virtual Network Gateway</td> <td>Improper input validation in Azure Virtual Network Gateway allows an au= thorized attacker to execute code over a network.</td>
    <td>2026-05-22</td>
    <td>9.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40411" target=3D= "_blank" rel=3D"noopener">CVE-2026-40411</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft 365 Copilot for iOS</td> <td>Improper neutralization of special elements used in a command ('command=
    injection') in Microsoft Copilot allows an unauthorized attacker to perfor=
    m tampering over a network.</td>
    <td>2026-05-22</td>
    <td>9.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41090" target=3D= "_blank" rel=3D"noopener">CVE-2026-41090</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=

    <td>Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability</td=

    <td>2026-05-18</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45495" target=3D= "_blank" rel=3D"noopener">CVE-2026-45495</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Entra</td>
    <td>Origin validation error in Microsoft Entra ID allows an unauthorized at= tacker to elevate privileges over a network.</td>
    <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42901" target=3D= "_blank" rel=3D"noopener">CVE-2026-42901</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Entra</td>
    <td>Authentication bypass using an alternate path or channel in Microsoft A= zure Active Directory B2C allows an unauthorized attacker to elevate privil= eges over a network.</td>
    <td>2026-05-22</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33843" target=3D= "_blank" rel=3D"noopener">CVE-2026-33843</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Global Secure Access (GSA= )</td>
    <td>Improper privilege management in Azure Entra ID allows an unauthorized = attacker to elevate privileges over a network.</td>
    <td>2026-05-22</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-23663" target=3D= "_blank" rel=3D"noopener">CVE-2026-23663</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Malware Protection Engine= </td>
    <td>Heap-based buffer overflow in Microsoft Defender allows an unauthorized=
    attacker to execute code over a network.</td>
    <td>2026-05-20</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45584" target=3D= "_blank" rel=3D"noopener">CVE-2026-45584</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Malware Protection Engine= </td>
    <td>Improper link resolution before file access ('link following') in Micro= soft Defender allows an authorized attacker to elevate privileges locally.<=

    <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41091" target=3D= "_blank" rel=3D"noopener">CVE-2026-41091</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Planetary Computer Pro (G= eoCatalog)</td>
    <td>Deserialization of untrusted data in Microsoft Planetary Computer Pro a= llows an unauthorized attacker to disclose information over a network.</td> <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41104" target=3D= "_blank" rel=3D"noopener">CVE-2026-41104</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Power Pages</td>
    <td>Improper neutralization of special elements used in a command ('command=
    injection') in Microsoft Power Pages allows an unauthorized attacker to ex= ecute code over a network.</td>
    <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-23652" target=3D= "_blank" rel=3D"noopener">CVE-2026-23652</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft SharePoint Enterprise Ser= ver 2016</td>
    <td>Deserialization of untrusted data in Microsoft Office SharePoint allows=
    an authorized attacker to execute code over a network.</td> <td>2026-05-22</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45659" target=3D= "_blank" rel=3D"noopener">CVE-2026-45659</a></td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Windows Admin Center in Azure Porta= l</td>
    <td>Improper link resolution before file access ('link following') in Azure=
    Portal Windows Admin Center allows an authorized attacker to elevate privi= leges locally.</td>
    <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42834" target=3D= "_blank" rel=3D"noopener">CVE-2026-42834</a></td>
    </tr>

    <td class=3D"vendor-product">Motorola--Phones</td>
    <td>An improper authentication vulnerability was discovered in the Motorola=
    Factory Test=C2=A0component=C2=A0(com.motorola.motocit). The application= =C2=A0contained=C2=A0a reference to a writable file descriptor in external = storage which could be used by third party apps running on the device to op=
    en a TCP server, exposing sensitive permissions and data. This could allow =
    a local attacker to bypass permission checks and access protected device se= ttings.</td>
    <td>2026-05-19</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5804" target=3D"= _blank" rel=3D"noopener">CVE-2026-5804</a></td>
    </tr>

    <td class=3D"vendor-product">mullvad--mullvadvpn-app</td>
    <td>Mullvad VPN is a VPN client app for desktop and mobile. When using macO=
    S with versions 2026.1 and below, Mullvad VPN may allow local privilege esc= alation during installation or upgrade. The installer package executes bina= ries from /Applications/Mullvad VPN.app without verifying if the bundle is = attacker-controlled or that the path is the legitimate Mullvad application.=
    A user in the admin group can pre-place a crafted application bundle at th=
    at location and may be able to achieve code execution as root. Since the is= sue only affected the installer, there is no immediate need for users to up= date if they are already running an older version. This issue has been fixe=
    d in version 2026.2-beta1.</td>
    <td>2026-05-19</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32323" target=3D= "_blank" rel=3D"noopener">CVE-2026-32323</a></td>
    </tr>

    <td class=3D"vendor-product">n/a--exifreader</td>
    <td>This affects versions of the package exifreader before 4.39.0. A crafte=
    d image containing an ICC mluc tag can set an attacker-controlled record co= unt together with a zero record size. During parsing, ExifReader repeatedly=
    processes the same record and appends entries to an array without sufficie=
    nt bounds validation, causing excessive memory growth. In applications that=
    parse attacker-supplied images, this may lead to denial of service through=
    memory exhaustion.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8813" target=3D"= _blank" rel=3D"noopener">CVE-2026-8813</a></td>
    </tr>

    <td class=3D"vendor-product">n/a--lwIP</td>
    <td>A vulnerability was found in lwIP up to 2.2.1. Affected is the function=
    snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the compo= nent snmpv3 USM Handler. Performing a manipulation of the argument msgAuthe= nticationParameters results in stack-based buffer overflow. The attack may =
    be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90a= da3898c. It is suggested to install a patch to address this issue.</td> <td>2026-05-18</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8836" target=3D"= _blank" rel=3D"noopener">CVE-2026-8836</a></td>
    </tr>

    <td class=3D"vendor-product">n/a--shell-quote</td>
    <td>shell-quote's `quote()` function did not validate object-token inputs a= gainst the operator model used by `parse()`. The `.op` field was backslash-= escaped character by character using `/(.)/g`, which in JavaScript does not=
    match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op=
    ` therefore passed through unescaped into the output; POSIX shells treat a = literal newline as a command separator, so any content after it would execu=
    te as a second command. The vulnerable code path is reachable in two ways: = (1) direct construction of `{ op: '...\n...' }` from external input, and (2=
    ) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is=
    attacker-influenced. Both are documented API surface. Fixed by replacing t=
    he per-character escape with strict shape validation: `.op` must match the = parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `p= attern` and forbids line terminators; `{ comment }` validates `comment` and=
    forbids line terminators; any other object shape throws `TypeError`.</td> <td>2026-05-22</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9277" target=3D"= _blank" rel=3D"noopener">CVE-2026-9277</a></td>
    </tr>

    <td class=3D"vendor-product">NeoRazorX--facturascripts</td>
    <td>FacturaScripts is an open source accounting and invoicing software. Ver= sions 2026 and below contain a critical vulnerability in the Plugins::add()=
    function. The system fails to properly validate the file paths within uplo= aded ZIP archives. This allows an attacker to perform a Zip Slip attack, le= ading to Arbitrary File Write and Remote Code Execution (RCE) by overwritin=
    g sensitive .php files outside the designated plugins directory. The vulner= ability is located in Plugins.php. While the testZipFile function attempts =
    to validate that the ZIP contains only one root folder, it does not sanitiz=
    e or validate the individual file paths within that folder. An attacker can=
    bypass this check by naming a file ValidPluginName/../../shell.php. The ex= plode function will see ValidPluginName as the root folder, satisfying the = count($folders) !=3D 1 check. However, during extraction, the ../../ sequen=
    ce triggers a path traversal, allowing the file to be written anywhere the = web server has permissions the root directory. This issue is fixed in versi=
    on 2026.1.</td>
    <td>2026-05-18</td>
    <td>7.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27891" target=3D= "_blank" rel=3D"noopener">CVE-2026-27891</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A heap-based buffer overflow in the CNID daemon comm_rcv() function in = Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to exec= ute arbitrary code with escalated privileges or cause a denial of service.<=

    <td>2026-05-21</td>
    <td>9.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44050" target=3D= "_blank" rel=3D"noopener">CVE-2026-44050</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.= 1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthor= ized access to data, modify data, or cause a denial of service.</td> <td>2026-05-21</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44047" target=3D= "_blank" rel=3D"noopener">CVE-2026-44047</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A stack-based buffer overflow via UCS-2 type confusion in convert_chars= et() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker=
    to execute arbitrary code or cause a denial of service.</td> <td>2026-05-21</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44048" target=3D= "_blank" rel=3D"noopener">CVE-2026-44048</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4=
    .2 allows a remote authenticated attacker to read arbitrary files or overwr= ite arbitrary files via attacker-controlled symlink creation.</td> <td>2026-05-21</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44051" target=3D= "_blank" rel=3D"noopener">CVE-2026-44051</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An out-of-bounds write due to improper null termination in convert_char= set() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacke=
    r to execute arbitrary code or cause a denial of service via crafted charac= ter data.</td>
    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44049" target=3D= "_blank" rel=3D"noopener">CVE-2026-44049</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into lo=
    g output in cleartext, which allows an attacker with access to the log file=
    s to obtain LDAP credentials.</td>
    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44052" target=3D= "_blank" rel=3D"noopener">CVE-2026-44052</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in t=
    he DHCAST128 UAM, which allows a remote attacker to obtain authentication c= redentials or impersonate a user via cryptanalytic attack.</td> <td>2026-05-21</td>
    <td>7.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44053" target=3D= "_blank" rel=3D"noopener">CVE-2026-44053</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A logic error involving bitwise OR operations in Netatalk 3.1.4 through=
    4.4.2 allows a remote authenticated attacker to inject OS commands and exe= cute arbitrary code.</td>
    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44055" target=3D= "_blank" rel=3D"noopener">CVE-2026-44055</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2=
    allows a remote unauthenticated attacker to cause a denial of service via =
    a crafted DSI write request.</td>
    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44060" target=3D= "_blank" rel=3D"noopener">CVE-2026-44060</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A missing output length bounds check in pull_charset_flags() in Netatal=
    k 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arb= itrary code or cause a denial of service via crafted character set data.</t=

    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44062" target=3D= "_blank" rel=3D"noopener">CVE-2026-44062</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An out-of-bounds read in ASP session ID handling in Netatalk 1.3 throug=
    h 4.4.2 allows an adjacent network attacker to obtain limited information o=
    r cause a denial of service via a crafted ASP request.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44064" target=3D= "_blank" rel=3D"noopener">CVE-2026-44064</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling co=
    de in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to=
    obtain sensitive information or cause a minor service disruption.</td> <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44066" target=3D= "_blank" rel=3D"noopener">CVE-2026-44066</a></td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Incomplete sanitization of extended attribute (EA) path components in N= etatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write=
    to files outside the intended metadata namespace via crafted EA names.</td=

    <td>2026-05-21</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44068" target=3D= "_blank" rel=3D"noopener">CVE-2026-44068</a></td>
    </tr>

    <td class=3D"vendor-product">nimiq--core-rs-albatross</td>
    <td>nimiq-blockchain provides persistent block storage for Nimiq's Rust imp= lementation. In versions 1.3.0 and below, a malicious network peer can cras=
    h any Nimiq full node by publishing a crafted Kademlia DHT record. The mali= ciously crafted record would contain a TaggedSigned&lt;ValidatorRecord, Key= Pair&gt; with a signature field whose byte length is not exactly 64 in orde=
    r to cause a crash. When the victim node's DHT verifier calls TaggedSigned:= :verify, execution reaches Ed25519Signature::from_bytes(sig).unwrap() in th=
    e TaggedPublicKey implementation for Ed25519PublicKey. The from_bytes call = fails because ed25519_zebra::Signature::try_from rejects slices not 64 byte=
    s, and the unwrap() panics. The BLS TaggedPublicKey implementation correctl=
    y returns false on error; only the Ed25519 implementation panics. This issu=
    e has been fixed in version 1.4.0.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40092" target=3D= "_blank" rel=3D"noopener">CVE-2026-40092</a></td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A vulnerability was identified in NousResearch hermes-agent up to 2026.= 4.16. This affects the function check_all_command_guards of the file tools/= approval.py of the component Batch Runner. Such manipulation leads to missi=
    ng authorization. The attack can be launched remotely. The exploit is publi= cly available and might be used. The vendor was contacted early about this = disclosure but did not respond in any way.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9350" target=3D"= _blank" rel=3D"noopener">CVE-2026-9350</a></td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A security vulnerability has been detected in NousResearch hermes-agent=
    up to 2026.4.23. Impacted is an unknown function of the file agent/skills_= guard.py of the component Skills Guard Multi-Word Prompt Handler. The manip= ulation of the argument THREAT_PATTERNS leads to injection. Remote exploita= tion of the attack is possible. The exploit has been disclosed publicly and=
    may be used. The vendor was contacted early about this disclosure but did = not respond in any way.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9353" target=3D"= _blank" rel=3D"noopener">CVE-2026-9353</a></td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A vulnerability was found in NousResearch hermes-agent 2026.4.23. The i= mpacted element is the function _scan_context_content of the file agent/pro= mpt_builder.py. The manipulation results in injection. The attack may be pe= rformed from remote. The exploit has been made public and could be used. Th=
    e vendor was contacted early about this disclosure but did not respond in a=
    ny way.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9366" target=3D"= _blank" rel=3D"noopener">CVE-2026-9366</a></td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A vulnerability was determined in NousResearch hermes-agent up to 5157f= 5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dange= rous_command of the file tools/approval.py of the component terminal_tool. = This manipulation causes os command injection. It is possible to initiate t=
    he attack remotely. The exploit has been publicly disclosed and may be util= ized. The vendor was contacted early about this disclosure but did not resp= ond in any way.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9367" target=3D"= _blank" rel=3D"noopener">CVE-2026-9367</a></td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A vulnerability was identified in NousResearch hermes-agent up to 2026.= 4.16. This impacts the function execute_code of the file tools/code_executi= on_tool.py of the component Environment Variable Handler. Such manipulation=
    leads to sandbox issue. It is possible to launch the attack remotely. The = exploit is publicly available and might be used. The vendor was contacted e= arly about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9368" target=3D"= _blank" rel=3D"noopener">CVE-2026-9368</a></td>
    </tr>

    <td class=3D"vendor-product">nukeviet--nukeviet</td>
    <td>NukeViet CMS is a multi Content Management System. Versions 4.5.07 and = prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by i= nsufficient server-side input sanitization in the Request class. The applic= ation relies primarily on client-side filtering to sanitize HTML tags and a= ttributes in user-submitted content, which can be bypassed by intercepting = and modifying HTTP requests directly (e.g., using Burp Suite). An attacker = can inject malicious payloads which are stored server-side and executed in = the browser of any user who views the content. Anyone viewing user-submitte=
    d content (such as administrators and moderators reviewing contact messages=
    or comments) is impacted, and the vulnerability can be exploited by any an= onymous visitor without authentication, with the Contact module used only a=
    s a proof of concept. Potential consequences include session hijacking thro= ugh cookie theft, unauthorized actions performed under the victim's identit=
    y, defacement or redirection to phishing pages, and phishing attacks via ma= nipulated email notifications. This issue has been fixed in version 4.5.08.=
    If developers are unable to upgrade immediately, they should work around t= his issue by implementing server-side HTML sanitization in the Request clas=
    s to strip or encode dangerous tags and attributes (e.g., &lt;iframe&gt;, s= rcdoc, event handlers like onerror/onload), enforcing a Content Security Po= licy (CSP) to restrict inline script execution, and set cookies with the Ht= tpOnly flag to mitigate cookie theft via XSS.</td>
    <td>2026-05-22</td>
    <td>8.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41147" target=3D= "_blank" rel=3D"noopener">CVE-2026-41147</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--BioNeMo Framework</td>
    <td>NVIDIA BioNeMo Core for Linux contains a vulnerability where a user cou=
    ld cause a path traversal by loading a malicious file. A successful exploit=
    of this vulnerability might lead to code execution, denial of service, inf= ormation disclosure, and data tampering.</td>
    <td>2026-05-20</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24217" target=3D= "_blank" rel=3D"noopener">CVE-2026-24217</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--BioNeMo Framework</td>
    <td>NVIDIA BioNemo for Linux contains a vulnerability where a user could ca= use a deserialization of untrusted data. A successful exploit of this vulne= rability might lead to code execution, denial of service, information discl= osure, and data tampering.</td>
    <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24216" target=3D= "_blank" rel=3D"noopener">CVE-2026-24216</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--DGX Spark</td>
    <td>NVIDIA DGX OS contains a vulnerability in the factory provisioning proc= ess, where the cloning of a base image causes identical SSH host keys to be=
    deployed across multiple systems. The sharing of cryptographic identifiers=
    across all similarly provisioned systems enables host impersonation or att= acker-in-the-middle attacks. A successful exploit of this vulnerability mig=
    ht lead to code execution, data tampering, escalation of privileges, inform= ation disclosure, and denial of service.</td>
    <td>2026-05-20</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24218" target=3D= "_blank" rel=3D"noopener">CVE-2026-24218</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--TensorRT</td>
    <td>NVIDIA TensorRT contains a vulnerability where an attacker could cause =
    an out-of-bounds write. A successful exploit of this vulnerability might le=
    ad to data tampering.</td>
    <td>2026-05-20</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24188" target=3D= "_blank" rel=3D"noopener">CVE-2026-24188</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--TensorRT-LLM</td>
    <td>NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server,=
    where an attacker could cause an unsafe deserialization. A successful expl= oit of this vulnerability might lead to code execution, denial of service, = data tampering, and information disclosure.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-33255" target=3D= "_blank" rel=3D"noopener">CVE-2025-33255</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--TensorRT-LLM</td>
    <td>NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing=
    , where an attacker could cause an unsafe deserialization. A successful exp= loit of this vulnerability might lead to code execution, denial of service,=
    data tampering, and information disclosure.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24163" target=3D= "_blank" rel=3D"noopener">CVE-2026-24163</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability where an attack=
    er could cause an authentication bypass. A successful exploit of this vulne= rability might lead to code execution, escalation of privileges, data tampe= ring, denial of service, or information disclosure.</td>
    <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24207" target=3D= "_blank" rel=3D"noopener">CVE-2026-24207</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability in the DALI bac= kend where an attacker could cause an out-of-bounds read. A successful expl= oit of this vulnerability might lead to code execution, data tampering, den= ial of service, or information disclosure.</td>
    <td>2026-05-20</td>
    <td>8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24213" target=3D= "_blank" rel=3D"noopener">CVE-2026-24213</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability in the DALI bac= kend where an attacker could cause an integer overflow. A successful exploi=
    t of this vulnerability might lead to code execution, data tampering, or de= nial of service.</td>
    <td>2026-05-20</td>
    <td>8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24214" target=3D= "_blank" rel=3D"noopener">CVE-2026-24214</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability where an attack=
    er could cause an authentication bypass. A successful exploit of this vulne= rability might lead to escalation of privileges, denial of service, or info= rmation disclosure.</td>
    <td>2026-05-20</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24206" target=3D= "_blank" rel=3D"noopener">CVE-2026-24206</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability where an attack=
    er could cause a path traversal issue. A successful exploit of this vulnera= bility might lead to denial of service.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24209" target=3D= "_blank" rel=3D"noopener">CVE-2026-24209</a></td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability where an attack=
    er could cause an integer overflow. A successful exploit of this vulnerabil= ity might lead to denial of service.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24210" target=3D= "_blank" rel=3D"noopener">CVE-2026-24210</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude,=
    and timestamp values parsed from external GPS tracking service XML/JSON re= sponses (InstaMapper and Google Latitude integration) are concatenated into=
    UPDATE and INSERT statements without sanitization. An attacker able to com= promise or impersonate the remote GPS tracker endpoint can inject SQL to ma= nipulate the responder location, tracks, and assignment tables.</td> <td>2026-05-21</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48235" target=3D= "_blank" rel=3D"noopener">CVE-2026-48235</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains hardcoded MySQL database crede= ntials in loader.php (a public-facing database utility) that are committed =
    to the source repository. Any actor with access to the public source tree (=
    or an unauthenticated attacker with read access to the file on a deployed i= nstallation) can read the username, password, and database name and use the=
    m to connect to the database if it is reachable from their network.</td> <td>2026-05-21</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48241" target=3D= "_blank" rel=3D"noopener">CVE-2026-48241</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains hardcoded MySQL database conne= ction credentials (host, username, password, database name) in import_mdb.p= hp. The credentials are embedded in source code committed to the public rep= ository, allowing any reader of the source to obtain valid configuration va= lues that may match deployed installations.</td>
    <td>2026-05-21</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48242" target=3D= "_blank" rel=3D"noopener">CVE-2026-48242</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in tables.php where the multiple POST parameters (tablename, indexname, sor= tby) are concatenated into table/column identifiers in dynamically construc= ted SELECT/UPDATE/DELETE statements without sanitization. Authenticated att= ackers can craft requests that alter query semantics to read, modify, or de= stroy database contents.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48231" target=3D= "_blank" rel=3D"noopener">CVE-2026-48231</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in ajax/fullsit_incidents.php where the offset GET parameter is concatenate=
    d into the LIMIT clause of a SELECT statement without sanitization. Authent= icated attackers can craft requests that alter query semantics to read, mod= ify, or destroy database contents.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48232" target=3D= "_blank" rel=3D"noopener">CVE-2026-48232</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in ajax/sit_incidents.php where the offset GET parameter is concatenated in=
    to the LIMIT clause of a SELECT statement without sanitization. Authenticat=
    ed attackers can craft requests that alter query semantics to read, modify,=
    or destroy database contents.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48233" target=3D= "_blank" rel=3D"noopener">CVE-2026-48233</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in portal/ajax/list_requests.php where the sort and dir GET parameters are = concatenated into the ORDER BY clause of a SELECT statement without sanitiz= ation. Authenticated attackers can craft requests that alter query semantic=
    s to read, modify, or destroy database contents.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48234" target=3D= "_blank" rel=3D"noopener">CVE-2026-48234</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost=
    , ticketsuser, ticketspassword) are concatenated into mysqli connection arg= uments and dynamic SQL operating against an attacker-controlled database wi= thout sanitization. Authenticated attackers can craft requests that alter q= uery semantics to read, modify, or destroy database contents.</td> <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48236" target=3D= "_blank" rel=3D"noopener">CVE-2026-48236</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in message.php where the frm_ticket_id and frm_resp_id POST parameters are = concatenated into WHERE clauses of SELECT/UPDATE statements without sanitiz= ation. Authenticated attackers can craft requests that alter query semantic=
    s to read, modify, or destroy database contents.</td>
    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48237" target=3D= "_blank" rel=3D"noopener">CVE-2026-48237</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in ajax/mobile_main.php where the id GET parameter is concatenated into the=
    WHERE clause of a SELECT statement used as a ticket-existence sanity check=
    without sanitization. Authenticated attackers can craft requests that alte=
    r query semantics to read, modify, or destroy database contents.</td> <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48238" target=3D= "_blank" rel=3D"noopener">CVE-2026-48238</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in ajax/reports.php where the tick_id POST parameter is concatenated into t=
    he WHERE clause of SELECT statements in the incidents summary report withou=
    t sanitization. Authenticated attackers can craft requests that alter query=
    semantics to read, modify, or destroy database contents.</td> <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48239" target=3D= "_blank" rel=3D"noopener">CVE-2026-48239</a></td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability =
    in ajax/statistics.php where the tick_id and f_tick_id POST parameters are = concatenated into WHERE clauses of SELECT statements in the statistics roll=
    up queries without sanitization. Authenticated attackers can craft requests=
    that alter query semantics to read, modify, or destroy database contents.<=

    <td>2026-05-21</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48240" target=3D= "_blank" rel=3D"noopener">CVE-2026-48240</a></td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrar=
    y code execution in pre-installed apps.</td>
    <td>2026-05-19</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24792" target=3D= "_blank" rel=3D"noopener">CVE-2026-24792</a></td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS=
    and it cannot be recovered.</td>
    <td>2026-05-19</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25781" target=3D= "_blank" rel=3D"noopener">CVE-2026-25781</a></td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrar=
    y code execution in pre-installed apps.</td>
    <td>2026-05-19</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27648" target=3D= "_blank" rel=3D"noopener">CVE-2026-27648</a></td>
    </tr>

    <td class=3D"vendor-product">OPPO--O+ Connect</td>
    <td>A local privilege escalation vulnerability exists in O+ Connect because=
    it fails to validate the identity of the caller on the pipe interface.</td=

    <td>2026-05-19</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22069" target=3D= "_blank" rel=3D"noopener">CVE-2026-22069</a></td>
    </tr>

    <td class=3D"vendor-product">Piotnet--Piotnet Addons For Elementor Pro</td> <td>The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable=
    to arbitrary file upload due to missing file type validation in the 'pafe_= ajax_form_builder' function in all versions up to, and including, 7.1.70. T=
    he plugin uses an incomplete extension blacklist that only blocks php, phpt=
    , php5, php7, and exe extensions, while allowing dangerous extensions such =
    as .phar or .phtml to be uploaded. This makes it possible for unauthenticat=
    ed attackers to upload arbitrary files on the affected site's server which = may make remote code execution possible. Note: The exploit can only be expl= oited if a file field is added to the form.</td>
    <td>2026-05-19</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4885" target=3D"= _blank" rel=3D"noopener">CVE-2026-4885</a></td>
    </tr>

    <td class=3D"vendor-product">Piotnet--Piotnet Forms</td>
    <td>The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file = upload due to missing file type validation in the 'piotnetforms_ajax_form_b= uilder' function in all versions up to, and including, 2.1.40. The plugin u= ses an incomplete extension blacklist that only blocks php, phpt, php5, php=
    7, and exe extensions, while allowing dangerous extensions such as .phar or=
    .phtml to be uploaded. This makes it possible for unauthenticated attacker=
    s to upload arbitrary files on the affected site's server which may make re= mote code execution possible. Note: The exploit can only be exploited if a = file field is added to the form.</td>
    <td>2026-05-19</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4883" target=3D"= _blank" rel=3D"noopener">CVE-2026-4883</a></td>
    </tr>

    <td class=3D"vendor-product">PixelYourSite--Boost</td>
    <td>The Boost plugin for WordPress is vulnerable to PHP Object Injection in=
    versions up to, and including, 2.0.3 via deserialization of untrusted inpu=
    t in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for una= uthenticated attackers to inject a PHP Object. No known POP chain is presen=
    t in the vulnerable software, which means this vulnerability has no impact = unless another plugin or theme containing a POP chain is installed on the s= ite. If a POP chain is present via an additional plugin or theme installed =
    on the target system, it may allow the attacker to perform actions like del= ete arbitrary files, retrieve sensitive data, or execute code depending on = the POP chain present.</td>
    <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7637" target=3D"= _blank" rel=3D"noopener">CVE-2026-7637</a></td>
    </tr>

    <td class=3D"vendor-product">PixelYourSite--Boost</td>
    <td>The Boost plugin for WordPress is vulnerable to time-based SQL Injectio=
    n via the 'current_url' and 'user_name' parameters in versions up to, and i= ncluding, 2.0.3 due to insufficient escaping on the user supplied parameter=
    s and lack of sufficient preparation on the existing SQL queries. This make=
    s it possible for unauthenticated attackers to append additional SQL querie=
    s into already existing queries that can be used to extract sensitive infor= mation from the database.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9010" target=3D"= _blank" rel=3D"noopener">CVE-2026-9010</a></td>
    </tr>

    <td class=3D"vendor-product">pixelyoursite--Cost of Goods by PixelYourSite<=

    <td>The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable t=
    o Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' par= ameter in versions up to, and including, 1.2.12 due to insufficient input s= anitization and output escaping. This makes it possible for unauthenticated=
    attackers to inject arbitrary web scripts in pages that will execute whene= ver a user accesses an injected page.</td>
    <td>2026-05-20</td>
    <td>7.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7613" target=3D"= _blank" rel=3D"noopener">CVE-2026-7613</a></td>
    </tr>

    <td class=3D"vendor-product">PosCube Hardware Software and Consulting Ltd.-= -QR Menu</td>
    <td>Authorization bypass through User-Controlled key vulnerability in PosCu=
    be Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Tru= sted Identifiers. This issue affects QR Menu: through 21052026.=C2=A0NOTE: = The vendor was contacted early about this disclosure but did not respond in=
    any way.</td>
    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-13479" target=3D= "_blank" rel=3D"noopener">CVE-2025-13479</a></td>
    </tr>

    <td class=3D"vendor-product">PowerDNS--Authoritative</td>
    <td>Insufficient Validation of Autoprimary SOA Queries</td>
    <td>2026-05-21</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42001" target=3D= "_blank" rel=3D"noopener">CVE-2026-42001</a></td>
    </tr>

    <td class=3D"vendor-product">projectworlds--hospital-management-system-in-p= hp</td>
    <td>A flaw has been found in projectworlds hospital-management-system-in-ph=
    p 1.0. Affected by this vulnerability is the function getAllPatientDetail o=
    f the file update_info.php of the component GET Parameter Handler. Executin=
    g a manipulation of the argument appointment_no can lead to sql injection. = The attack may be performed from remote. The exploit has been published and=
    may be used. The project was informed of the problem early through an issu=
    e report but has not responded yet.</td>
    <td>2026-05-18</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8785" target=3D"= _blank" rel=3D"noopener">CVE-2026-8785</a></td>
    </tr>

    <td class=3D"vendor-product">projectworlds--Online Art Gallery Shop</td>
    <td>A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Imp= acted is an unknown function of the file /admin/adminHome.php. Executing a = manipulation of the argument social_linked can lead to sql injection. The a= ttack can be executed remotely. The exploit has been published and may be u= sed.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9364" target=3D"= _blank" rel=3D"noopener">CVE-2026-9364</a></td>
    </tr>

    <td class=3D"vendor-product">prosolution--ProSolution WP Client</td>
    <td>The ProSolution WP Client plugin for WordPress is vulnerable to Arbitra=
    ry File Upload in versions up to, and including, 2.0.0. This is due to an a= rray validation mismatch where only the first file in the upload array unde= rgoes extension and MIME type validation, while all files are processed and=
    uploaded to a web-accessible directory. This makes it possible for unauthe= nticated attackers to upload malicious PHP files and achieve remote code ex= ecution by sending a valid first file followed by a malicious file.</td> <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6555" target=3D"= _blank" rel=3D"noopener">CVE-2026-6555</a></td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.2</td>
    <td>A flaw was found in Keycloak's URL validation logic during redirect ope= rations. By crafting a malicious request, an attacker could bypass validati=
    on to redirect users to unauthorized URLs, potentially leading to the expos= ure of sensitive information within the domain or facilitating further atta= cks. This vulnerability specifically affects Keycloak clients configured wi=
    th a wildcard (*) in the "Valid Redirect URIs" field and requires user inte= raction to be successfully exploited. The issue stems from a discrepancy in=
    how Keycloak and the underlying Java URI implementation handle the user-in=
    fo component of a URL. If a malicious redirect URL is constructed using mul= tiple @ characters in the user-info section, Java's URI parser fails to ext= ract the user-info, leaving only the raw authority field. Consequently, Key= cloak's validation check fails to detect the malformed user-info, falls bac=
    k to a wildcard comparison, and incorrectly permits the malicious redirect.= </td>
    <td>2026-05-19</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7504" target=3D"= _blank" rel=3D"noopener">CVE-2026-7504</a></td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.2</td>
    <td>A flaw was found in Keycloak. A remote, unauthenticated attacker can se=
    nd a specially crafted XML input to the Security Assertion Markup Language = (SAML) endpoint. This malicious input can cause high CPU usage and worker t= hread starvation, leading to a Denial of Service (DoS) where the server bec= omes unavailable.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7307" target=3D"= _blank" rel=3D"noopener">CVE-2026-7307</a></td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.2</td>
    <td>A session fixation vulnerability was found in Keycloak's login-actions = endpoints. An unauthenticated attacker could exploit this flaw by pre-creat= ing an authentication session and tricking a victim into visiting a malicio= usly crafted link. By leveraging the /login-actions/restart endpoint-which = processes session handles without adequate CSRF protection or cookie owners= hip validation-an attacker can reset the authentication flow state. This ca= uses Single Sign-On (SSO) to authenticate the victim transparently upon cli= cking the link, allowing the attacker to hijack the required-action form wi= thout needing the victim's credentials. A successful exploit could lead to = complete account takeover, including highly privileged administrative accou= nts.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7507" target=3D"= _blank" rel=3D"noopener">CVE-2026-7507</a></td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.4</td>
    <td>A flaw was found in Keycloak. A low-privilege user, with knowledge of u= ser credentials and client ID, can bypass a security control intended to di= sable the implicit flow in OpenID Connect (OIDC) clients. By manipulating c= lient data during a session restart, an attacker can obtain an access token=
    that should not be available. This vulnerability can also lead to the expo= sure of these access tokens in server logs, proxy logs, and HTTP Referrer h= eaders, resulting in sensitive information disclosure.</td>
    <td>2026-05-19</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7571" target=3D"= _blank" rel=3D"noopener">CVE-2026-7571</a></td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Directory Server 11</td>
    <td>A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fun= ction in the LDAP server does not enforce an upper bound on the number of c= ontrols per LDAP message. A remote, unauthenticated attacker can send a spe= cially crafted LDAP request containing hundreds of thousands of minimal con= trols within the default maximum BER message size (2 MB), causing excessive=
    CPU consumption and heap allocation on the server. Under concurrent exploi= tation, this leads to significant latency degradation, worker thread starva= tion, or out-of-memory termination, resulting in a denial of service.</td> <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9064" target=3D"= _blank" rel=3D"noopener">CVE-2026-9064</a></td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Hardened Images</td>
    <td>A flaw was found in gnutls. A remote attacker could exploit an issue in=
    the Datagram Transport Layer Security (DTLS) packet reordering logic. The = comparator function, responsible for ordering DTLS packets by sequence numb= ers, did not correctly handle packets with duplicate sequence numbers. This=
    could lead to unstable packet ordering or undefined behavior, resulting in=
    a denial of service.</td>
    <td>2026-05-18</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42009" target=3D= "_blank" rel=3D"noopener">CVE-2026-42009</a></td>
    </tr>

    <td class=3D"vendor-product">Redaxo--Redaxo CMS Mediapool</td>
    <td>Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file u= pload vulnerability that allows authenticated users to bypass file extensio=
    n blacklist restrictions. Attackers with editor accounts can upload executa= ble files by using obfuscated extensions like php71 or php53 to evade the b= lacklist filter and execute arbitrary code.</td>
    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25353" target=3D= "_blank" rel=3D"noopener">CVE-2018-25353</a></td>
    </tr>

    <td class=3D"vendor-product">Repute Infosystems--BookingPress Appointment B= ooking Pro</td>
    <td>The BookingPress Pro plugin for WordPress is vulnerable to arbitrary fi=
    le uploads due to missing file type validation in the 'bookingpress_validat= e_submitted_booking_form_func' function in all versions up to, and includin=
    g, 5.6. This makes it possible for unauthenticated attackers to upload arbi= trary files on the affected site's server which may make remote code execut= ion possible. Note: The vulnerability can only be exploited if a signature = custom field is added to the booking form.</td>
    <td>2026-05-21</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6960" target=3D"= _blank" rel=3D"noopener">CVE-2026-6960</a></td>
    </tr>

    <td class=3D"vendor-product">RsyncProject--rsync</td>
    <td>Rsync version=C2=A03.4.2 and prior contain an integer overflow vulnerab= ility in the compressed-token decoder where a 32-bit signed counter is not = checked for overflow, allowing a malicious sender to trigger an overflow th=
    at causes the receiver process to read and return data from outside the int= ended buffer bounds. Attackers can exploit this vulnerability to disclose p= rocess memory contents including environment variables, passwords, heap and=
    stack data, and library memory pointers, significantly reducing ASLR effec= tiveness and facilitating further exploitation.</td>
    <td>2026-05-20</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43618" target=3D= "_blank" rel=3D"noopener">CVE-2026-43618</a></td>
    </tr>

    <td class=3D"vendor-product">RsyncProject--rsync</td>
    <td>Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOC= TOU) race condition in daemon file handling that allows attackers to redire=
    ct file writes outside intended directories by replacing parent directory c= omponents with symbolic links. Attackers with write access to a module path=
    can exploit this race condition to create or overwrite arbitrary files, po= tentially modifying sensitive system files and achieving privilege escalati=
    on when the daemon runs with elevated privileges. This vulnerability can on=
    ly be triggered if the chroot setting is false.</td>
    <td>2026-05-20</td>
    <td>7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29518" target=3D= "_blank" rel=3D"noopener">CVE-2026-29518</a></td>
    </tr>

    <td class=3D"vendor-product">ruby-lang--Ruby</td>
    <td>An issue was discovered in Ruby 4 before 4.0.5. A race condition leadin=
    g to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_= getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can del=
    ay DNS responses near the user-specified timeout to crash a Ruby process th=
    at calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_time= out:). Memory-corruption-based exploitation is theoretically possible. The = attack could, for example, be carried out through a crafted authoritative D=
    NS server or recursive resolver.</td>
    <td>2026-05-22</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46727" target=3D= "_blank" rel=3D"noopener">CVE-2026-46727</a></td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td>
    <td>Use after free vulnerability in Samsung Open Source Escargot allows Poi= nter Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846c= e6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47310" target=3D= "_blank" rel=3D"noopener">CVE-2026-47310</a></td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td>
    <td>Heap-based buffer overflow vulnerability in Samsung Open Source Escargo=
    t allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da= 850d846ce6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47311" target=3D= "_blank" rel=3D"noopener">CVE-2026-47311</a></td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td> <td>Out-of-bounds write vulnerability in Samsung Open Source Escargot allow=
    s Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846= ce6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47314" target=3D= "_blank" rel=3D"noopener">CVE-2026-47314</a></td>
    </tr>

    <td class=3D"vendor-product">SigmaPlugin--Advanced Database Cleaner Premium= </td>
    <td>The Advanced Database Cleaner - Premium plugin for WordPress is vulnera= ble to Local File Inclusion in versions up to, and including, 4.1.0 via the=
    'template' parameter. This makes it possible for authenticated attackers, = with Subscriber-level access and above, to include and execute arbitrary .p=
    hp files on the server, allowing the execution of any PHP code in those fil= es. This can be used to bypass access controls, obtain sensitive data, or a= chieve code execution in cases where .php file types can be uploaded and in= cluded.</td>
    <td>2026-05-20</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7522" target=3D"= _blank" rel=3D"noopener">CVE-2026-7522</a></td>
    </tr>

    <td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
    <td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Versions 0.6.36 through=
    0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an a= uthenticated attacker can determine the session_id of another user's sessio=
    n, they can take it over, reading any messages in it and locking the legiti= mate user out. The PATCH /sessions/{session_id}/assign-user endpoint authen= ticates the caller but never verifies session ownership: the service layer = invokes the session lookup with user_id=3DNone, which the data access layer=
    interprets as a privileged/system call that bypasses the ownership filter,=
    allowing any authenticated user to reassign an arbitrary session to themse= lves. This issue has been patched in version 0.6.51.</td>
    <td>2026-05-18</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-30950" target=3D= "_blank" rel=3D"noopener">CVE-2026-30950</a></td>
    </tr>

    <td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
    <td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Versions 0.4.2 through = 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through=
    the server due to uncontrolled disk space consumption. The download_agent_= file endpoint creates persistent temporary files for every request but fail=
    s to delete them after they are served. An unauthenticated attacker can rep= eatedly call this endpoint to exhaust the server's disk space, causing the = database or other system services to fail due to "No space left on device" = errors, rendering the entire AutoGPT Platform backend unavailable to all us= ers. This issue has been patched in version 0.6.52.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33232" target=3D= "_blank" rel=3D"noopener">CVE-2026-33232</a></td>
    </tr>

    <td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
    <td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. In versions 0.6.34 thro= ugh 0.6.51, the backend deserializes Redis cache bytes using pickle.loads w= ithout integrity/authenticity checks. The write path serializes values with=
    pickle.dumps(...) into Redis and the read path blindly invokes pickle.load= s(...) on bytes with no HMAC/signature or strict schema validation gating d= eserialization. If an attacker can poison a shared-cache key in Redis, arbi= trary command execution is possible in the backend container context, affec= ting confidentiality, integrity, and availability. This issue has been fixe=
    d in version 0.6.52.</td>
    <td>2026-05-19</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33233" target=3D= "_blank" rel=3D"noopener">CVE-2026-33233</a></td>
    </tr>

    <td class=3D"vendor-product">Sipp--SIPp</td>
    <td>SIPp 3.6 and earlier contains a local buffer overflow vulnerability in = command-line argument handling that allows local attackers to crash the app= lication or execute arbitrary code. Attackers can trigger the vulnerability=
    by supplying oversized input to the -3pcc, -i, or -log_file parameters, ca= using strcpy to write beyond buffer boundaries in sipp.cpp.</td> <td>2026-05-23</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25356" target=3D= "_blank" rel=3D"noopener">CVE-2018-25356</a></td>
    </tr>

    <td class=3D"vendor-product">Sitemio Information Technologies Trade Ltd. Co= .--WISECP</td>
    <td>Cross-Site request forgery (CSRF) vulnerability in Sitemio Information = Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This = issue affects WISECP: through 20022026.=C2=A0NOTE: The vendor was contacted=
    early about this disclosure but did not respond in any way.</td> <td>2026-05-20</td>
    <td>8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-11954" target=3D= "_blank" rel=3D"noopener">CVE-2025-11954</a></td>
    </tr>

    <td class=3D"vendor-product">SourceCodester--Hospitals Patient Records Mana= gement System</td>
    <td>A flaw has been found in SourceCodester Hospitals Patient Records Manag= ement System 1.0. The impacted element is an unknown function of the file /= classes/Master.php?f=3Dsave_patient_history. This manipulation of the argum= ent ID causes sql injection. The attack is possible to be carried out remot= ely. The exploit has been published and may be used.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9355" target=3D"= _blank" rel=3D"noopener">CVE-2026-9355</a></td>
    </tr>

    <td class=3D"vendor-product">SourceCodester--Hospitals Patient Records Mana= gement System</td>
    <td>A vulnerability has been found in SourceCodester Hospitals Patient Reco= rds Management System 1.0. This affects an unknown function of the file /ad= min/patients/manage_history.php. Such manipulation of the argument ID leads=
    to sql injection. The attack may be performed from remote. The exploit has=
    been disclosed to the public and may be used.</td>
    <td>2026-05-24</td>
    <td>7.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9356" target=3D"= _blank" rel=3D"noopener">CVE-2026-9356</a></td>
    </tr>

    <td class=3D"vendor-product">Splunk--Splunk Enterprise</td>
    <td>In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud=
    Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.= 2503.13, a user with a role that has access to the `_internal` index could = view session cookies and response bodies that contain sensitive data.</td> <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20239" target=3D= "_blank" rel=3D"noopener">CVE-2026-20239</a></td>
    </tr>

    <td class=3D"vendor-product">Splunk--Splunk Enterprise</td>
    <td>In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12,=
    and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.25= 10.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user = that does not hold the 'admin' or 'power' Splunk roles could cause a Denial=
    of Service by exploiting the `coldToFrozen.sh` script in the `splunk_archi= ver` app to rename critical Splunk directories, making the instance non-fun= ctional.&lt;br&gt;&lt;br&gt;The Denial of Service is possible because of mi= ssing input validation in the `coldToFrozen.sh` script, which accepts arbit= rary file paths and renames them without restricting operations to safe dir= ectories.</td>
    <td>2026-05-20</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20240" target=3D= "_blank" rel=3D"noopener">CVE-2026-20240</a></td>
    </tr>

    <td class=3D"vendor-product">steipete--summarize</td>
    <td>Summarize prior to 0.15.1 contains a path traversal vulnerability in th=
    e /v1/summarize daemon endpoint that allows authenticated callers to write = files to arbitrary directories by supplying an absolute path or directory t= raversal sequence in the slidesDir request parameter. Attackers can exploit=
    this to write slide_*.png and slides.json files to any writable directory = and subsequently delete matching files at the specified location through re= peat extraction.</td>
    <td>2026-05-18</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45242" target=3D= "_blank" rel=3D"noopener">CVE-2026-45242</a></td>
    </tr>

    <td class=3D"vendor-product">steipete--summarize</td>
    <td>Summarize prior to 0.15.1 contains a vulnerability in the hover summary=
    feature that allows malicious pages to dispatch synthetic mouseover events=
    over attacker-controlled links, causing the extension to make authenticate=
    d daemon requests using stored tokens without verifying event trustworthine= ss. Attackers can place local or private-network URLs behind hoverable link=
    s to route authenticated requests through the daemon, potentially accessing=
    sensitive internal endpoints when users interact with attacker-controlled = content.</td>
    <td>2026-05-18</td>
    <td>7.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45245" target=3D= "_blank" rel=3D"noopener">CVE-2026-45245</a></td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.= 21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the = grid tile compositing, allowing an attacker to write 64 bytes of fully atta= cker-controlled data past the end of a chroma plane heap allocation by craf= ting a HEIF/AVIF file with a 1=C3=83=E2=80=944 grid of odd-height tiles. Th=
    e overflow is triggered during normal image decoding with default build con= figuration. The written bytes are chroma (Cb/Cr) pixel values from the atta= cking tile, giving the attacker full control over the overflow content. Thi=
    s issue has been fixed in version 1.22.0.</td>
    <td>2026-05-19</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32740" target=3D= "_blank" rel=3D"noopener">CVE-2026-32740</a></td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.= 21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mas= k_image(). When decoding a HEIF file containing a mask image (mski), the fu= nction copies the full iloc extent data into a pixel buffer using memcpy(ds=
    t, data.data(), data.size()). The copy length data.size() is determined by = the iloc extent in the file (attacker-controlled), while the destination bu= ffer is sized based on the declared image dimensions. Because no upper-boun=
    d check exists on the data length, a crafted file whose iloc extent exceeds=
    the pixel buffer allocation overflows the heap. The vulnerable single-memc=
    py branch is reached when the mskC property specifies bits_per_pixel =3D 8 = and the ispe property declares an even width =C3=A2=E2=80=B0=C2=A5 64 (so t= hat stride =3D=3D width), with no changes to default security limits or ext= ernal codec plugins required. This issue has been fixed in version 1.22.0.<=

    <td>2026-05-19</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32741" target=3D= "_blank" rel=3D"noopener">CVE-2026-32741</a></td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.= 21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay()=
    in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose c= hild image has a different bit depth for the alpha channel than for the col=
    or channels, the function indexes into the alpha plane using the color chan= nel stride (in_stride) instead of the previously retrieved alpha_stride, ca= using reads past the end of the alpha buffer (up to 3,123 bytes for a 100= =C3=83=E2=80=9450 image with 10-bit color and 8-bit alpha). A crafted HEIF = file can exploit this to cause a denial of service (crash) or potentially d= isclose adjacent heap memory through leaked bytes embedded in the decoded o= utput pixels. This issue has been fixed in versionThis issue has been fixed=
    in version 1.22.0.</td>
    <td>2026-05-19</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32882" target=3D= "_blank" rel=3D"noopener">CVE-2026-32882</a></td>
    </tr>

    <td class=3D"vendor-product">SUSE--Container suse/sle-micro-rancher/5.3:lat= est</td>
    <td>In `src/havegecmd.c`, the `socket_handler` function performs a credenti=
    al check on the abstract UNIX socket (` /sys/entropy/haveged`). However, wh= ile it detects if the connecting user is not root (`cred.uid !=3D 0`) and p= repares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execut= ion**. The code proceeds to the `switch` statement, allowing any local unpr= ivileged user to execute privileged commands such as `MAGIC_CHROOT`.</td> <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41054" target=3D= "_blank" rel=3D"noopener">CVE-2026-41054</a></td>
    </tr>

    <td class=3D"vendor-product">SUSE--SUSE Linux Enterprise</td> <td>`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`=
    , this root is frequently `/` (the system root) in standard configurations =
    or when using `--root`. If the chroot target is `/`, it is a no-op, allowin=
    g the traversed path to execute host binaries (like `/bin/bash`) with root = privileges.</td>
    <td>2026-05-20</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44933" target=3D= "_blank" rel=3D"noopener">CVE-2026-44933</a></td>
    </tr>

    <td class=3D"vendor-product">syslink software AG--Avantra</td>
    <td>Insufficient session expiration vulnerability in syslink software AG Av= antra on Linux, Windows allows Reusing Session IDs (aka Session Replay). Th=
    is issue affects Avantra: before 25.3.1.</td>
    <td>2026-05-22</td>
    <td>9.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8670" target=3D"= _blank" rel=3D"noopener">CVE-2026-8670</a></td>
    </tr>

    <td class=3D"vendor-product">syslink software AG--Avantra</td>
    <td>Insertion of sensitive information into log file vulnerability in sysli=
    nk software AG Avantra on Linux, Windows allows Resource Leak Exposure. Thi=
    s issue affects Avantra: before 25.3.0.</td>
    <td>2026-05-22</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8671" target=3D"= _blank" rel=3D"noopener">CVE-2026-8671</a></td>
    </tr>

    <td class=3D"vendor-product">Taiko Network Communications Pte Ltd.--AG1000-= 01A SMS Alert Gateway</td>
    <td>Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-co= ded credential vulnerability in the embedded web configuration interface wh= ere authentication is implemented entirely in client-side JavaScript in log= in.zhtml, exposing static plaintext credentials in the page source. Unauthe= nticated attackers with network access can recover administrative credentia=
    ls directly from the client-side validate() function to obtain full adminis= trative access to the device.</td>
    <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9139" target=3D"= _blank" rel=3D"noopener">CVE-2026-9139</a></td>
    </tr>

    <td class=3D"vendor-product">Taiko Network Communications Pte Ltd.--AG1000-= 01A SMS Alert Gateway</td>
    <td>Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authen= tication bypass vulnerability in the embedded web configuration interface t= hat allows unauthenticated attackers to access internal application pages w= ithout any session management or server-side authentication checks. Attacke=
    rs with network access can directly request internal resources such as inde= x.zhtml, point.zhtml, and log.shtml to gain full administrative read and wr= ite access, enabling unauthorized modification of alarm routing, device con= figuration, and disruption of monitoring and control functions.</td> <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9141" target=3D"= _blank" rel=3D"noopener">CVE-2026-9141</a></td>
    </tr>

    <td class=3D"vendor-product">Taiko Network Communications Pte Ltd.--AG1000-= 01A SMS Alert Gateway</td>
    <td>Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored = cross-site scripting vulnerability in the embedded web configuration interf= ace that allows authenticated attackers to execute persistent JavaScript by=
    fragmenting malicious payloads across multiple administrative form fields.=
    Attackers can bypass front-end length restrictions using JavaScript commen=
    ts and template literals to concatenate executable script fragments that ar=
    e rendered in administrative dashboard views such as index.zhtml, resulting=
    in persistent script execution within administrative sessions.</td> <td>2026-05-20</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9144" target=3D"= _blank" rel=3D"noopener">CVE-2026-9144</a></td>
    </tr>

    <td class=3D"vendor-product">Talend--Talend Administration Center</td>
    <td>A broken access control issue has been identified in the Talend Adminis= tration Center, that allows a user with "View" permission to modify the Tal= end Studio update URL. This issue was resolved in a patch, which is already=
    available.</td>
    <td>2026-05-20</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9057" target=3D"= _blank" rel=3D"noopener">CVE-2026-9057</a></td>
    </tr>

    <td class=3D"vendor-product">tenable--Terrascan</td>
    <td>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forge=
    ry (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1= /{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. A=
    n unauthenticated remote attacker can supply an arbitrary URL as the webhoo= k_url multipart form parameter. After scanning the uploaded file, Terrascan=
    sends an HTTP POST request to the attacker-controlled URL containing the f= ull scan results as a JSON body, with the attacker-supplied webhook_token f= orwarded as a Bearer token in the Authorization header. The retryable HTTP = client retries up to 10 times on failure. This affects deployments running = terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no=
    authentication. Note: Terrascan was archived in August 2023 and no patch w= ill be released.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47356" target=3D= "_blank" rel=3D"noopener">CVE-2026-47356</a></td>
    </tr>

    <td class=3D"vendor-product">tenable--Terrascan</td>
    <td>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forge=
    ry (SSRF) via the remote_url parameter in the remote directory scan endpoin=
    t (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in ser= ver mode. An unauthenticated remote attacker can supply an attacker-control= led HTTP URL as remote_url with remote_type set to "http". The URL is passe=
    d directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's = HttpGetter supports the X-Terraform-Get response header, allowing the attac= ker's server to redirect the download to a file:// URL, enabling local file=
    read. Additionally, HttpGetter has Netrc set to true, causing it to read ~= /.netrc and send stored credentials to attacker-controlled hostnames. This = affects deployments running terrascan in server mode (terrascan server), wh= ich binds to 0.0.0.0 with no authentication. Note: Terrascan was archived i=
    n August 2023 and no patch will be released.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47357" target=3D= "_blank" rel=3D"noopener">CVE-2026-47357</a></td>
    </tr>

    <td class=3D"vendor-product">tenable--Terrascan</td>
    <td>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forge=
    ry (SSRF) via external URL resolution in uploaded IaC templates when runnin=
    g in server mode. When Terrascan parses uploaded ARM templates or CloudForm= ation templates, it resolves external URLs referenced within those template=
    s via hashicorp/go-getter with all default detectors enabled, including Fil= eDetector. An unauthenticated remote attacker can upload an ARM template co= ntaining a templateLink.uri or parametersLink.uri field, or a CloudFormatio=
    n template containing an AWS::CloudFormation::Stack TemplateURL field, poin= ting to an attacker-controlled URL. Terrascan will fetch the attacker-contr= olled URL server-side. Unlike SSRF via the remote scan endpoint, file:// UR=
    Ls are directly usable without requiring an X-Terraform-Get redirect, enabl= ing local file read. This affects deployments running terrascan in server m= ode (terrascan server), which binds to 0.0.0.0 with no authentication. Note=
    : Terrascan was archived in August 2023 and no patch will be released.</td> <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47358" target=3D= "_blank" rel=3D"noopener">CVE-2026-47358</a></td>
    </tr>

    <td class=3D"vendor-product">Tenda--F456</td>
    <td>A security vulnerability has been detected in Tenda F456 1.0.0.5. This = affects the function frmL7ImForm of the file /goform/L7Im. The manipulation=
    of the argument page leads to buffer overflow. The attack can be initiated=
    remotely. The exploit has been disclosed publicly and may be used.</td> <td>2026-05-24</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9389" target=3D"= _blank" rel=3D"noopener">CVE-2026-9389</a></td>
    </tr>

    <td class=3D"vendor-product">themefusion--Avada (Fusion) Builder</td>
    <td>The Avada Builder (fusion-builder) plugin for WordPress is vulnerable t=
    o Unauthenticated Remote Code Execution via PHP Function Injection in versi= ons up to and including 3.15.2. This is due to the `wp_conditional_tags` ca=
    se in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attac= ker-controlled values from a base64-decoded JSON blob directly to `call_use= r_func()` without any allowlist validation. This is exploitable by unauthen= ticated attackers through the `fusion_get_widget_markup` AJAX endpoint, whi=
    ch is registered for non-privileged (unauthenticated) users via `wp_ajax_no= priv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (= `fusion_load_nonce`), but this nonce is generated for user ID 0 and is dete= rministically exposed in the JavaScript output of any public-facing page co= ntaining a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusio= n_table_of_contents]`) element. This makes it possible for unauthenticated = attackers to execute arbitrary code on affected sites.</td>
    <td>2026-05-21</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6279" target=3D"= _blank" rel=3D"noopener">CVE-2026-6279</a></td>
    </tr>

    <td class=3D"vendor-product">themeum--Kirki Freeform Page Builder, Website = Builder &amp; Customizer</td>
    <td>The Kirki - Freeform Page Builder, Website Builder &amp; Customizer plu= gin for WordPress is vulnerable to arbitrary file deletion due to insuffici= ent file path validation and missing capability check in the 'downloadZIP' = function in all versions up to, and including, 6.0.6. This makes it possibl=
    e for unauthenticated attackers to read and delete arbitrary files limited =
    in the WordPress uploads base directory.</td>
    <td>2026-05-19</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8073" target=3D"= _blank" rel=3D"noopener">CVE-2026-8073</a></td>
    </tr>

    <td class=3D"vendor-product">themewant--Easy Elements for Elementor Addons = &amp; Website Templates</td>
    <td>The Easy Elements for Elementor - Addons &amp; Website Templates plugin=
    for WordPress is vulnerable to privilege escalation via user registration =
    in all versions up to, and including, 1.4.4. This is due to the 'easyel_han= dle_register' function not restricting what user roles a user can register = with. This makes it possible for unauthenticated attackers to supply the 'a= dministrator' role during registration and gain administrator access to the=
    site.</td>
    <td>2026-05-20</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7284" target=3D"= _blank" rel=3D"noopener">CVE-2026-7284</a></td>
    </tr>

    <td class=3D"vendor-product">themewant--Easy Elements for Elementor Addons = &amp; Website Templates</td>
    <td>The Easy Elements for Elementor - Addons &amp; Website Templates plugin=
    for WordPress is vulnerable to Privilege Escalation in all versions up to,=
    and including, 1.4.5 via the `easyel_handle_register()` function. This is = due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacke= r-controlled `custom_meta` POST array and writing every supplied key-value = pair to the newly created user's meta via `update_user_meta()` without any = key whitelist or blocklist, allowing the `wp_capabilities` user meta key to=
    be overwritten after `wp_insert_user()` has already assigned a safe role. = This makes it possible for unauthenticated attackers to register a new acco= unt with full administrator-level privileges by supplying `custom_meta[wp_c= apabilities][administrator]=3D1`. Exploitation requires that user registrat= ion is enabled on the site and that at least one page exposes the Login/Reg= ister widget, which publishes the required `easy_elements_nonce` into the p= age DOM where it can be retrieved by any unauthenticated visitor via a simp=
    le GET request.</td>
    <td>2026-05-22</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9018" target=3D"= _blank" rel=3D"noopener">CVE-2026-9018</a></td>
    </tr>

    <td class=3D"vendor-product">TONNET--TPR7308</td>
    <td>E-LAN Hybrid Recording System developed by TONNET has a SQL Injection v= ulnerability, allowing unauthenticated remote attackers to inject arbitrary=
    SQL commands to read database contents.</td>
    <td>2026-05-20</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9003" target=3D"= _blank" rel=3D"noopener">CVE-2026-9003</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This=
    vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cs= tecgi.cgi of the component Web Management Interface. The manipulation of th=
    e argument ip results in os command injection. The attack can be executed r= emotely. The exploit has been made public and could be used.</td> <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9384" target=3D"= _blank" rel=3D"noopener">CVE-2026-9384</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521.=
    This issue affects the function setTracerouteCfg of the file /cgi-bin/cste= cgi.cgi of the component Web Management Interface. This manipulation of the=
    argument command causes os command injection. The attack is possible to be=
    carried out remotely. The exploit has been publicly disclosed and may be u= tilized.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9385" target=3D"= _blank" rel=3D"noopener">CVE-2026-9385</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521.=
    Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi o=
    f the component Web Management Interface. Such manipulation of the argument=
    lang leads to os command injection. The attack may be performed from remot=
    e. The exploit is publicly available and might be used.</td> <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9386" target=3D"= _blank" rel=3D"noopener">CVE-2026-9386</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b2020= 0521. The affected element is the function setUpgradeFW of the file /cgi-bi= n/cstecgi.cgi of the component Web Management Interface. Performing a manip= ulation of the argument resetFlags results in os command injection. It is p= ossible to initiate the attack remotely. The exploit has been released to t=
    he public and may be used for attacks.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9387" target=3D"= _blank" rel=3D"noopener">CVE-2026-9387</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521.=
    The impacted element is the function setScheduleCfg of the file /cgi-bin/c= stecgi.cgi of the component Web Management Interface. Executing a manipulat= ion of the argument mode can lead to os command injection. It is possible t=
    o launch the attack remotely. The exploit has been made available to the pu= blic and could be used for attacks.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9388" target=3D"= _blank" rel=3D"noopener">CVE-2026-9388</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521.=
    This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of t=
    he component Web Management Interface. Such manipulation of the argument pr= ovider leads to os command injection. The attack may be launched remotely. = The exploit is publicly available and might be used.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9404" target=3D"= _blank" rel=3D"noopener">CVE-2026-9404</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b2020= 0521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecg= i.cgi of the component Web Management Interface. Performing a manipulation =
    of the argument enable results in os command injection. Remote exploitation=
    of the attack is possible. The exploit has been released to the public and=
    may be used for attacks.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9405" target=3D"= _blank" rel=3D"noopener">CVE-2026-9405</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521.=
    Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of = the component Web Management Interface. Executing a manipulation of the arg= ument enable can lead to os command injection. The attack can be executed r= emotely. The exploit has been made available to the public and could be use=
    d for attacks.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9406" target=3D"= _blank" rel=3D"noopener">CVE-2026-9406</a></td>
    </tr>

    <td class=3D"vendor-product">Totolink--A8000RU</td>
    <td>A security vulnerability has been detected in Totolink A8000RU 7.1cu.64= 3_b20200521. Affected by this vulnerability is the function setFirewallType=
    of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface=
    . The manipulation of the argument firewallType leads to os command injecti= on. The attack is possible to be carried out remotely. The exploit has been=
    disclosed publicly and may be used.</td>
    <td>2026-05-24</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9407" target=3D"= _blank" rel=3D"noopener">CVE-2026-9407</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>A vulnerability in the Trend Micro Apex One management console could al= low a remote attacker to upload malicious code and execute commands on affe= cted installations. Please note: although this vulnerability carries a tech= nical critical CVSS rating, this was reported via responsible disclosure vi=
    a a researcher through the Zero Day Initiative. The SaaS versions of the pr= oduct have already been mitigated and no customer action required. For this=
    particular vulnerability, an attacker must have access to the Trend Micro = Apex One Management Console, so customers that have their console=C3=AF=C2= =BF=C2=BDs IP address exposed externally should consider mitigating factors=
    such as source restrictions if not already applied.</td>
    <td>2026-05-21</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71210" target=3D= "_blank" rel=3D"noopener">CVE-2025-71210</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>A vulnerability in the Trend Micro Apex One management console could al= low a remote attacker to upload malicious code and execute commands on affe= cted installations. This vulnerability is similar in scope to CVE-2025-7121=
    0 but affects a different executable. Please note: although this vulnerabil= ity carries a technical critical CVSS rating, this was reported via respons= ible disclosure via a researcher through the Zero Day Initiative. The SaaS = versions of the product have already been mitigated and no customer action = required. For this particular vulnerability, an attacker must have access t=
    o the Trend Micro Apex One Management Console, so customers that have their=
    console=C3=AF=C2=BF=C2=BDs IP address exposed externally should consider m= itigating factors such as source restrictions if not already applied.</td> <td>2026-05-21</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71211" target=3D= "_blank" rel=3D"noopener">CVE-2025-71211</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>A link following vulnerability in the Trend Micro Apex One scan engine = could allow a local attacker to escalate privileges on affected installatio= ns. Please note: an attacker must first obtain the ability to execute low-p= rivileged code on the target system in order to exploit this vulnerability.= </td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71212" target=3D= "_blank" rel=3D"noopener">CVE-2025-71212</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation error vulnerability in Trend Micro Apex One could = allow a local attacker to escalate privileges on affected installations. Pl= ease note: an attacker must first obtain the ability to execute low-privile= ged code on the target system in order to exploit this vulnerability.</td> <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71213" target=3D= "_blank" rel=3D"noopener">CVE-2025-71213</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation vulnerability in the Apex One/SEP agent could allo=
    w a local attacker to escalate privileges on affected installations. Please=
    note: an attacker must first obtain the ability to execute low-privileged = code on the target system in order to exploit this vulnerability.</td> <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34927" target=3D= "_blank" rel=3D"noopener">CVE-2026-34927</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation vulnerability in the Apex One/SEP agent could allo=
    w a local attacker to escalate privileges on affected installations. This i=
    s similar to CVE-2026-34927 but exists in a different named pipe communicat= ion mechanism. Please note: an attacker must first obtain the ability to ex= ecute low-privileged code on the target system in order to exploit this vul= nerability.</td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34928" target=3D= "_blank" rel=3D"noopener">CVE-2026-34928</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation vulnerability in the Apex One/SEP agent could allo=
    w a local attacker to escalate privileges on affected installations. This i=
    s similar to CVE-2026-34927 but exists in a different inter-process communi= cation mechanism. Please note: an attacker must first obtain the ability to=
    execute low-privileged code on the target system in order to exploit this = vulnerability.</td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34929" target=3D= "_blank" rel=3D"noopener">CVE-2026-34929</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation vulnerability in the Apex One/SEP agent could allo=
    w a local attacker to escalate privileges on affected installations. This i=
    s similar to CVE-2026-34927 but exists in a different process protection me= chanism. Please note: an attacker must first obtain the ability to execute = low-privileged code on the target system in order to exploit this vulnerabi= lity.</td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34930" target=3D= "_blank" rel=3D"noopener">CVE-2026-34930</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation vulnerability in the Apex One/SEP agent could allo=
    w a local attacker to escalate privileges on affected installations. This i=
    s similar to CVE-2026-45207 but exists in a different process protection co= mmunication mechanism. Please note: an attacker must first obtain the abili=
    ty to execute low-privileged code on the target system in order to exploit = this vulnerability.</td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45206" target=3D= "_blank" rel=3D"noopener">CVE-2026-45206</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>An origin validation vulnerability in the Apex One/SEP agent could allo=
    w a local attacker to escalate privileges on affected installations. This i=
    s similar to CVE-2026-45206 but exists in a different process protection co= mmunication mechanism. Please note: an attacker must first obtain the abili=
    ty to execute low-privileged code on the target system in order to exploit = this vulnerability.</td>
    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45207" target=3D= "_blank" rel=3D"noopener">CVE-2026-45207</a></td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>A time-of-check time-of-use vulnerability in the Apex One/SEP agent cou=
    ld allow a local attacker to escalate privileges on affected installations.=
    Please note: an attacker must first obtain the ability to execute low-priv= ileged code on the target system in order to exploit this vulnerability.</t=

    <td>2026-05-21</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45208" target=3D= "_blank" rel=3D"noopener">CVE-2026-45208</a></td>
    </tr>

    <td class=3D"vendor-product">TriliumNext--Trilium</td>
    <td>Trilium Notes is a cross-platform, hierarchical note taking application=
    focused on building large personal knowledge bases. In versions 0.102.1 an=
    d prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authenti= cation bypass when running in an Electron environment. When Trilium detects=
    an Electron environment, it explicitly disables authentication middleware = for the Clipper API, exposing endpoints such as /api/clipper/notes to the n= etwork with no password, API token, or CSRF protection. An attacker on a sh= ared network (for example, a corporate LAN or public Wi-Fi) can scan for op=
    en high-range ports using a tool like nmap, since Trilium often binds to po= rts such as 37840. Once a candidate port is found, an unauthenticated reque=
    st to the Clipper handshake endpoint, which also bypasses authentication, c= onfirms a Trilium instance by returning the application name and protocol v= ersion. This facilitates unauthorized data access, phishing, and local syst=
    em compromise. The issue has been fixed in version 0.102.2.</td> <td>2026-05-20</td>
    <td>8.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39310" target=3D= "_blank" rel=3D"noopener">CVE-2026-39310</a></td>
    </tr>

    <td class=3D"vendor-product">twigphp--Twig</td>
    <td>Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass = vulnerability when using a SourcePolicyInterface that allows attackers with=
    template rendering capabilities to pass arbitrary PHP callables to sort, f= ilter, map, and reduce filters. Attackers can exploit the runtime check tha=
    t fails to use the current template source to bypass sandbox restrictions a=
    nd execute arbitrary code when the sandbox is enabled through a source poli=
    cy rather than globally.</td>
    <td>2026-05-20</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24425" target=3D= "_blank" rel=3D"noopener">CVE-2026-24425</a></td>
    </tr>

    <td class=3D"vendor-product">Tyler Technologies--TID-L</td>
    <td>Tyler Identity Local (TID-L) uses documented, default administrative cr= edentials. Users are not required to change the credentials before deployme= nt. TID-L has not been distributed since December 2020, and has not been su= pported since 2021.</td>
    <td>2026-05-19</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44159" target=3D= "_blank" rel=3D"noopener">CVE-2026-44159</a></td>
    </tr>

    <td class=3D"vendor-product">Ubiquiti Inc--UniFi OS Server</td>
    <td>A malicious actor with access to the network could exploit an Improper = Access Control vulnerability found in UniFi OS devices to make unauthorized=
    changes to the system.</td>
    <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34908" target=3D= "_blank" rel=3D"noopener">CVE-2026-34908</a></td>
    </tr>

    <td class=3D"vendor-product">Ubiquiti Inc--UniFi OS Server</td>
    <td>A malicious actor with access to the network could exploit a Path Trave= rsal vulnerability found in UniFi OS devices to access files on the underly= ing system that could be manipulated to access an underlying account.</td> <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34909" target=3D= "_blank" rel=3D"noopener">CVE-2026-34909</a></td>
    </tr>

    <td class=3D"vendor-product">Ubiquiti Inc--UniFi OS Server</td>
    <td>A malicious actor with access to the network could exploit an Improper = Input Validation vulnerability found in UniFi OS devices to execute a Comma=
    nd Injection.</td>
    <td>2026-05-22</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34910" target=3D= "_blank" rel=3D"noopener">CVE-2026-34910</a></td>
    </tr>

    <td class=3D"vendor-product">Ubiquiti Inc--UniFi OS Server</td>
    <td>A malicious actor with access to the network and high privileges could = exploit an Improper Input Validation vulnerability found in UniFi OS device=
    s to execute a Command Injection.</td>
    <td>2026-05-22</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33000" target=3D= "_blank" rel=3D"noopener">CVE-2026-33000</a></td>
    </tr>

    <td class=3D"vendor-product">Ubiquiti Inc--UniFi OS Server</td>
    <td>A malicious actor with access to the network and low privileges could e= xploit a Path Traversal vulnerability found in UniFi OS devices to access f= iles on the underlying system that could be manipulated to obtain sensitive=
    information.</td>
    <td>2026-05-22</td>
    <td>7.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34911" target=3D= "_blank" rel=3D"noopener">CVE-2026-34911</a></td>
    </tr>

    <td class=3D"vendor-product">ultimate-form-builder-lite--Ultimate Form Buil= der Lite</td>
    <td>WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below con= tains an SQL injection vulnerability that allows authenticated attackers to=
    manipulate database queries by injecting SQL code through the entry_id POS=
    T parameter. Attackers can send POST requests to the admin-ajax.php endpoin=
    t with the ufbl_get_entry_detail_action action to extract, modify, or escal= ate privileges within the WordPress database.</td>
    <td>2026-05-23</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25352" target=3D= "_blank" rel=3D"noopener">CVE-2018-25352</a></td>
    </tr>

    <td class=3D"vendor-product">UserSpice--userSpice</td>
    <td>userSpice 4.3.24 contains a username enumeration vulnerability that all= ows unauthenticated attackers to discover valid usernames by sending POST r= equests to the existingUsernameCheck.php endpoint. Attackers can submit use= rnames and analyze response text for the 'taken' string to identify existin=
    g accounts in the system.</td>
    <td>2026-05-23</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25350" target=3D= "_blank" rel=3D"noopener">CVE-2018-25350</a></td>
    </tr>

    <td class=3D"vendor-product">web-dorado--Contact Form Maker</td>
    <td>WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vuln= erabilities that allow authenticated attackers to manipulate database queri=
    es through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attac= kers can inject malicious SQL code via the 'name' and 'search_labels' param= eters to extract sensitive database information or escalate privileges.</td=

    <td>2026-05-23</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25347" target=3D= "_blank" rel=3D"noopener">CVE-2018-25347</a></td>
    </tr>

    <td class=3D"vendor-product">webdriverio--webdriverio</td>
    <td>WebdriverIO is a test automation framework for unit, e2e and component = testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 c= ontain a command injection vulnerability leading to remote code execution (= RCE) in test orchestration. Git permits branch names containing shell metac= haracters, and getGitMetadataForAISelection() interpolates these names dire= ctly into execSync() calls without sanitization. An attacker can exploit th=
    is by supplying a malicious repository (via testOrchestrationOptions.runSma= rtSelection.source, or the current directory if unset) whose branch name ca= rries a payload, causing the shell to execute arbitrary code. This enables = remote code execution on CI/CD servers and developer machines, leading to c= redential and secret disclosure, source code and SSH key exfiltration, syst=
    em compromise, and supply chain attacks via tampered build artifacts. The i= ssue has been fixed in version 9.24.0.</td>
    <td>2026-05-18</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25244" target=3D= "_blank" rel=3D"noopener">CVE-2026-25244</a></td>
    </tr>

    <td class=3D"vendor-product">weDevs--WP ERP Pro</td>
    <td>The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via = the 'search_key' parameter in all versions up to, and including, 1.5.1. Thi=
    s is due to insufficient escaping on the user supplied parameter and lack o=
    f sufficient preparation on the existing SQL query. This makes it possible = for unauthenticated attackers to append additional SQL queries into already=
    existing queries that can be used to extract sensitive information from th=
    e database.</td>
    <td>2026-05-22</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4834" target=3D"= _blank" rel=3D"noopener">CVE-2026-4834</a></td>
    </tr>

    <td class=3D"vendor-product">windmill-labs--windmill</td>
    <td>Windmill prior to 1.703.2 contains an incorrect default permissions vul= nerability in nsjail sandbox configuration files where /etc is bind-mounted=
    without read-write restrictions, allowing authenticated users to write arb= itrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certi= ficates.crt from within script execution sandboxes. Attackers can exploit p= ersistent poisoned entries across all subsequent script executions on the s= ame worker pod to redirect hostnames, intercept DNS queries, perform transp= arent HTTPS man-in-the-middle attacks, and intercept WM_TOKEN JWTs to gain = workspace-admin access to other users' workspaces.</td>
    <td>2026-05-19</td>
    <td>8.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47107" target=3D= "_blank" rel=3D"noopener">CVE-2026-47107</a></td>
    </tr>

    <td class=3D"vendor-product">Wishlist Member--Wishlist Member</td>
    <td>The WishList Member plugin for WordPress is vulnerable to Privilege Esc= alation via Missing Authorization in versions up to and including 3.30.1. T= his is due to the missing capability and nonce check in the ajax_get_screen=
    () function. This makes it possible for authenticated attackers, with Subsc= riber-level access and above, to supply an arbitrary admin screen identifie=
    r via the data[url] parameter, causing the plugin to load and execute the a= dministrative API configuration template without authorization. The rendere=
    d HTML, which contains the plugin's plaintext REST API Secret Key, is retur= ned directly to the attacker in the AJAX JSON response. An attacker who obt= ains this key can authenticate to the WishList Member API, create a new mem= bership level assigned the administrator WordPress role, and register an ar= bitrary administrator-level user account, resulting in complete site takeov= er.</td>
    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6419" target=3D"= _blank" rel=3D"noopener">CVE-2026-6419</a></td>
    </tr>

    <td class=3D"vendor-product">Wishlist Member--Wishlist Member</td>
    <td>The WishList Member plugin for WordPress is vulnerable to Missing Autho= rization leading to Sensitive Information Disclosure and Privilege Escalati=
    on in versions up to and including 3.30.1. This is due to the missing capab= ility checks in the 'export_settings' function. This function returns the R= EST API Secret Key to the attacker in the AJAX JSON response. An attacker w=
    ho obtains this key can authenticate to the WishList Member API, create a n=
    ew membership level assigned the administrator WordPress role, and register=
    an arbitrary administrator-level user account, resulting in complete site = takeover.</td>
    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6895" target=3D"= _blank" rel=3D"noopener">CVE-2026-6895</a></td>
    </tr>

    <td class=3D"vendor-product">Wishlist Member--Wishlist Member</td>
    <td>The Wishlist Member plugin for WordPress is vulnerable to unauthorized = modification of data due to a missing capability check on the 'WishListMemb= er\Features\Team_Accounts::save_settings' function in all versions up to, a=
    nd including, 3.30.1. This makes it possible for authenticated attackers, w= ith Subscriber-level access and above, to update arbitrary plugin options, = includes the REST API Secret Key, which can be used to create a new members= hip level assigned the administrator WordPress role, and register an arbitr= ary administrator-level user account, resulting in complete site takeover.<=

    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6897" target=3D"= _blank" rel=3D"noopener">CVE-2026-6897</a></td>
    </tr>

    <td class=3D"vendor-product">Wishlist Member--Wishlist Member</td>
    <td>The Wishlist Member plugin for WordPress is vulnerable to unauthorized = modification of data due to a missing capability check on the 'WishListMemb= er3_Hooks::generate_api_key' function in all versions up to, and including,=
    3.30.1. This makes it possible for authenticated attackers, with Subscribe= r-level access and above, to update the REST API Secret Key, which can be u= sed to create a new membership level assigned the administrator WordPress r= ole, and register an arbitrary administrator-level user account, resulting =
    in complete site takeover.</td>
    <td>2026-05-23</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6898" target=3D"= _blank" rel=3D"noopener">CVE-2026-6898</a></td>
    </tr>

    <td class=3D"vendor-product">woocommerce--WooCommerce PayPal Payments</td> <td>The WooCommerce PayPal Payments plugin for WordPress is vulnerable to u= nauthorized order manipulation and information disclosure due to missing au= thorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX en= dpoints in all versions up to, and including, 4.0.1. The `ppc-create-order`=
    endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` contex=
    t without validating order ownership, allowing attackers to create PayPal o= rders for any WC order and write PayPal metadata to it. The `ppc-get-order`=
    endpoint returns full PayPal order details for any PayPal order ID without=
    binding to the requester's session. This makes it possible for unauthentic= ated attackers to chain these endpoints to manipulate other customers' orde=
    r payment flows and exfiltrate sensitive order details (payer information, = shipping data) by creating a PayPal order for a victim's WC order and then = retrieving the PayPal order data.</td>
    <td>2026-05-23</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9284" target=3D"= _blank" rel=3D"noopener">CVE-2026-9284</a></td>
    </tr>

    <td class=3D"vendor-product">Wp Directory Kit--WP Directory Kit</td> <td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
    L Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Bli=
    nd SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5= .0.</td>
    <td>2026-05-21</td>
    <td>9.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39531" target=3D= "_blank" rel=3D"noopener">CVE-2026-39531</a></td>
    </tr>

    <td class=3D"vendor-product">WP Swings--Gift Cards For WooCommerce Pro</td> <td>Unrestricted Upload of File with Dangerous Type vulnerability in WP Swi= ngs Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue=
    affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.</td> <td>2026-05-20</td>
    <td>10</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45444" target=3D= "_blank" rel=3D"noopener">CVE-2026-45444</a></td>
    </tr>

    <td class=3D"vendor-product">yiisoft--yii2</td>
    <td>Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain=
    flawed logic in the core view rendering method View::renderPhpFile() that = leads to Local File Inclusion. The function calls extract($_params_, EXTR_O= VERWRITE) before the require statement that loads the view file. As a resul=
    t, a caller-controlled _file_ key in the $params array overwrites the inter= nal local variable specifying which file to include, potentially enabling R=
    CE if an attacker can write PHP files through a separate primitive, as well=
    as information disclosure. This issue has been fixed in version 2.0.55.</t=

    <td>2026-05-20</td>
    <td>7.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39850" target=3D= "_blank" rel=3D"noopener">CVE-2026-39850</a></td>
    </tr>

    <td class=3D"vendor-product">YITH--YITH WooCommerce Product Add-Ons</td> <td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
    L Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows=
    Blind SQL Injection. This issue affects YITH WooCommerce Product Add-Ons: = from n/a through 4.29.0.</td>
    <td>2026-05-20</td>
    <td>7.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42383" target=3D= "_blank" rel=3D"noopener">CVE-2026-42383</a></td>
    </tr>

    <td class=3D"vendor-product">ZKTeco--SSC335-GC2063-Face-0b77 Solution Camer= a</td>
    <td>An undocumented configuration export port is accessible on some models =
    of ZKTeco CCTV cameras. This port does not require authentication and expos=
    es critical information about the camera such as open services and camera a= ccount credentials.</td>
    <td>2026-05-20</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8598" target=3D"= _blank" rel=3D"noopener">CVE-2026-8598</a></td>
    </tr>

    <td class=3D"vendor-product">Zohocorp--ManageEngine ADSelfService Plus</td> <td>Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecur= ity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to=
    Authenticated Remote code execution in the agent machines due to the bug i=
    n the 3rd party dependency.</td>
    <td>2026-05-21</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2740" target=3D"= _blank" rel=3D"noopener">CVE-2026-2740</a></td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    <div id=3D"medium_v">
    <h2 id=3D"medium_v_title">Medium Vulnerabilities</h2>
    <table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Medium Vulnerabilities">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">546669204--vps-inventory-monitoring</td>
    <td>A vulnerability was determined in 546669204 vps-inventory-monitoring up=
    to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the functi=
    on eval of the file app/index/command/VpsTest.php of the component VpsTest = Console. Executing a manipulation of the argument vf can lead to code injec= tion. The attack may be performed from remote. The exploit has been publicl=
    y disclosed and may be utilized. This product utilizes a rolling release sy= stem for continuous delivery, and as such, version information for affected=
    or updated releases is not disclosed. The project was informed of the prob= lem early through an issue report but has not responded yet.</td> <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9302" target=3D"= _blank" rel=3D"noopener">CVE-2026-9302</a></td>

    <a href=3D"https://vuldb.com/vuln/365249" target=3D"_blank" rel=3D"noopener= ">VDB-365249 | 546669204 vps-inventory-monitoring VpsTest Console VpsTest.p=
    hp eval code injection</a><br><a href=3D"https://vuldb.com/vuln/365249/cti"=
    target=3D"_blank" rel=3D"noopener">VDB-365249 | CTI Indicators (IOB, IOC, = TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/811843" target=3D"_bla= nk" rel=3D"noopener">Submit #811843 | 546669204 vps-inventory-monitoring &l= t;=3D98c00b3 Code Injection / Eval Injection</a><br><a href=3D"https://gith= ub.com/546669204/vps-inventory-monitoring/issues/36" target=3D"_blank" rel= =3D"noopener">https://github.com/546669204/vps-inventory-monitoring/issues/= 36</a><br><a href=3D"https://github.com/dntyfate/cve/issues/2" target=3D"_b= lank" rel=3D"noopener">https://github.com/dntyfate/cve/issues/2</a><br><a h= ref=3D"https://github.com/546669204/vps-inventory-monitoring/" target=3D"_b= lank" rel=3D"noopener">https://github.com/546669204/vps-inventory-monitorin= g/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ADD-ONS.ORG--PDF for Elementor Forms + Drag An=
    d Drop Template Builder</td>
    <td>Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Fo= rms + Drag And Drop Template Builder allows Exploiting Incorrectly Configur=
    ed Access Control Security Levels. This issue affects PDF for Elementor For=
    ms + Drag And Drop Template Builder: from n/a through 5.5.1.</td> <td>2026-05-20</td>
    <td>5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45443" target=3D= "_blank" rel=3D"noopener">CVE-2026-45443</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/pdf-for-element= or-forms/vulnerability/wordpress-pdf-for-elementor-forms-drag-and-drop-temp= late-builder-plugin-5-5-1-broken-access-control-vulnerability?_s_id=3Dcve" = target=3D"_blank" rel=3D"noopener">https://patchstack.com/database/wordpres= s/plugin/pdf-for-elementor-forms/vulnerability/wordpress-pdf-for-elementor-= forms-drag-and-drop-template-builder-plugin-5-5-1-broken-access-control-vul= nerability?_s_id=3Dcve</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">askywhale--Games Catalog</td>
    <td>The Games Catalog plugin for WordPress is vulnerable to Cross-Site Requ= est Forgery in versions up to, and including, 1.2.0. This is due to missing=
    or incorrect nonce validation on the gc_crud() function which handles the = delete action (action=3Ddelete) via a GET request without any wp_verify_non= ce() / check_admin_referer() call. This makes it possible for unauthenticat=
    ed attackers to delete arbitrary game catalog entries (including the associ= ated WordPress post created for the game) via a forged request, granted the=
    y can trick a site administrator into performing an action such as clicking=
    on a link.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8418" target=3D"= _blank" rel=3D"noopener">CVE-2026-8418</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/0888cd= a8-63ca-44f6-a3eb-765c14a7e6c7?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/0888cda8-63c= a-44f6-a3eb-765c14a7e6c7?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/game-catalog/trunk/admin-crud.php#L94" target=3D"_b= lank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/game-cata= log/trunk/admin-crud.php#L94</a><br><a href=3D"https://plugins.trac.wordpre= ss.org/browser/game-catalog/tags/1.2.0/admin-crud.php#L94" target=3D"_blank=
    " rel=3D"noopener">https://plugins.trac.wordpress.org/browser/game-catalog/= tags/1.2.0/admin-crud.php#L94</a><br><a href=3D"https://plugins.trac.wordpr= ess.org/browser/game-catalog/trunk/admin-crud.php#L31" target=3D"_blank" re= l=3D"noopener">https://plugins.trac.wordpress.org/browser/game-catalog/trun= k/admin-crud.php#L31</a><br><a href=3D"https://plugins.trac.wordpress.org/b= rowser/game-catalog/tags/1.2.0/admin-crud.php#L31" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2= .0/admin-crud.php#L31</a><br><a href=3D"https://plugins.trac.wordpress.org/= browser/game-catalog/trunk/games-catalog.php#L96" target=3D"_blank" rel=3D"= noopener">https://plugins.trac.wordpress.org/browser/game-catalog/trunk/gam= es-catalog.php#L96</a><br><a href=3D"https://plugins.trac.wordpress.org/bro= wser/game-catalog/tags/1.2.0/games-catalog.php#L96" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/game-catalog/tags/= 1.2.0/games-catalog.php#L96</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the ge= tResultLogs API endpoint authorizes the caller against the provided typebot=
    Id but fetches logs solely by resultId without verifying that the result be= longs to the authorized typebot, leading to IDOR. An authenticated attacker=
    can supply their own typebotId alongside any victim's resultId to read exe= cution logs from other workspaces, leaking sensitive data including HTTP re= sponse bodies, AI model outputs, and webhook payloads. Every other result-s= coped endpoint in the same router properly validates that the resultId belo= ngs to the authorized typebotId. This confirms the missing check is an over= sight, not a design choice. This issue has been fixed in version 3.15.2.</t=

    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28444" target=3D= "_blank" rel=3D"noopener">CVE-2026-28444</a></td>

    <a href=3D"https://github.com/baptisteArno/typebot.io/security/advisories/G= HSA-c63p-mqx5-75r7" target=3D"_blank" rel=3D"noopener">https://github.com/b= aptisteArno/typebot.io/security/advisories/GHSA-c63p-mqx5-75r7</a><br><a hr= ef=3D"https://github.com/baptisteArno/typebot.io/commit/d82b2d47c86ae614a08= d4073c669ca64442faff2" target=3D"_blank" rel=3D"noopener">https://github.co= m/baptisteArno/typebot.io/commit/d82b2d47c86ae614a08d4073c669ca64442faff2</= a><br><a href=3D"https://github.com/baptisteArno/typebot.io/releases/tag/v3= .16.0" target=3D"_blank" rel=3D"noopener">https://github.com/baptisteArno/t= ypebot.io/releases/tag/v3.16.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTyp= ebots API endpoint returns full bot definitions to any authenticated user w=
    ho references a target bot ID in a Typebot Link block, regardless of worksp= ace ownership, leading to IDOR. The authorization check uses Array.filter()=
    with an async callback - since filter() is synchronous, the callback alway=
    s returns a truthy Promise, so the access control predicate is never actual=
    ly evaluated. Any authenticated Typebot user can read the full definition o=
    f any other workspace's private bots, including: all conversation blocks an=
    d logic flow, variable values embedded in the bot (credentials, API keys, P= II), webhook URLs and integration configurations. This issue has been fixed=
    in version 3.16.0.</td>
    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39966" target=3D= "_blank" rel=3D"noopener">CVE-2026-39966</a></td>

    <a href=3D"https://github.com/baptisteArno/typebot.io/security/advisories/G= HSA-3fr5-999r-84qj" target=3D"_blank" rel=3D"noopener">https://github.com/b= aptisteArno/typebot.io/security/advisories/GHSA-3fr5-999r-84qj</a><br><a hr= ef=3D"https://github.com/baptisteArno/typebot.io/commit/b9530a089b43bfa6e79= e3ff9cbfab921ce832f45" target=3D"_blank" rel=3D"noopener">https://github.co= m/baptisteArno/typebot.io/commit/b9530a089b43bfa6e79e3ff9cbfab921ce832f45</= a><br><a href=3D"https://github.com/baptisteArno/typebot.io/releases/tag/v3= .16.0" target=3D"_blank" rel=3D"noopener">https://github.com/baptisteArno/t= ypebot.io/releases/tag/v3.16.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the Wh= atsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsa= pp/{credentialsId}/webhook) does not verify the x-hub-signature-256 HMAC si= gnature included by Meta in every webhook delivery. The webhook URL exposes=
    both workspaceId and credentialsId as path parameters, which are logged in=
    web server access logs, visible in Meta's webhook configuration dashboard,=
    and potentially shared when configuring integrations. This allows any unau= thenticated attacker to send spoofed webhook messages to trigger bot flows,=
    consume API resources, and interact with external services using the works= pace owner's credentials. The issue has been fixed in version 3.17.0.</td> <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39969" target=3D= "_blank" rel=3D"noopener">CVE-2026-39969</a></td>

    <a href=3D"https://github.com/baptisteArno/typebot.io/security/advisories/G= HSA-8vqp-r5w7-v47f" target=3D"_blank" rel=3D"noopener">https://github.com/b= aptisteArno/typebot.io/security/advisories/GHSA-8vqp-r5w7-v47f</a><br><a hr= ef=3D"https://github.com/baptisteArno/typebot.io/releases/tag/v3.17.0" targ= et=3D"_blank" rel=3D"noopener">https://github.com/baptisteArno/typebot.io/r= eleases/tag/v3.17.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typ= ebot viewer (packages/embeds/js) renders anchor tags from rich text bubble = content without filtering the javascript: URI scheme. A bot author can set =
    a link URL to javascript:PAYLOAD, which executes in the visitor's browser c= ontext when clicked. Since the viewer is typically embedded in a third-part=
    y site, the attacker's JavaScript runs in the host page's origin and can ex= filtrate cookies and session tokens. This can result in any authenticated T= ypebot user (including those on the free tier) being able to create a bot w= ith this payload. Shared bots are publicly accessible - no victim authentic= ation is required. This issue has been resolved in version 3.16.0.</td> <td>2026-05-22</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39964" target=3D= "_blank" rel=3D"noopener">CVE-2026-39964</a></td>

    <a href=3D"https://github.com/baptisteArno/typebot.io/security/advisories/G= HSA-hqmv-v56g-4m47" target=3D"_blank" rel=3D"noopener">https://github.com/b= aptisteArno/typebot.io/security/advisories/GHSA-hqmv-v56g-4m47</a><br><a hr= ef=3D"https://github.com/baptisteArno/typebot.io/commit/2c3fc7267a5e1529ba4= b1a2ab4f1edb3e3b8990b" target=3D"_blank" rel=3D"noopener">https://github.co= m/baptisteArno/typebot.io/commit/2c3fc7267a5e1529ba4b1a2ab4f1edb3e3b8990b</= a><br><a href=3D"https://github.com/baptisteArno/typebot.io/releases/tag/v3= .16.0" target=3D"_blank" rel=3D"noopener">https://github.com/baptisteArno/t= ypebot.io/releases/tag/v3.16.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Behance--Smartshop</td>
    <td>Smartshop 1 contains a cross-site request forgery vulnerability that al= lows attackers to modify user profiles by tricking authenticated users into=
    submitting malicious requests. Attackers can craft HTML forms targeting ed= itprofile.php with hidden fields for email and password parameters that exe= cute automatically when visited by an authenticated admin user.</td> <td>2026-05-23</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25343" target=3D= "_blank" rel=3D"noopener">CVE-2018-25343</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44824" target=3D"_blank" rel= =3D"noopener">ExploitDB-44824</a><br><a href=3D"https://www.behance.net/gal= lery/49080415/Smartshop-Free-e-commerce-website" target=3D"_blank" rel=3D"n= oopener">Official Product Homepage</a><br><a href=3D"https://github.com/sma= kosh/Smartshop/archive/master.zip" target=3D"_blank" rel=3D"noopener">Produ=
    ct Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/smartsh= op-1-cross-site-request-forgery-via-editprofile-php" target=3D"_blank" rel= =3D"noopener">VulnCheck Advisory: Smartshop 1 Cross-Site Request Forgery vi=
    a editprofile.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">bentoml--BentoML</td>
    <td>BentoML is a Python library for building online serving systems optimiz=
    ed for AI apps and model inference. In versions 1.4.38 and prior, the build=
    packaging workflow follows attacker-controlled symlinks inside the build c= ontext and copies the referenced file contents into the generated Bento art= ifact. If a victim builds an untrusted repository or other attacker-supplie=
    d build context, the attacker can place a symlink such as loot.txt -&gt; /t= mp/outside-marker.txt or a link to a more sensitive local file. When bentom=
    l build runs, BentoML dereferences the symlink and packages the target file=
    contents into the Bento. The leaked file can then propagate further throug=
    h export, push, or containerization workflows. An attacker can exfiltrate l= ocal files from the build host into the Bento artifact, exposing secrets su=
    ch as cloud credentials, SSH keys, API tokens, environment files, or other = sensitive local configurations. Because Bento artifacts are commonly export= ed, uploaded, stored, or containerized after build, the leaked file content=
    s can spread beyond the original build machine. This issue has been fixed i=
    n version 1.4.39.</td>
    <td>2026-05-22</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40610" target=3D= "_blank" rel=3D"noopener">CVE-2026-40610</a></td>

    <a href=3D"https://github.com/bentoml/BentoML/security/advisories/GHSA-mcfx= -4vc6-qgxv" target=3D"_blank" rel=3D"noopener">https://github.com/bentoml/B= entoML/security/advisories/GHSA-mcfx-4vc6-qgxv</a><br><a href=3D"https://gi= thub.com/bentoml/BentoML/commit/5fb7cd41f92e2a56b45391284cf15b9ac9963a1f" t= arget=3D"_blank" rel=3D"noopener">https://github.com/bentoml/BentoML/commit= /5fb7cd41f92e2a56b45391284cf15b9ac9963a1f</a><br><a href=3D"https://github.= com/bentoml/BentoML/releases/tag/v1.4.39" target=3D"_blank" rel=3D"noopener= ">https://github.com/bentoml/BentoML/releases/tag/v1.4.39</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">bestpractical--rt</td>
    <td>RT is an open source, enterprise-grade issue and ticket tracking system=
    . Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (C= SV/formula) injection vulnerability. User-controlled data in spreadsheet ex= ports is not sanitized before being written to the output file, which can c= ause spreadsheet applications to interpret crafted values as formulas or ma= cros when the file is opened. This issue has been fixed in versions 5.0.10 = and 6.0.3. If developers are unable to upgrade immediately, they can tempor= arily work around this issue by avoiding opening exported RT spreadsheet fi= les directly in spreadsheet applications when the data may contain untruste=
    d user input.</td>
    <td>2026-05-22</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41073" target=3D= "_blank" rel=3D"noopener">CVE-2026-41073</a></td>

    <a href=3D"https://github.com/bestpractical/rt/security/advisories/GHSA-6x9= 2-7v65-7m3r" target=3D"_blank" rel=3D"noopener">https://github.com/bestprac= tical/rt/security/advisories/GHSA-6x92-7v65-7m3r</a><br><a href=3D"https://= github.com/bestpractical/rt/releases/tag/rt-5.0.10" target=3D"_blank" rel= =3D"noopener">https://github.com/bestpractical/rt/releases/tag/rt-5.0.10</a= ><br><a href=3D"https://github.com/bestpractical/rt/releases/tag/rt-6.0.3" = target=3D"_blank" rel=3D"noopener">https://github.com/bestpractical/rt/rele= ases/tag/rt-6.0.3</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">bigbluebutton--bigbluebutton</td> <td>BigBlueButton is an open-source virtual classroom. In versions prior to=
    3.0.19, the recording playback (presentation format) was not sanitizing us= er's input in public chat. This allowed for a malicious actor to craft and = carry out a targeted XSS attack, activated on anyone replaying the recordin=
    g. This issue has been fixed 3.0.19.</td>
    <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27737" target=3D= "_blank" rel=3D"noopener">CVE-2026-27737</a></td>

    <a href=3D"https://github.com/bigbluebutton/bigbluebutton/security/advisori= es/GHSA-8vv7-vj94-q2pv" target=3D"_blank" rel=3D"noopener">https://github.c= om/bigbluebutton/bigbluebutton/security/advisories/GHSA-8vv7-vj94-q2pv</a><= br><a href=3D"https://github.com/bigbluebutton/bbb-playback/commit/09e89bfe= 4ff8488b68c3ff040d3081e419dc89b1" target=3D"_blank" rel=3D"noopener">https:= //github.com/bigbluebutton/bbb-playback/commit/09e89bfe4ff8488b68c3ff040d30= 81e419dc89b1</a><br><a href=3D"https://github.com/bigbluebutton/bigbluebutt= on/commit/69f45aa1b963dc7d80179d0155acc670aec5c4fc" target=3D"_blank" rel= =3D"noopener">https://github.com/bigbluebutton/bigbluebutton/commit/69f45aa= 1b963dc7d80179d0155acc670aec5c4fc</a><br><a href=3D"https://github.com/bigb= luebutton/bigbluebutton/releases/tag/v3.0.19" target=3D"_blank" rel=3D"noop= ener">https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.19</= a><br><a href=3D"https://github.com/blindsidenetworks/scalelite/releases/ta= g/v1.7.0" target=3D"_blank" rel=3D"noopener">https://github.com/blindsidene= tworks/scalelite/releases/tag/v1.7.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Brainstorm Force--Presto Player</td>
    <td>Missing Authorization vulnerability in Brainstorm Force Presto Player a= llows Exploiting Incorrectly Configured Access Control Security Levels. Thi=
    s issue affects Presto Player: from n/a through 4.1.3.</td>
    <td>2026-05-19</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45442" target=3D= "_blank" rel=3D"noopener">CVE-2026-45442</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/presto-player/v= ulnerability/wordpress-presto-player-plugin-4-1-3-broken-access-control-vul= nerability?_s_id=3Dcve" target=3D"_blank" rel=3D"noopener">https://patchsta= ck.com/database/wordpress/plugin/presto-player/vulnerability/wordpress-pres= to-player-plugin-4-1-3-broken-access-control-vulnerability?_s_id=3Dcve</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">broadstreetads--Broadstreet</td>
    <td>The Broadstreet plugin for WordPress is vulnerable to Insecure Direct O= bject Reference in all versions up to, and including, 1.52.2 via the get_sp= onsored_meta AJAX action due to missing validation on a user controlled key=
    . This makes it possible for authenticated attackers, with Subscriber-level=
    access and above, to disclose any private post metadata.</td> <td>2026-05-21</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-1881" target=3D"= _blank" rel=3D"noopener">CVE-2026-1881</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/328ccf= 8f-797b-4b1a-b0f1-afd8e44f41e6?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/328ccf8f-797= b-4b1a-b0f1-afd8e44f41e6?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/changeset?old_path=3D%2Fbroadstreet/tags/1.52.2&new_path=3D= %2Fbroadstreet/tags/1.53.2" target=3D"_blank" rel=3D"noopener">https://plug= ins.trac.wordpress.org/changeset?old_path=3D%2Fbroadstreet/tags/1.52.2&new_= path=3D%2Fbroadstreet/tags/1.53.2</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">burlingtonbytes--WP Blockade Visual Page Build= er</td>
    <td>The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-S= ite Scripting via the 'shortcode' parameter in all versions up to and inclu= ding 0.9.14. This is due to insufficient input sanitization and output esca= ping in the render_shortcode_preview() function. The function receives user=
    input from $_GET['shortcode'], passes it through stripslashes() without an=
    y sanitization, and then outputs it directly via echo do_shortcode($shortco= de) on line 393. When the input is not a valid WordPress shortcode (e.g., a=
    n HTML tag with JavaScript event handlers), do_shortcode() returns it uncha= nged, and it is reflected into the page without escaping. The endpoint is r= egistered via admin_post_ (not admin_post_nopriv_), meaning it requires the=
    user to be logged in with at minimum a Subscriber-level account. There is =
    no nonce verification or additional capability check. This makes it possibl=
    e for authenticated attackers, with Subscriber-level access and above, to i= nject arbitrary web scripts in pages that will execute if they can successf= ully trick a user into performing an action such as clicking a link.</td> <td>2026-05-22</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3481" target=3D"= _blank" rel=3D"noopener">CVE-2026-3481</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/669505= 09-ce2a-42fe-a8b2-2a92a1b573c3?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/66950509-ce2= a-42fe-a8b2-2a92a1b573c3?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/wp-blockade/trunk/wp-blockade.php#L393" target=3D"_= blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/wp-block= ade/trunk/wp-blockade.php#L393</a><br><a href=3D"https://plugins.trac.wordp= ress.org/browser/wp-blockade/tags/0.9.14/wp-blockade.php#L393" target=3D"_b= lank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/wp-blocka= de/tags/0.9.14/wp-blockade.php#L393</a><br><a href=3D"https://plugins.trac.= wordpress.org/browser/wp-blockade/trunk/wp-blockade.php#L360" target=3D"_bl= ank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/wp-blockad= e/trunk/wp-blockade.php#L360</a><br><a href=3D"https://plugins.trac.wordpre= ss.org/browser/wp-blockade/tags/0.9.14/wp-blockade.php#L360" target=3D"_bla= nk" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/wp-blockade= /tags/0.9.14/wp-blockade.php#L360</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">calcom--cal.diy</td>
    <td>A security flaw has been discovered in calcom cal.diy up to 4.9.4. The = affected element is the function validateUrlForSSRF of the file apps/web/ap= p/api/logo/route.ts of the component Logo API. The manipulation results in = server-side request forgery. It is possible to launch the attack remotely. = Attacks of this nature are highly complex. The exploitability is described =
    as difficult. The exploit has been released to the public and may be used f=
    or attacks. The vendor was contacted early about this disclosure but did no=
    t respond in any way.</td>
    <td>2026-05-23</td>
    <td>5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9304" target=3D"= _blank" rel=3D"noopener">CVE-2026-9304</a></td>

    <a href=3D"https://vuldb.com/vuln/365251" target=3D"_blank" rel=3D"noopener= ">VDB-365251 | calcom cal.diy Logo API route.ts validateUrlForSSRF server-s= ide request forgery</a><br><a href=3D"https://vuldb.com/vuln/365251/cti" ta= rget=3D"_blank" rel=3D"noopener">VDB-365251 | CTI Indicators (IOB, IOC, IOA= )</a><br><a href=3D"https://vuldb.com/submit/812176" target=3D"_blank" rel= =3D"noopener">Submit #812176 | cal.com &lt;=3D v4.9.4 Server-Side Request F= orgery (CWE-918)</a><br><a href=3D"https://gist.github.com/YLChen-007/b3d0b= 85767b7e346a291933d602fbb3b" target=3D"_blank" rel=3D"noopener">https://gis= t.github.com/YLChen-007/b3d0b85767b7e346a291933d602fbb3b</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">calcom--cal.diy</td>
    <td>A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected =
    by this issue is the function getServerSideProps of the file apps/web/modul= es/bookings/views/bookings-single-view.getServerSideProps.tsx of the compon= ent Generic React API. This manipulation of the argument cancelledBy/resche= duledBy causes information disclosure. The attack can be initiated remotely=
    . The exploit has been publicly disclosed and may be utilized. The vendor w=
    as contacted early about this disclosure but did not respond in any way.</t=

    <td>2026-05-24</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9349" target=3D"= _blank" rel=3D"noopener">CVE-2026-9349</a></td>

    <a href=3D"https://vuldb.com/vuln/365312" target=3D"_blank" rel=3D"noopener= ">VDB-365312 | calcom cal.diy Generic React API bookings-single-view.getSer= verSideProps.tsx getServerSideProps information disclosure</a><br><a href= =3D"https://vuldb.com/vuln/365312/cti" target=3D"_blank" rel=3D"noopener">V= DB-365312 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href=3D"https://v= uldb.com/submit/812177" target=3D"_blank" rel=3D"noopener">Submit #812177 |=
    cal.com &lt;=3D v4.9.4 Exposure of Sensitive Information (CWE-200)</a><br>=
    <a href=3D"https://gist.github.com/YLChen-007/b59c44d1550c4b0f373ca4eb1c150= 994" target=3D"_blank" rel=3D"noopener">https://gist.github.com/YLChen-007/= b59c44d1550c4b0f373ca4eb1c150994</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">calcom--cal.diy</td>
    <td>A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted =
    is an unknown function. The manipulation leads to cross-site request forger=
    y. It is possible to initiate the attack remotely. The exploit is publicly = available and might be used. The vendor was contacted early about this disc= losure but did not respond in any way.</td>
    <td>2026-05-23</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9303" target=3D"= _blank" rel=3D"noopener">CVE-2026-9303</a></td>

    <a href=3D"https://vuldb.com/vuln/365250" target=3D"_blank" rel=3D"noopener= ">VDB-365250 | calcom cal.diy cross-site request forgery</a><br><a href=3D"= https://vuldb.com/vuln/365250/cti" target=3D"_blank" rel=3D"noopener">VDB-3= 65250 | CTI Indicators (IOB, IOC)</a><br><a href=3D"https://vuldb.com/submi= t/812173" target=3D"_blank" rel=3D"noopener">Submit #812173 | cal.com &lt;=
    =3D v4.9.4 Cross-Site Request Forgery (CWE-352)</a><br><a href=3D"https://v= uldb.com/submit/812175" target=3D"_blank" rel=3D"noopener">Submit #812175 |=
    cal.com &lt;=3D v4.9.4 Cross-Site Request Forgery (CWE-352) (Duplicate)</a= ><br><a href=3D"https://gist.github.com/YLChen-007/26663d9558e15994176dc420= d2e11d48" target=3D"_blank" rel=3D"noopener">https://gist.github.com/YLChen= -007/26663d9558e15994176dc420d2e11d48</a><br><a href=3D"https://gist.github= .com/YLChen-007/dafada36e356bc895b09829d8ec57e49" target=3D"_blank" rel=3D"= noopener">https://gist.github.com/YLChen-007/dafada36e356bc895b09829d8ec57e= 49</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Cisco--Cisco NX-OS Software</td>
    <td>A vulnerability in the Border Gateway Protocol (BGP)&amp;nbsp;enforce-f= irst-as feature of&amp;nbsp;Cisco Nexus 3000 Series Switches and Cisco Nexu=
    s 9000 Series Switches in standalone NX-OS mode could allow an unauthentica= ted, remote attacker to trigger BGP peer flaps, resulting in a denial of se= rvice (DoS) condition. This vulnerability is due to incorrect parsing of a = transitive BGP attribute. An attacker could exploit this vulnerability by s= ending a crafted BGP update through an established BGP peer session. If the=
    update propagates to an affected device, it could cause the device to drop=
    the BGP session and flap with the BGP peer that is forwarding this update,=
    resulting in a DoS condition.</td>
    <td>2026-05-20</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20171" target=3D= "_blank" rel=3D"noopener">CVE-2026-20171</a></td>

    <a href=3D"https://sec.cloudapps.cisco.com/security/center/content/CiscoSec= urityAdvisory/cisco-sa-bgp-iefab-3hb2pwtx" target=3D"_blank" rel=3D"noopene= r">cisco-sa-bgp-iefab-3hb2pwtx</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Cisco--Cisco ThousandEyes Enterprise Agent</td=

    <td>A vulnerability in the BrowserBot component of Cisco ThousandEyes Enter= prise Agent could have allowed an authenticated, remote attacker to execute=
    arbitrary commands on Agents on behalf of the BrowserBot synthetics orches= tration process. Cisco has addressed this vulnerability in the Cisco Thousa= ndEyes Enterprise Agent, and no customer action is needed. This vulnerabili=
    ty was due to insufficient input validation of command arguments that are s= upplied by the user. Prior to this vulnerability being addressed, an attack=
    er could have exploited this vulnerability by authenticating to the Thousan= dEyes SaaS and submitting crafted input into the affected parameter. A succ= essful exploit could have allowed the attacker to execute arbitrary command=
    s within the BrowserBot container as the node user. To exploit this vulnera= bility, the attacker must have valid user credentials for the ThousandEyes = SaaS and the ability to manage transaction tests.</td>
    <td>2026-05-20</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20206" target=3D= "_blank" rel=3D"noopener">CVE-2026-20206</a></td>

    <a href=3D"https://sec.cloudapps.cisco.com/security/center/content/CiscoSec= urityAdvisory/cisco-sa-tebbot-cmdinj-wN3yQ5gn" target=3D"_blank" rel=3D"noo= pener">cisco-sa-tebbot-cmdinj-wN3yQ5gn</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Cisco--Cisco ThousandEyes Enterprise Agent</td=

    <td>A vulnerability in the SSL certificate handling of Cisco ThousandEyes V= irtual Appliance could allow an authenticated, remote attacker to execute c= ommands on the underlying operating system as the root user. This vulnerabi= lity is due to insufficient validation of user-supplied input. An authentic= ated attacker could exploit this vulnerability by uploading a crafted certi= ficate to an affected device. A successful exploit could allow the attacker=
    to execute arbitrary code as the root user on the underlying operating sys= tem. To exploit this vulnerability, the attacker must have valid administra= tive credentials.</td>
    <td>2026-05-20</td>
    <td>4.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20199" target=3D= "_blank" rel=3D"noopener">CVE-2026-20199</a></td>

    <a href=3D"https://sec.cloudapps.cisco.com/security/center/content/CiscoSec= urityAdvisory/cisco-sa-tevacert-rce-RMJVEym5" target=3D"_blank" rel=3D"noop= ener">cisco-sa-tevacert-rce-RMJVEym5</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">conoha--TypeSquare Webfonts for ConoHa</td> <td>The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable t=
    o authorization bypass in all versions up to, and including, 2.0.4. This is=
    due to the plugin not properly verifying that a user is authorized to perf= orm an action. This makes it possible for authenticated attackers, with sub= scriber-level access and above, to modify the plugin's site-wide font setti= ngs, including the typesquare_auth option (fontThemeUseType), show_post_for=
    m, and typesquare_fonttheme, by submitting a POST request to any wp-admin p= age. For fontThemeUseType values 1 and 3, no nonce verification is performe=
    d either, meaning those branches are additionally exploitable via cross-sit=
    e request forgery.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8610" target=3D"= _blank" rel=3D"noopener">CVE-2026-8610</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/88002a= 25-6890-4f8b-8a11-239b59d56672?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/88002a25-689= 0-4f8b-8a11-239b59d56672?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.4/typesquare-admin.= php#L93" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.= org/browser/ts-webfonts-for-conoha/tags/2.0.4/typesquare-admin.php#L93</a><= br><a href=3D"https://plugins.trac.wordpress.org/browser/ts-webfonts-for-co= noha/tags/2.0.4/inc/class/class.auth.php#L51" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tag= s/2.0.4/inc/class/class.auth.php#L51</a><br><a href=3D"https://plugins.trac= .wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.4/typesquare-admin.p= hp#L25" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.o= rg/browser/ts-webfonts-for-conoha/tags/2.0.4/typesquare-admin.php#L25</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">cryptpad--cryptpad</td>
    <td>CryptPad is an end-to-end encrypted collaborative office suite. In vers= ions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed=
    due to incomplete attribute filtering on restricted tags. The sanitizer va= lidates only the src attribute of &lt;iframe&gt;, &lt;video&gt;, and &lt;au= dio&gt; elements, leaving all other attributes unchecked. As a result, an a= ttacker can inject arbitrary HTML through srcdoc, completely defeating Cryp= tPad's intended bounce sandboxing and enabling link injection or other inte= ractive content within user-controlled documents. The root cause lies in ho=
    w the sanitizer classifies and enforces tag restrictions: although it defin=
    es both forbidden and restricted tag lists, &lt;iframe&gt; is treated as "r= estricted" rather than "forbidden." Enforcement then inspects only the src = attribute, so pairing a benign blob: src with a malicious srcdoc results in=
    unrestricted rendering. This issue has been fixed in version 2026.2.0.</td=

    <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-26028" target=3D= "_blank" rel=3D"noopener">CVE-2026-26028</a></td>

    <a href=3D"https://github.com/cryptpad/cryptpad/security/advisories/GHSA-g2= g4-47gv-p72v" target=3D"_blank" rel=3D"noopener">https://github.com/cryptpa= d/cryptpad/security/advisories/GHSA-g2g4-47gv-p72v</a><br><a href=3D"https:= //github.com/cryptpad/cryptpad/releases/tag/2026.2.0" target=3D"_blank" rel= =3D"noopener">https://github.com/cryptpad/cryptpad/releases/tag/2026.2.0</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Ctrlpanel-gg--panel</td>
    <td>CtrlPanel is open-source billing software for hosting providers. In ver= sions 1.1.1 and prior, the admin settings update endpoint accepted a fully = qualified class name directly from user-supplied request input and used it = for dynamic static method calls and object instantiation without any allowl= ist validation, allowing for authenticated Remote Code Execution. An authen= ticated admin-level user could supply an arbitrary class name available in = the Composer autoloader, potentially triggering unintended constructor or m= agic method execution. The update() method reads settings_class directly fr=
    om the HTTP request and passed it to new $settings_class() and $settings_cl= ass::getValidations() without verifying that the provided value corresponds=
    to a legitimate settings class: Because PHP resolves class names against t=
    he Composer autoloader at runtime, any autoloadable class in the applicatio=
    n or its dependencies could be instantiated. Depending on the classes avail= able in the dependency tree, this can trigger unintended side effects throu=
    gh constructors or magic methods (__construct, __toString, __wakeup), follo= wing a PHP object injection / gadget chain pattern. This issue has been fix=
    ed in version 1.2.0.</td>
    <td>2026-05-19</td>
    <td>6.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34216" target=3D= "_blank" rel=3D"noopener">CVE-2026-34216</a></td>

    <a href=3D"https://github.com/Ctrlpanel-gg/panel/security/advisories/GHSA-v= cg3-fjrx-rg5q" target=3D"_blank" rel=3D"noopener">https://github.com/Ctrlpa= nel-gg/panel/security/advisories/GHSA-vcg3-fjrx-rg5q</a><br><a href=3D"http= s://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0" target=3D"_blank" rel= =3D"noopener">https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Ctrlpanel-gg--panel</td>
    <td>CtrlPanel is open-source billing software for hosting providers. In ver= sions 1.1.1 and prior, multiple admin controllers expose DataTable endpoint=
    s without authorization checks, allowing any authenticated user to access s= ensitive administrative data that should be restricted to administrators on= ly. The affected admin controllers define datatable() methods that are reac= hable via GET requests but lack any permission or role verification. Becaus=
    e the routes fall under the /admin/ prefix, operators may assume they are p= rotected - however, the middleware applied to this route group does not enf= orce admin-level authorization on these specific endpoints. As a result, an=
    y authenticated user (regardless of role) can query these endpoints and rec= eive paginated JSON responses containing sensitive records. Exploitation ca=
    n result in enumeration of user PII, payment and transaction records, activ=
    e voucher and coupon codes, role and permission structure, server ownership=
    mappings and support ticket contents. This issue has been fixed in version=
    1.2.0.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34233" target=3D= "_blank" rel=3D"noopener">CVE-2026-34233</a></td>

    <a href=3D"https://github.com/Ctrlpanel-gg/panel/security/advisories/GHSA-m= j5g-j7fq-7hc4" target=3D"_blank" rel=3D"noopener">https://github.com/Ctrlpa= nel-gg/panel/security/advisories/GHSA-mj5g-j7fq-7hc4</a><br><a href=3D"http= s://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0" target=3D"_blank" rel= =3D"noopener">https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Ctrlpanel-gg--panel</td>
    <td>CtrlPanel is open-source billing software for hosting providers. Versio=
    ns 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerabilit=
    y exists in the admin role management interface. In app/Http/Controllers/Ad= min/RoleController.php, the datatable() method interpolates $role-&gt;name = and $role-&gt;color directly into a &lt;span&gt; element's HTML and style a= ttribute without sanitization, and the chained .rawColumns(['actions', 'nam= e']) call instructs DataTables to render the name column as raw HTML, bypas= sing automatic output escaping. An admin with role creation or edit permiss= ions can inject a payload such as &lt;img src=3Dx onerror=3D"alert('XSS_POC= ')"&gt; into the name or color fields, which is persisted to the database a=
    nd executes in the browser of every admin who loads the /admin/roles page. = This enables session hijacking via cookie theft, credential harvesting thro= ugh fake login prompts or keyloggers, lateral privilege escalation by perfo= rming admin actions on behalf of victims, and a persistent backdoor that re= -executes on every page load until the malicious role record is removed. Th=
    is issue has been resolved in version 1.2.0.</td>
    <td>2026-05-19</td>
    <td>4.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34246" target=3D= "_blank" rel=3D"noopener">CVE-2026-34246</a></td>

    <a href=3D"https://github.com/Ctrlpanel-gg/panel/security/advisories/GHSA-w= pqj-xwhq-2mmh" target=3D"_blank" rel=3D"noopener">https://github.com/Ctrlpa= nel-gg/panel/security/advisories/GHSA-wpqj-xwhq-2mmh</a><br><a href=3D"http= s://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0" target=3D"_blank" rel= =3D"noopener">https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">cvmh--Sticky</td>
    <td>The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scri= pting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions =
    up to and including 2.5.6. This is due to insufficient input sanitization a=
    nd output escaping in the `cvmh_sticky_front_render()` function - the `read= moretext` attribute value is passed through `apply_filters()` and directly = concatenated into the HTML output without any escaping function such as `es= c_html()`. This makes it possible for authenticated attackers with Contribu= tor-level access and above to inject arbitrary web scripts in pages that wi=
    ll execute whenever a user accesses a page containing the injected shortcod= e.</td>
    <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6397" target=3D"= _blank" rel=3D"noopener">CVE-2026-6397</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/135783= c5-8175-4775-a013-f1e2bef04479?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/135783c5-817= 5-4775-a013-f1e2bef04479?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/sticky/trunk/includes/functions.php#L118" target=3D= "_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sticky= /trunk/includes/functions.php#L118</a><br><a href=3D"https://plugins.trac.w= ordpress.org/browser/sticky/tags/2.5.6/includes/functions.php#L118" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sti= cky/tags/2.5.6/includes/functions.php#L118</a><br><a href=3D"https://plugin= s.trac.wordpress.org/browser/sticky/trunk/includes/shortcode.php#L7" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sti= cky/trunk/includes/shortcode.php#L7</a><br><a href=3D"https://plugins.trac.= wordpress.org/browser/sticky/tags/2.5.6/includes/shortcode.php#L7" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sti= cky/tags/2.5.6/includes/shortcode.php#L7</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">dartiss--Draft List</td>
    <td>The Draft List plugin for WordPress is vulnerable to Stored Cross-Site = Scripting via Draft Post Title in all versions up to, and including, 2.6.3 = due to insufficient input sanitization and output escaping. This makes it p= ossible for authenticated attackers, with author-level access and above, to=
    inject arbitrary web scripts in pages that will execute whenever a user ac= cesses an injected page. The unescaped injection path is triggered specific= ally when the viewing user lacks edit capabilities, meaning payloads embedd=
    ed in draft post titles via attribute-breakout techniques execute for unaut= henticated users and subscribers.</td>
    <td>2026-05-22</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9104" target=3D"= _blank" rel=3D"noopener">CVE-2026-9104</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/073612= 78-7abb-4d22-a8df-218d3f982483?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/07361278-7ab= b-4d22-a8df-218d3f982483?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/simple-draft-list/tags/2.6.3/inc/create-lists.php#L= 396" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/= browser/simple-draft-list/tags/2.6.3/inc/create-lists.php#L396</a><br><a hr= ef=3D"https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6= .3/inc/create-lists.php#L305" target=3D"_blank" rel=3D"noopener">https://pl= ugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.3/inc/create-li= sts.php#L305</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/s= imple-draft-list/tags/2.6.3/inc/create-lists.php#L66" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/simple-draft-list/= tags/2.6.3/inc/create-lists.php#L66</a><br><a href=3D"https://plugins.trac.= wordpress.org/browser/simple-draft-list/tags/2.6.4/inc/create-lists.php#L38=
    9" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/br= owser/simple-draft-list/tags/2.6.4/inc/create-lists.php#L389</a><br><a href= =3D"https://plugins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.4= /inc/create-lists.php#L391" target=3D"_blank" rel=3D"noopener">https://plug= ins.trac.wordpress.org/browser/simple-draft-list/tags/2.6.4/inc/create-list= s.php#L391</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/sim= ple-draft-list/tags/2.6.4/inc/create-lists.php#L394" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/simple-draft-list/= tags/2.6.4/inc/create-lists.php#L394</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--ECS</td>
    <td>Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in t=
    he Identity and Access Management (IAM) module. A remote unauthenticated at= tacker may potentially exploit this vulnerability, leading to gaining read = access to unauthorized data.</td>
    <td>2026-05-22</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2022-31231" target=3D= "_blank" rel=3D"noopener">CVE-2022-31231</a></td>

    <a href=3D"https://dellservices.lightning.force.com/lightning/r/Lightning_K= nowledge__kav/ka06P0000004RFTQA2/view" target=3D"_blank" rel=3D"noopener">h= ttps://dellservices.lightning.force.com/lightning/r/Lightning_Knowledge__ka= v/ka06P0000004RFTQA2/view</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--Live Optics</td>
    <td>Dell Live Optics Windows and Personal Edition collectors contain an imp= roper certificate validation vulnerability. A remote unauthenticated attack=
    er could potentially exploit this vulnerability leading to loss of confiden= tiality and integrity.</td>
    <td>2026-05-18</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41119" target=3D= "_blank" rel=3D"noopener">CVE-2026-41119</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000464862/dsa-2026-221-= security-update-for-dell-live-optics-collector-ssl-vulnerability" target=3D= "_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/00046486= 2/dsa-2026-221-security-update-for-dell-live-optics-collector-ssl-vulnerabi= lity</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redi= rect Vulnerability. An unauthenticated attacker could potentially exploit t= his vulnerability, leading to a targeted application user being redirected =
    to arbitrary web URLs. The vulnerability could be leveraged by attackers to=
    conduct phishing attacks that cause users to divulge sensitive information= .</td>
    <td>2026-05-22</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-26483" target=3D= "_blank" rel=3D"noopener">CVE-2025-26483</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) an Incorrec=
    t Privilege Assignment vulnerability. A low privileged attacker with local = access could potentially exploit this vulnerability, leading to Elevation o=
    f privileges.</td>
    <td>2026-05-22</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32747" target=3D= "_blank" rel=3D"noopener">CVE-2025-32747</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) an Exposure=
    of Information Through Directory Listing vulnerability. An unauthenticated=
    attacker with remote access could potentially exploit this vulnerability, = leading to Information exposure.</td>
    <td>2026-05-22</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32749" target=3D= "_blank" rel=3D"noopener">CVE-2025-32749</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) an Insecure=
    Storage of Sensitive Information vulnerability. A low privileged attacker = with local access could potentially exploit this vulnerability, leading to = unauthorized access to sensitive information.</td>
    <td>2026-05-22</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32751" target=3D= "_blank" rel=3D"noopener">CVE-2025-32751</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) an Improper=
    Certificate Validation vulnerability. An unauthenticated attacker with adj= acent network access could potentially exploit this vulnerability, leading =
    to Information tampering.</td>
    <td>2026-05-22</td>
    <td>4.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32745" target=3D= "_blank" rel=3D"noopener">CVE-2025-32745</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) an Insecure=
    Storage of Sensitive Information vulnerability. An unauthenticated attacke=
    r with local access could potentially exploit this vulnerability, leading t=
    o unauthorized access to sensitive information.</td>
    <td>2026-05-22</td>
    <td>4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32746" target=3D= "_blank" rel=3D"noopener">CVE-2025-32746</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--SmartFabric Storage Software</td>
    <td>Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an=
    Improper Neutralization of Special Elements used in a Command ('Command In= jection') vulnerability. A high privileged attacker with local access could=
    potentially exploit this vulnerability, leading to Filesystem access for a= ttacker.</td>
    <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35070" target=3D= "_blank" rel=3D"noopener">CVE-2026-35070</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000466942/dsa-2026-235-= security-update-for-dell-networking-smartfabric-storage-software-vulnerabil= ities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdo= c/en-us/000466942/dsa-2026-235-security-update-for-dell-networking-smartfab= ric-storage-software-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--Unisphere for PowerMax</td>
    <td>Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an=
    authorization bypass vulnerability in the=C2=A0 Unisphere for VMAX applica= tion running in=C2=A0vApp</td>
    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2022-34363" target=3D= "_blank" rel=3D"noopener">CVE-2022-34363</a></td>

    <a href=3D"https://dellservices.lightning.force.com/lightning/r/Lightning_K= nowledge__kav/ka06P000000xAiKQAU/view" target=3D"_blank" rel=3D"noopener">h= ttps://dellservices.lightning.force.com/lightning/r/Lightning_Knowledge__ka= v/ka06P000000xAiKQAU/view</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--VxRail</td>
    <td>Dell VxRail versions before 7.0.200 contain a Plain-text Password Stora=
    ge Vulnerability in VxRail Manager. A sys-admin user may exploit this vulne= rability, leading to the disclosure of certain user credentials. The attack=
    er may be able to use the exposed credentials to access the vulnerable appl= ication with privileges of the compromised account.</td>
    <td>2026-05-22</td>
    <td>6.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-21508" target=3D= "_blank" rel=3D"noopener">CVE-2021-21508</a></td>

    <a href=3D"https://dellservices.lightning.force.com/lightning/r/Lightning_K= nowledge__kav/ka0Do000000m7VwIAI/view" target=3D"_blank" rel=3D"noopener">h= ttps://dellservices.lightning.force.com/lightning/r/Lightning_Knowledge__ka= v/ka0Do000000m7VwIAI/view</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">discourse--discourse</td>
    <td>Discourse is an open-source discussion platform. In versions prior to 2= 026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summa= ries can leak removed content to anonymous and unprivileged users who canno=
    t regenerate summaries. This issue has been fixed in versions 2026.1.4, 202= 6.3.1, 2026.4.1 and 2026.5.0-latest.1. To work around this issue, restrict = summary generation by tightening the allowed groups on the summarization Pe= rsonas.</td>
    <td>2026-05-19</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32244" target=3D= "_blank" rel=3D"noopener">CVE-2026-32244</a></td>

    <a href=3D"https://github.com/discourse/discourse/security/advisories/GHSA-= hjmg-2mww-vfvx" target=3D"_blank" rel=3D"noopener">https://github.com/disco= urse/discourse/security/advisories/GHSA-hjmg-2mww-vfvx</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">DumbWareio--DumbAssets</td>
    <td>DumbAssets through 1.0.11 contains a stored cross-site scripting vulner= ability in asset fields including name, description, modelNumber, serialNum= ber, and tags that are stored without server-side sanitization and rendered=
    using innerHTML without client-side escaping. Attackers can create or upda=
    te assets with HTML or JavaScript payloads via the asset API endpoints to e= xecute arbitrary scripts in the browsers of users viewing the asset list, a=
    nd with Content-Security-Policy disabled, the injected scripts can make unr= estricted connections to internal network services.</td>
    <td>2026-05-18</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45231" target=3D= "_blank" rel=3D"noopener">CVE-2026-45231</a></td>

    <a href=3D"https://github.com/DumbWareio/DumbAssets/pull/135" target=3D"_bl= ank" rel=3D"noopener">https://github.com/DumbWareio/DumbAssets/pull/135</a>= <br><a href=3D"https://www.vulncheck.com/advisories/dumbassets-stored-cross= -site-scripting-via-asset-fields" target=3D"_blank" rel=3D"noopener">https:= //www.vulncheck.com/advisories/dumbassets-stored-cross-site-scripting-via-a= sset-fields</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">eazyserver--Sentence To SEO (keywords, descrip= tion and tags)</td>
    <td>The Sentence To SEO (keywords, description and tags) plugin for WordPre=
    ss is vulnerable to Cross-Site Request Forgery in all versions up to, and i= ncluding, 1.0. This is due to missing or incorrect nonce validation on the = create_admin_page() function. This makes it possible for unauthenticated at= tackers to inject malicious web scripts and update plugin settings via a fo= rged request granted they can trick a site administrator into performing an=
    action such as clicking on a link.</td>
    <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6391" target=3D"= _blank" rel=3D"noopener">CVE-2026-6391</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/add32c= 06-90d0-466f-b176-aaae55cf03fb?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/add32c06-90d= 0-466f-b176-aaae55cf03fb?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/sentence-to-seo/trunk/index.php#L75" target=3D"_bla= nk" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sentence-to= -seo/trunk/index.php#L75</a><br><a href=3D"https://plugins.trac.wordpress.o= rg/browser/sentence-to-seo/tags/1.0/index.php#L75" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/= 1.0/index.php#L75</a><br><a href=3D"https://plugins.trac.wordpress.org/brow= ser/sentence-to-seo/trunk/index.php#L81" target=3D"_blank" rel=3D"noopener"= >https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php= #L81</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/sentence-= to-seo/tags/1.0/index.php#L81" target=3D"_blank" rel=3D"noopener">https://p= lugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.php#L81</a= ><br><a href=3D"https://plugins.trac.wordpress.org/browser/sentence-to-seo/= trunk/index.php#L87" target=3D"_blank" rel=3D"noopener">https://plugins.tra= c.wordpress.org/browser/sentence-to-seo/trunk/index.php#L87</a><br><a href= =3D"https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/ind= ex.php#L87" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpre= ss.org/browser/sentence-to-seo/tags/1.0/index.php#L87</a><br><a href=3D"htt= ps://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php#L50=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/bro= wser/sentence-to-seo/trunk/index.php#L50</a><br><a href=3D"https://plugins.= trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.php#L50" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sen= tence-to-seo/tags/1.0/index.php#L50</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6228NC</td>
    <td>A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this=
    issue is the function mp of the file /goform/mp of the component POST Requ= est Handler. The manipulation of the argument command results in command in= jection. The attack may be performed from remote. The exploit is now public=
    and may be used. The vendor was contacted early about this disclosure but = did not respond in any way.</td>
    <td>2026-05-18</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8774" target=3D"= _blank" rel=3D"noopener">CVE-2026-8774</a></td>

    <a href=3D"https://vuldb.com/vuln/364399" target=3D"_blank" rel=3D"noopener= ">VDB-364399 | Edimax BR-6228NC POST Request mp command injection</a><br><a=
    href=3D"https://vuldb.com/vuln/364399/cti" target=3D"_blank" rel=3D"noopen= er">VDB-364399 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href=3D"http= s://vuldb.com/submit/811529" target=3D"_blank" rel=3D"noopener">Submit #811= 529 | EDIMAX BR6228NC BR-6228NCv2 (Version : v1.22) Command Injection</a><b= r><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6228NC-mp-34= b53a41781f80db8aaed24e43ea24b9?source=3Dcopy_link" target=3D"_blank" rel=3D= "noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6228NC-mp-34b5= 3a41781f80db8aaed24e43ea24b9?source=3Dcopy_link</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects = the function formStaDrvSetup of the file /goform/formStaDrvSetup of the com= ponent POST Request Handler. Performing a manipulation of the argument stad= rv_ssid results in command injection. The attack can be initiated remotely.=
    The exploit has been made public and could be used. The vendor was contact=
    ed early about this disclosure but did not respond in any way.</td> <td>2026-05-18</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8777" target=3D"= _blank" rel=3D"noopener">CVE-2026-8777</a></td>

    <a href=3D"https://vuldb.com/vuln/364402" target=3D"_blank" rel=3D"noopener= ">VDB-364402 | Edimax BR-6428NS POST Request formStaDrvSetup command inject= ion</a><br><a href=3D"https://vuldb.com/vuln/364402/cti" target=3D"_blank" = rel=3D"noopener">VDB-364402 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a=
    href=3D"https://vuldb.com/submit/811532" target=3D"_blank" rel=3D"noopener= ">Submit #811532 | EDIMAX BR-6428NS BR-6428NS_v4_1.10 Command Injection</a>= <br><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-fo= rmStaDrvSetup-34b53a41781f80ca940cc467cd15dfc2?source=3Dcopy_link" target= =3D"_blank" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMA= X-BR-6428NS-formStaDrvSetup-34b53a41781f80ca940cc467cd15dfc2?source=3Dcopy_= link</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A weakness has been identified in Edimax BR-6428NS 1.10. This impacts t=
    he function system of the file /goform/formWlanM of the component POST Requ= est Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTx= Count/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPow= er4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Pow= er3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ate= Mode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDe= ltaMix/e2pTxPwDeltaN/readE2P can lead to command injection. The attack can =
    be launched remotely. The exploit has been made available to the public and=
    could be used for attacks. The vendor was contacted early about this discl= osure but did not respond in any way.</td>
    <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9296" target=3D"= _blank" rel=3D"noopener">CVE-2026-9296</a></td>

    <a href=3D"https://vuldb.com/vuln/365243" target=3D"_blank" rel=3D"noopener= ">VDB-365243 | Edimax BR-6428NS POST Request formWlanM system command injec= tion</a><br><a href=3D"https://vuldb.com/vuln/365243/cti" target=3D"_blank"=
    rel=3D"noopener">VDB-365243 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><=
    a href=3D"https://vuldb.com/submit/811535" target=3D"_blank" rel=3D"noopene= r">Submit #811535 | EDIMAX BR-6428NS BR-6428NS_v4_1.10 Command Injection</a= ><br><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-f= ormWlanMP-34b53a41781f808fb207ce3f297db80b?source=3Dcopy_link" target=3D"_b= lank" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6= 428NS-formWlanMP-34b53a41781f808fb207ce3f297db80b?source=3Dcopy_link</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6428NS</td>
    <td>A security vulnerability has been detected in Edimax BR-6428NS 1.10. Af= fected is the function formWlbasic of the file /goform/formWlbasic of the c= omponent POST Request Handler. The manipulation of the argument repeaterSSI=
    D leads to command injection. The attack may be initiated remotely. The exp= loit has been disclosed publicly and may be used. The vendor was contacted = early about this disclosure but did not respond in any way.</td> <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9297" target=3D"= _blank" rel=3D"noopener">CVE-2026-9297</a></td>

    <a href=3D"https://vuldb.com/vuln/365244" target=3D"_blank" rel=3D"noopener= ">VDB-365244 | Edimax BR-6428NS POST Request formWlbasic command injection<= /a><br><a href=3D"https://vuldb.com/vuln/365244/cti" target=3D"_blank" rel= =3D"noopener">VDB-365244 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a hr= ef=3D"https://vuldb.com/submit/811536" target=3D"_blank" rel=3D"noopener">S= ubmit #811536 | EDIMAX BR-6428NS BR-6428NS_v4_1.10 Command Injection</a><br= ><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-formW= lbasic-34b53a41781f807fb398dbab03bdbb38?source=3Dcopy_link" target=3D"_blan=
    k" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428= NS-formWlbasic-34b53a41781f807fb398dbab03bdbb38?source=3Dcopy_link</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A security flaw has been discovered in Edimax BR-6675nD 1.12. This affe= cts the function formHwSet of the file /goform/formHwSet of the component P= OST Request Handler. The manipulation of the argument regDomain/ABandregDom= ain/nic0Addr/nic1Addr/wlanAddr/inicAddr results in command injection. It is=
    possible to launch the attack remotely. The exploit has been released to t=
    he public and may be used for attacks. The vendor was contacted early about=
    this disclosure but did not respond in any way.</td>
    <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9378" target=3D"= _blank" rel=3D"noopener">CVE-2026-9378</a></td>

    <a href=3D"https://vuldb.com/vuln/365341" target=3D"_blank" rel=3D"noopener= ">VDB-365341 | Edimax BR-6675nD POST Request formHwSet command injection</a= ><br><a href=3D"https://vuldb.com/vuln/365341/cti" target=3D"_blank" rel=3D= "noopener">VDB-365341 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href= =3D"https://vuldb.com/submit/811555" target=3D"_blank" rel=3D"noopener">Sub= mit #811555 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection</a><br><a = href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formHwSet= -34b53a41781f8077b588f6e7cbbed36b?source=3Dcopy_link" target=3D"_blank" rel= =3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-for= mHwSet-34b53a41781f8077b588f6e7cbbed36b?source=3Dcopy_link</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A weakness has been identified in Edimax BR-6675nD 1.12. This impacts t=
    he function formWpsStart of the file /goform/formWpsStart of the component = POST Request Handler. This manipulation of the argument pinCode causes comm= and injection. The attack can be initiated remotely. The exploit has been m= ade available to the public and could be used for attacks. The vendor was c= ontacted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9379" target=3D"= _blank" rel=3D"noopener">CVE-2026-9379</a></td>

    <a href=3D"https://vuldb.com/vuln/365342" target=3D"_blank" rel=3D"noopener= ">VDB-365342 | Edimax BR-6675nD POST Request formWpsStart command injection= </a><br><a href=3D"https://vuldb.com/vuln/365342/cti" target=3D"_blank" rel= =3D"noopener">VDB-365342 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a hr= ef=3D"https://vuldb.com/submit/811556" target=3D"_blank" rel=3D"noopener">S= ubmit #811556 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection</a><br><=
    a href=3D"https://vuldb.com/submit/811567" target=3D"_blank" rel=3D"noopene= r">Submit #811567 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection (Dup= licate)</a><br><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-B= R-6675nD-formWpsStart-34b53a41781f8011b77ac5ebb77dfddd?source=3Dcopy_link" = target=3D"_blank" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site= /EDIMAX-BR-6675nD-formWpsStart-34b53a41781f8011b77ac5ebb77dfddd?source=3Dco= py_link</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the = function formUSBStorage of the file /goform/formUSBStorage of the component=
    POST Request Handler. Executing a manipulation of the argument sub_dir can=
    lead to command injection. It is possible to launch the attack remotely. T=
    he exploit has been published and may be used. The vendor was contacted ear=
    ly about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9400" target=3D"= _blank" rel=3D"noopener">CVE-2026-9400</a></td>

    <a href=3D"https://vuldb.com/vuln/365381" target=3D"_blank" rel=3D"noopener= ">VDB-365381 | Edimax BR-6675nD POST Request formUSBStorage command injecti= on</a><br><a href=3D"https://vuldb.com/vuln/365381/cti" target=3D"_blank" r= el=3D"noopener">VDB-365381 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a = href=3D"https://vuldb.com/submit/811562" target=3D"_blank" rel=3D"noopener"= >Submit #811562 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection</a><br= ><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formU= SBStorage-34b53a41781f80809fc9e6ab3c51328b?source=3Dcopy_link" target=3D"_b= lank" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6= 675nD-formUSBStorage-34b53a41781f80809fc9e6ab3c51328b?source=3Dcopy_link</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--BR-6675nD</td>
    <td>A vulnerability was found in Edimax BR-6675nD 1.12. The affected elemen=
    t is the function formWlanMP of the file /goform/formWlanMP of the componen=
    t POST Request Handler. The manipulation of the argument ateFunc/ateGain/at= eRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power= 4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/e2pTxPower1/e2pTxPower2/e2pTxPower= 3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/ateTxFreqOffset/ateMode/a= teMacID/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxP= wDeltaMix/readE2P/e2pTxPwDeltaN results in command injection. The attack ca=
    n be launched remotely. The exploit has been made public and could be used.=
    The vendor was contacted early about this disclosure but did not respond i=
    n any way.</td>
    <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9402" target=3D"= _blank" rel=3D"noopener">CVE-2026-9402</a></td>

    <a href=3D"https://vuldb.com/vuln/365383" target=3D"_blank" rel=3D"noopener= ">VDB-365383 | Edimax BR-6675nD POST Request formWlanMP command injection</= a><br><a href=3D"https://vuldb.com/vuln/365383/cti" target=3D"_blank" rel= =3D"noopener">VDB-365383 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a hr= ef=3D"https://vuldb.com/submit/811565" target=3D"_blank" rel=3D"noopener">S= ubmit #811565 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection</a><br><=
    a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formWla= nMP-34b53a41781f8041aa2ecb4fa1927f59?source=3Dcopy_link" target=3D"_blank" = rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-= formWlanMP-34b53a41781f8041aa2ecb4fa1927f59?source=3Dcopy_link</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A weakness has been identified in Edimax EW-7438RPn up to 1.31. The aff= ected element is the function formWpsStart of the file /goform/formWpsStart=
    of the component webs. This manipulation of the argument pinCode causes os=
    command injection. Remote exploitation of the attack is possible. The expl= oit has been made available to the public and could be used for attacks. Th=
    e vendor was contacted early about this disclosure but did not respond in a=
    ny way.</td>
    <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9343" target=3D"= _blank" rel=3D"noopener">CVE-2026-9343</a></td>

    <a href=3D"https://vuldb.com/vuln/365306" target=3D"_blank" rel=3D"noopener= ">VDB-365306 | Edimax EW-7438RPn webs formWpsStart os command injection</a>= <br><a href=3D"https://vuldb.com/vuln/365306/cti" target=3D"_blank" rel=3D"= noopener">VDB-365306 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href= =3D"https://vuldb.com/submit/813884" target=3D"_blank" rel=3D"noopener">Sub= mit #813884 | Edimax EW-7438RPn 1.31 Command Injection</a><br><a href=3D"ht= tps://vuldb.com/submit/811551" target=3D"_blank" rel=3D"noopener">Submit #8= 11551 | EDIMAX EW-7438RPn Mini EW-7438RPn Mini Firmware 1.28a (Version : 1.= 28a) Command Injection (Duplicate)</a><br><a href=3D"https://github.com/wud= ipjq/my_vuln/blob/main/Edimax/vuln_1/1.md" target=3D"_blank" rel=3D"noopene= r">https://github.com/wudipjq/my_vuln/blob/main/Edimax/vuln_1/1.md</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affecte=
    d is the function formWizSurvey of the file /goform/formWizSurvey of the co= mponent webs. The manipulation of the argument ip/mask/gateway leads to os = command injection. It is possible to initiate the attack remotely. The expl= oit has been disclosed to the public and may be used. The vendor was contac= ted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9347" target=3D"= _blank" rel=3D"noopener">CVE-2026-9347</a></td>

    <a href=3D"https://vuldb.com/vuln/365310" target=3D"_blank" rel=3D"noopener= ">VDB-365310 | Edimax EW-7438RPn webs formWizSurvey os command injection</a= ><br><a href=3D"https://vuldb.com/vuln/365310/cti" target=3D"_blank" rel=3D= "noopener">VDB-365310 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href= =3D"https://vuldb.com/submit/813889" target=3D"_blank" rel=3D"noopener">Sub= mit #813889 | Edimax EW-7438RPn 1.31 Command Injection</a><br><a href=3D"ht= tps://vuldb.com/submit/811543" target=3D"_blank" rel=3D"noopener">Submit #8= 11543 | EDIMAX EW-7438RPn Mini EW-7438RPn Mini Firmware 1.28a (Version : 1.= 28a) Command Injection (Duplicate)</a><br><a href=3D"https://github.com/wud= ipjq/my_vuln/blob/main/Edimax/vuln_5/5.md" target=3D"_blank" rel=3D"noopene= r">https://github.com/wudipjq/my_vuln/blob/main/Edimax/vuln_5/5.md</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by = this vulnerability is the function formHwSet of the file /goform/formHwSet =
    of the component POST Request Handler. The manipulation of the argument Ann= tena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/com= d/initgain/txcck/txofdm leads to command injection. The attack can be initi= ated remotely. The exploit is publicly available and might be used. The ven= dor was contacted early about this disclosure but did not respond in any wa= y.</td>
    <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9359" target=3D"= _blank" rel=3D"noopener">CVE-2026-9359</a></td>

    <a href=3D"https://vuldb.com/vuln/365322" target=3D"_blank" rel=3D"noopener= ">VDB-365322 | Edimax EW-7438RPn POST Request formHwSet command injection</= a><br><a href=3D"https://vuldb.com/vuln/365322/cti" target=3D"_blank" rel= =3D"noopener">VDB-365322 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a hr= ef=3D"https://vuldb.com/submit/811540" target=3D"_blank" rel=3D"noopener">S= ubmit #811540 | EDIMAX EW-7438RPn Mini EW-7438RPn Mini Firmware 1.28a (Vers= ion : 1.28a) Command Injection</a><br><a href=3D"https://lavender-bicycle-a= 5a.notion.site/EDIMAX-EW-7438RPn-Mini-formHwSet-34b53a41781f80b98d10f0da699= f2236?source=3Dcopy_link" target=3D"_blank" rel=3D"noopener">https://lavend= er-bicycle-a5a.notion.site/EDIMAX-EW-7438RPn-Mini-formHwSet-34b53a41781f80b= 98d10f0da699f2236?source=3Dcopy_link</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A weakness has been identified in Edimax EW-7438RPn 1.12. This affects = the function formAccept of the file /goform/formAccep of the component POST=
    Request Handler. This manipulation of the argument submit-url causes comma=
    nd injection. The attack may be initiated remotely. The exploit has been ma=
    de available to the public and could be used for attacks. The vendor was co= ntacted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9361" target=3D"= _blank" rel=3D"noopener">CVE-2026-9361</a></td>

    <a href=3D"https://vuldb.com/vuln/365324" target=3D"_blank" rel=3D"noopener= ">VDB-365324 | Edimax EW-7438RPn POST Request formAccep formAccept command = injection</a><br><a href=3D"https://vuldb.com/vuln/365324/cti" target=3D"_b= lank" rel=3D"noopener">VDB-365324 | CTI Indicators (IOB, IOC, TTP, IOA)</a>= <br><a href=3D"https://vuldb.com/submit/811552" target=3D"_blank" rel=3D"no= opener">Submit #811552 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection= </a><br><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675n= D-formAccept-34b53a41781f807fb8f3d96c5e5ef215?source=3Dcopy_link" target=3D= "_blank" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/EDIMAX-B= R-6675nD-formAccept-34b53a41781f807fb8f3d96c5e5ef215?source=3Dcopy_link</a>= <br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A security vulnerability has been detected in Edimax EW-7438RPn 1.12. T= his vulnerability affects the function formConnectionSetting of the file /g= oform/formConnectionSetting of the component Setting Handler. Such manipula= tion of the argument max_Conn/timeOut leads to command injection. The attac=
    k may be launched remotely. The exploit has been disclosed publicly and may=
    be used. The vendor was contacted early about this disclosure but did not = respond in any way.</td>
    <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9362" target=3D"= _blank" rel=3D"noopener">CVE-2026-9362</a></td>

    <a href=3D"https://vuldb.com/vuln/365325" target=3D"_blank" rel=3D"noopener= ">VDB-365325 | Edimax EW-7438RPn Setting formConnectionSetting command inje= ction</a><br><a href=3D"https://vuldb.com/vuln/365325/cti" target=3D"_blank=
    " rel=3D"noopener">VDB-365325 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br>=
    <a href=3D"https://vuldb.com/submit/811553" target=3D"_blank" rel=3D"noopen= er">Submit #811553 | EDIMAX BR-6675nD BR-6675nD v1.12 Command Injection</a>= <br><a href=3D"https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-fo= rmConnectionSetting-34b53a41781f807a9c88e746d24540cd?source=3Dcopy_link" ta= rget=3D"_blank" rel=3D"noopener">https://lavender-bicycle-a5a.notion.site/E= DIMAX-BR-6675nD-formConnectionSetting-34b53a41781f807a9c88e746d24540cd?sour= ce=3Dcopy_link</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Edimax--EW-7438RPn</td>
    <td>A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affe= cts the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu o=
    f the component POST Request Handler. Performing a manipulation of the argu= ment method results in command injection. Remote exploitation of the attack=
    is possible. The exploit is now public and may be used. The vendor was con= tacted early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9363" target=3D"= _blank" rel=3D"noopener">CVE-2026-9363</a></td>

    <a href=3D"https://vuldb.com/vuln/365326" target=3D"_blank" rel=3D"noopener= ">VDB-365326 | Edimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwl= anSetup command injection</a><br><a href=3D"https://vuldb.com/vuln/365326/c= ti" target=3D"_blank" rel=3D"noopener">VDB-365326 | CTI Indicators (IOB, IO=
    C, TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/811554" target=3D"_= blank" rel=3D"noopener">Submit #811554 | EDIMAX BR-6675nD BR-6675nD v1.12 C= ommand Injection</a><br><a href=3D"https://lavender-bicycle-a5a.notion.site= /EDIMAX-BR-6675nD-formEZCHNwlanSetup-34b53a41781f803a8c60ca409394df5b?sourc= e=3Dcopy_link" target=3D"_blank" rel=3D"noopener">https://lavender-bicycle-= a5a.notion.site/EDIMAX-BR-6675nD-formEZCHNwlanSetup-34b53a41781f803a8c60ca4= 09394df5b?source=3Dcopy_link</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">edmonparker--Read More &amp; Accordion</td> <td>The Read More &amp; Accordion plugin for WordPress is vulnerable to tim= e-based blind SQL Injection via the 'orderby' parameter in all versions up = to, and including, 3.5.7. This is due to the use of esc_sql() without surro= unding the value in quotes in an ORDER BY clause inside the getAllDataByLim= it() and getAccordionAllDataByLimit() functions in ReadMoreData.php. The us= er-supplied $_GET['orderby'] value is only processed through esc_attr() (an=
    HTML-escaping function) before being passed to these database functions, w= here esc_sql() is applied but the value is directly concatenated-unquoted-i= nto the ORDER BY fragment of the SQL query before $wpdb-&gt;prepare() is ca= lled. Because esc_sql() only escapes quote characters and backslashes (whic=
    h are irrelevant in an unquoted ORDER BY context), an attacker can inject a= rbitrary SQL expressions such as (SELECT SLEEP(5)) or conditional subquerie=
    s to perform time-based blind data extraction. This makes it possible for a= uthenticated attackers with administrator-level access or above (or any rol=
    e explicitly permitted access to the plugin's admin pages via the yrm-user-= roles setting) to extract sensitive data from the database, including admin= istrator credential hashes.</td>
    <td>2026-05-20</td>
    <td>4.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7472" target=3D"= _blank" rel=3D"noopener">CVE-2026-7472</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc7c7e= 21-fbd7-4451-bc7d-3d11db01a443?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/cc7c7e21-fbd= 7-4451-bc7d-3d11db01a443?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/expand-maker/trunk/classes/ReadMoreData.php#L1522" = target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brows= er/expand-maker/trunk/classes/ReadMoreData.php#L1522</a><br><a href=3D"http= s://plugins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/classes/Read= MoreData.php#L1522" target=3D"_blank" rel=3D"noopener">https://plugins.trac= .wordpress.org/browser/expand-maker/tags/3.5.7/classes/ReadMoreData.php#L15= 22</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/expand-make= r/trunk/views/readMorePagesView.php#L29" target=3D"_blank" rel=3D"noopener"= >https://plugins.trac.wordpress.org/browser/expand-maker/trunk/views/readMo= rePagesView.php#L29</a><br><a href=3D"https://plugins.trac.wordpress.org/br= owser/expand-maker/tags/3.5.7/views/readMorePagesView.php#L29" target=3D"_b= lank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/expand-ma= ker/tags/3.5.7/views/readMorePagesView.php#L29</a><br><a href=3D"https://pl= ugins.trac.wordpress.org/browser/expand-maker/trunk/classes/ReadMoreData.ph= p#L1537" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.= org/browser/expand-maker/trunk/classes/ReadMoreData.php#L1537</a><br><a hre= f=3D"https://plugins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/cla= sses/ReadMoreData.php#L1537" target=3D"_blank" rel=3D"noopener">https://plu= gins.trac.wordpress.org/browser/expand-maker/tags/3.5.7/classes/ReadMoreDat= a.php#L1537</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/ex= pand-maker/trunk/views/accordionBuilder/list.php#L29" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/expand-maker/trunk= /views/accordionBuilder/list.php#L29</a><br><a href=3D"https://plugins.trac= .wordpress.org/browser/expand-maker/tags/3.5.7/views/accordionBuilder/list.= php#L29" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.= org/browser/expand-maker/tags/3.5.7/views/accordionBuilder/list.php#L29</a>= <br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">espocrm--espocrm</td>
    <td>EspoCRM is an open source customer relationship management application.=
    Versions 9.3.3 and below allow authenticated users to upload SVG attachmen=
    ts through normal attachment-capable fields and later serve those SVG files=
    as top-level inline documents through both the attachment and image entry = points, resulting in stored cross-user XSS reachable through a normal attac= hment workflow. Although inline SVG script is blocked by the response CSP, = the same CSP still allows same-origin external script. As a result, an atta= cker can upload a malicious SVG together with a second attacker-controlled = JavaScript attachment, then trick another user into opening the SVG to exec= ute JavaScript in the victim's EspoCRM origin. This issue has been fixed in=
    version 9.3.4.</td>
    <td>2026-05-19</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33741" target=3D= "_blank" rel=3D"noopener">CVE-2026-33741</a></td>

    <a href=3D"https://github.com/espocrm/espocrm/security/advisories/GHSA-5wh5= -ccv2-m3pv" target=3D"_blank" rel=3D"noopener">https://github.com/espocrm/e= spocrm/security/advisories/GHSA-5wh5-ccv2-m3pv</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Esri--ArcGIS Server</td>
    <td>ArcGIS Server contains an improper authentication vulnerability in an u= ndocumented administrative endpoint. An unauthenticated attacker could expl= oit this issue by sending a crafted request to the endpoint. Successful exp= loitation may result in disruption of the web-based browsing interface. Thi=
    s issue affects ArcGIS Server 12.0 and earlier.</td>
    <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2812" target=3D"= _blank" rel=3D"noopener">CVE-2026-2812</a></td>

    <a href=3D"https://www.esri.com/arcgis-blog/products/trust-arcgis/administr= ation/april2026_security_bulletin" target=3D"_blank" rel=3D"noopener">https= ://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_= security_bulletin</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Esri--ArcGIS Server</td>
    <td>ArcGIS Server contains an input validation weakness in the login redire= ction workflow. An Authenticated attacker could exploit this issue by sendi=
    ng a specially crafted request, Successful exploitation may result in the a= pplication redirecting the browser to an unintended, untrusted site, result= ing in a limited confidentiality impact under specific user interaction con= ditions. The vulnerability affects only the client side navigation logic du= ring authentication and remains confined to the same security boundary. No = server side compromise or cross component impact is possible.=C2=A0=C2=A0Th=
    is issue affects ArcGIS Server 11.5.</td>
    <td>2026-05-20</td>
    <td>4.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2813" target=3D"= _blank" rel=3D"noopener">CVE-2026-2813</a></td>

    <a href=3D"https://www.esri.com/arcgis-blog/products/trust-arcgis/administr= ation/april2026_security_bulletin" target=3D"_blank" rel=3D"noopener">https= ://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_= security_bulletin</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">etspring--LJ comments import: reloaded</td> <td>The LJ comments import: reloaded plugin for WordPress is vulnerable to = Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to=
    , and including, 0.97.1 due to insufficient input sanitization and output e= scaping. This makes it possible for unauthenticated attackers to inject arb= itrary web scripts in pages that execute if they can successfully trick a u= ser into performing an action such as clicking on a link. The vulnerability=
    arises specifically because PHP_SELF includes attacker-controllable PATH_I= NFO appended to the script name, and there are two distinct unsanitized ech=
    o points for this value in the same function.</td>
    <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8624" target=3D"= _blank" rel=3D"noopener">CVE-2026-8624</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f09cb= 59-dbbb-48a3-aeac-377f6ec87b88?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/0f09cb59-dbb= b-48a3-aeac-377f6ec87b88?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/lj-comments-import-reloaded/trunk/lj_comments_impor= t.php#L129" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpre= ss.org/browser/lj-comments-import-reloaded/trunk/lj_comments_import.php#L12= 9</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/lj-comments-= import-reloaded/trunk/lj_comments_import.php#L161" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/browser/lj-comments-import-re= loaded/trunk/lj_comments_import.php#L161</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">goback2--Logo Manager For Enamad</td>
    <td>The Logo Manager For Enamad plugin for WordPress is vulnerable to Store=
    d Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, = `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to=
    , and including, 0.7.4 due to insufficient input sanitization and output es= caping on user supplied attributes. This makes it possible for authenticate=
    d attackers, with contributor-level access and above, to inject arbitrary w=
    eb scripts in pages that will execute whenever a user accesses an injected = page.</td>
    <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6549" target=3D"= _blank" rel=3D"noopener">CVE-2026-6549</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/ed6d11= 67-c89d-4c97-9446-b968df945e6c?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/ed6d1167-c89= d-4c97-9446-b968df945e6c?source=3Dcve</a><br><a href=3D"https://wordpress.o= rg/plugins/logo-manager-for-enamad" target=3D"_blank" rel=3D"noopener">http= s://wordpress.org/plugins/logo-manager-for-enamad</a><br><a href=3D"https:/= /plugins.trac.wordpress.org/browser/logo-manager-for-enamad/tags/0.7.4/widg= ets.php#L295" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordp= ress.org/browser/logo-manager-for-enamad/tags/0.7.4/widgets.php#L295</a><br= ><a href=3D"https://plugins.trac.wordpress.org/browser/logo-manager-for-ena= mad/trunk/widgets.php#L295" target=3D"_blank" rel=3D"noopener">https://plug= ins.trac.wordpress.org/browser/logo-manager-for-enamad/trunk/widgets.php#L2= 95</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HCL--BigFix Service Management (SM)</td>
    <td>HCL BigFix Service Management (SM) is susceptible to a Configuration - = 'Insecure Use of Base Image Version'. Using outdated or insecure base image=
    s may introduce known vulnerabilities, potentially increasing the risk of e= xploitation in the application environment.</td>
    <td>2026-05-20</td>
    <td>4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-31973" target=3D= "_blank" rel=3D"noopener">CVE-2025-31973</a></td>

    <a href=3D"https://support.hcl-software.com/csm?id=3Dkb_article&sysparm_art= icle=3DKB0128144" target=3D"_blank" rel=3D"noopener">https://support.hcl-so= ftware.com/csm?id=3Dkb_article&sysparm_article=3DKB0128144</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">HCLSoftware--Connections</td>
    <td>HCL Connections contains a broken access control vulnerability that may=
    allow unauthorized user to update data in certain scenarios.</td> <td>2026-05-18</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-21789" target=3D= "_blank" rel=3D"noopener">CVE-2026-21789</a></td>

    <a href=3D"https://support.hcl-software.com/csm?id=3Dkb_article&sysparm_art= icle=3DKB0129719" target=3D"_blank" rel=3D"noopener">https://support.hcl-so= ftware.com/csm?id=3Dkb_article&sysparm_article=3DKB0129719</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">HCLSoftware--DominoIQ</td>
    <td>The HCL DominoIQ RAG feature is=C2=A0affected by=C2=A0a Broken Access C= ontrol vulnerability. =C2=A0Under certain circumstances, document level acc= ess restrictions will be ignored when determining what data to return from =
    an AI query. =C2=A0This could enable an authenticated attacker to view sens= itive data.</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-21836" target=3D= "_blank" rel=3D"noopener">CVE-2026-21836</a></td>

    <a href=3D"https://support.hcl-software.com/csm?id=3Dkb_article&sysparm_art= icle=3DKB0130932" target=3D"_blank" rel=3D"noopener">https://support.hcl-so= ftware.com/csm?id=3Dkb_article&sysparm_article=3DKB0130932</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">heartcombo--devise</td>
    <td>Devise is an authentication solution for Rails based on Warden. In vers= ions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the=
    FailureApp#redirect_url method returns request.referrer - the HTTP Referer=
    header, which is attacker-controllable - without validation for any non-GE=
    T request that results in a session timeout. An attacker who hosts a page w= ith an auto-submitting cross-origin form can cause a victim with an expired=
    Devise session to be redirected to an arbitrary external URL. This contras=
    ts with the GET timeout path (which uses server-side attempted_path) and De= vise's own store_location_for mechanism (which strips external hosts via ex= tract_path_from_location), both of which are protected; only the non-GET ti= meout redirect path is unprotected. Expired-session users can be silently r= edirected from the trusted app domain to attacker-controlled URLs, enabling=
    phishing and malware delivery while bypassing browser warnings. Note: Rail=
    s' built-in open-redirect protection does not mitigate this issue. Devise::= FailureApp is an ActionController::Metal app with its own isolated copy of = the relevant redirect configuration, so config.action_controller.action_on_= open_redirect =3D :raise (and the older raise_on_open_redirects setting) do=
    not reach it. This issue has been fixed in version 5.0.4.</td> <td>2026-05-22</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40295" target=3D= "_blank" rel=3D"noopener">CVE-2026-40295</a></td>

    <a href=3D"https://github.com/heartcombo/devise/security/advisories/GHSA-jp= 94-3292-c3xv" target=3D"_blank" rel=3D"noopener">https://github.com/heartco= mbo/devise/security/advisories/GHSA-jp94-3292-c3xv</a><br><a href=3D"https:= //github.com/heartcombo/devise/commit/025fe2124f9928766fc46520e999633b598d0= 360" target=3D"_blank" rel=3D"noopener">https://github.com/heartcombo/devis= e/commit/025fe2124f9928766fc46520e999633b598d0360</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">helgatheviking--KIA Subtitle</td>
    <td>The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Sit=
    e Scripting via the plugin's `the-subtitle` shortcode `before` and `after` = attributes in all versions up to, and including, 4.0.1. This is due to insu= fficient input sanitization and output escaping on user supplied attributes=
    . This makes it possible for authenticated attackers, with Contributor-leve=
    l access and above, to inject arbitrary web scripts in pages that will exec= ute whenever a user accesses an injected page.</td>
    <td>2026-05-22</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7509" target=3D"= _blank" rel=3D"noopener">CVE-2026-7509</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/a9a520= 97-0d85-4036-9b74-f35fea549607?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/a9a52097-0d8= 5-4036-9b74-f35fea549607?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subtitle.php#L359" targ= et=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/k= ia-subtitle/tags/4.0.1/kia-subtitle.php#L359</a><br><a href=3D"https://plug= ins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subtitle.php#L32=
    9" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/br= owser/kia-subtitle/tags/4.0.1/kia-subtitle.php#L329</a><br><a href=3D"https= ://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.php#L= 359" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/= browser/kia-subtitle/trunk/kia-subtitle.php#L359</a><br><a href=3D"https://= plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.php#L329=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/bro= wser/kia-subtitle/trunk/kia-subtitle.php#L329</a><br><a href=3D"https://plu= gins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle.php#L3= 69" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/b= rowser/kia-subtitle/tags/4.0.2/kia-subtitle.php#L369</a><br><a href=3D"http= s://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle= .php#L370" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpres= s.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle.php#L370</a><br>=C2=A0</=

    </tr>

    <td class=3D"vendor-product">helpstring--Child Height Predictor by Ostheime= r</td>
    <td>The Child Height Predictor by Ostheimer plugin for WordPress is vulnera= ble to Cross-Site Request Forgery in all versions up to and including 1.3. = This is due to missing nonce verification in the options() function, which = handles plugin settings updates. The form template does not include a wp_no= nce_field() call, and the handler never calls check_admin_referer() or wp_v= erify_nonce(). This makes it possible for unauthenticated attackers to tric=
    k a site administrator into clicking a link or visiting a malicious page th=
    at submits a forged POST request, causing unauthorized changes to the plugi=
    n settings such as unit preferences to be persisted to the database via upd= ate_option().</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6400" target=3D"= _blank" rel=3D"noopener">CVE-2026-6400</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc1681= a8-5f2e-45f1-96d9-797b13644607?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/dc1681a8-5f2= e-45f1-96d9-797b13644607?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/child-height-predictor/trunk/childheight.php#L149" = target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brows= er/child-height-predictor/trunk/childheight.php#L149</a><br><a href=3D"http= s://plugins.trac.wordpress.org/browser/child-height-predictor/tags/1.3/chil= dheight.php#L149" target=3D"_blank" rel=3D"noopener">https://plugins.trac.w= ordpress.org/browser/child-height-predictor/tags/1.3/childheight.php#L149</= a><br><a href=3D"https://plugins.trac.wordpress.org/browser/child-height-pr= edictor/trunk/childheight.php#L135" target=3D"_blank" rel=3D"noopener">http= s://plugins.trac.wordpress.org/browser/child-height-predictor/trunk/childhe= ight.php#L135</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/= child-height-predictor/tags/1.3/childheight.php#L135" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/child-height-predi= ctor/tags/1.3/childheight.php#L135</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Honeywell International Inc.--Control Network = Module (CNM)</td>
    <td>Honeywell Control Network Module (CNM)=C2=A0contains insertion of sensi= tive information into an unintended directory. An attacker could exploit th=
    is vulnerability through probing system files, potentially resulting in uni= ntended access to protected data.</td>
    <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5434" target=3D"= _blank" rel=3D"noopener">CVE-2026-5434</a></td>

    <a href=3D"https://process.honeywell.com/" target=3D"_blank" rel=3D"noopene= r">https://process.honeywell.com/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">infility--Infility Global</td>
    <td>The Infility Global plugin for WordPress is vulnerable to SQL Injection=
    via the 'orderby' and 'order' parameters in all versions up to, and includ= ing, 2.15.16. This is due to insufficient escaping on user supplied paramet= ers and lack of sufficient preparation on the existing SQL query within the=
    show_control_data::post_list() function, which is registered as an admin m= enu page with only the 'read' capability. This makes it possible for authen= ticated attackers, with Subscriber-level access and above, to append additi= onal SQL queries into already existing queries that can be used to extract = sensitive information from the database.</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8685" target=3D"= _blank" rel=3D"noopener">CVE-2026-8685</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/1caeb5= e0-9e4e-4c9e-a6e4-881fb81dc5f2?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/1caeb5e0-9e4= e-4c9e-a6e4-881fb81dc5f2?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/infility-global/trunk/widgets/show-control-data/sho= w-control-data.php#L34" target=3D"_blank" rel=3D"noopener">https://plugins.= trac.wordpress.org/browser/infility-global/trunk/widgets/show-control-data/= show-control-data.php#L34</a><br><a href=3D"https://plugins.trac.wordpress.= org/browser/infility-global/trunk/widgets/show-control-data/show-control-da= ta.php#L74" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpre= ss.org/browser/infility-global/trunk/widgets/show-control-data/show-control= -data.php#L74</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/= infility-global/trunk/widgets/show-control-data/show-control-data.php#L78" = target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brows= er/infility-global/trunk/widgets/show-control-data/show-control-data.php#L7= 8</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/infility-glo= bal/trunk/widgets/show-control-data/show-control-data.php#L84" target=3D"_b= lank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/infility-= global/trunk/widgets/show-control-data/show-control-data.php#L84</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Intelbras -- VIP-1230-D-G4</td>
    <td>An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a=
    remote attacker to obtain sensitive information via password reset functio= nality under /OutsideCmd</td>
    <td>2026-05-18</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36438" target=3D= "_blank" rel=3D"noopener">CVE-2026-36438</a></td>

    <a href=3D"https://backend.intelbras.com/sites/default/files/2023-03/Datash= eet%20UNIFICADO%20-%20VIP%201230%20B.D.G4-v2.pdf" target=3D"_blank" rel=3D"= noopener">https://backend.intelbras.com/sites/default/files/2023-03/Datashe= et%20UNIFICADO%20-%20VIP%201230%20B.D.G4-v2.pdf</a><br><a href=3D"https://w= ww.intelbras.com/pt-br/camera-dome-wi-fi-vip-1230-d-w-g4" target=3D"_blank"=
    rel=3D"noopener">https://www.intelbras.com/pt-br/camera-dome-wi-fi-vip-123= 0-d-w-g4</a><br><a href=3D"https://github.com/kensh1k/CVE-2026-36438/tree/m= ain" target=3D"_blank" rel=3D"noopener">https://github.com/kensh1k/CVE-2026= -36438/tree/main</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ISC--BIND 9</td>
    <td>BIND resolvers are vulnerable to an amplified resource consumption/exha= ustion attack. If a victim resolver makes a query to a specially crafted zo= ne, the resolver will consume disproportionate resources. This issue affect=
    s BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 th= rough 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.1= 1-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.</td> <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3592" target=3D"= _blank" rel=3D"noopener">CVE-2026-3592</a></td>

    <a href=3D"https://kb.isc.org/docs/cve-2026-3592" target=3D"_blank" rel=3D"= noopener">CVE-2026-3592</a><br><a href=3D"https://downloads.isc.org/isc/bin= d9/9.18.49" target=3D"_blank" rel=3D"noopener">https://downloads.isc.org/is= c/bind9/9.18.49</a><br><a href=3D"https://downloads.isc.org/isc/bind9/9.20.= 23" target=3D"_blank" rel=3D"noopener">https://downloads.isc.org/isc/bind9/= 9.20.23</a><br><a href=3D"https://downloads.isc.org/isc/bind9/9.21.22" targ= et=3D"_blank" rel=3D"noopener">https://downloads.isc.org/isc/bind9/9.21.22<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ISC--BIND 9</td>
    <td>An unbounded resend loop vulnerability exists in the BIND 9 resolver st= ate machine during bad-server handling, enabling a remote unauthenticated a= ttacker to cause severe resource exhaustion by sending queries that trigger=
    specific retry conditions. This issue affects BIND 9 versions 9.18.36 thro= ugh 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 thr= ough 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.</td>
    <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5950" target=3D"= _blank" rel=3D"noopener">CVE-2026-5950</a></td>

    <a href=3D"https://kb.isc.org/docs/cve-2026-5950" target=3D"_blank" rel=3D"= noopener">CVE-2026-5950</a><br><a href=3D"https://downloads.isc.org/isc/bin= d9/9.18.49" target=3D"_blank" rel=3D"noopener">https://downloads.isc.org/is= c/bind9/9.18.49</a><br><a href=3D"https://downloads.isc.org/isc/bind9/9.20.= 23" target=3D"_blank" rel=3D"noopener">https://downloads.isc.org/isc/bind9/= 9.20.23</a><br><a href=3D"https://downloads.isc.org/isc/bind9/9.21.22" targ= et=3D"_blank" rel=3D"noopener">https://downloads.isc.org/isc/bind9/9.21.22<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ItzCrazyKns--Vane</td>
    <td>A security vulnerability has been detected in ItzCrazyKns Vane up to 1.= 12.1. Affected by this issue is some unknown functionality of the file rout= e.ts of the component API. The manipulation leads to missing authentication=
    . The attack may be initiated remotely. The attack's complexity is rated as=
    high. The exploitation is known to be difficult. The exploit has been disc= losed publicly and may be used. It appears that basic authentication is pla= nned.</td>
    <td>2026-05-24</td>
    <td>5.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9371" target=3D"= _blank" rel=3D"noopener">CVE-2026-9371</a></td>

    <a href=3D"https://vuldb.com/vuln/365334" target=3D"_blank" rel=3D"noopener= ">VDB-365334 | ItzCrazyKns Vane API route.ts missing authentication</a><br>=
    <a href=3D"https://vuldb.com/vuln/365334/cti" target=3D"_blank" rel=3D"noop= ener">VDB-365334 | CTI Indicators (IOB, IOC, IOA)</a><br><a href=3D"https:/= /vuldb.com/submit/813209" target=3D"_blank" rel=3D"noopener">Submit #813209=
    | ItzCrazyKns Vane 1.12.1 API Key Exposure</a><br><a href=3D"https://vuldb= .com/submit/813210" target=3D"_blank" rel=3D"noopener">Submit #813210 | Itz= CrazyKns Vane 1.12.1 Missing Authentication for Critical Function (Duplicat= e)</a><br><a href=3D"https://github.com/ItzCrazyKns/Vane/issues/1122" targe= t=3D"_blank" rel=3D"noopener">https://github.com/ItzCrazyKns/Vane/issues/11= 22</a><br><a href=3D"https://github.com/ItzCrazyKns/Vane/issues/1123" targe= t=3D"_blank" rel=3D"noopener">https://github.com/ItzCrazyKns/Vane/issues/11= 23</a><br><a href=3D"https://github.com/ItzCrazyKns/Vane/" target=3D"_blank=
    " rel=3D"noopener">https://github.com/ItzCrazyKns/Vane/</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">jarrodwatts--claude-hud</td>
    <td>Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 = terminal hyperlink escape sequences using raw cwd and branchUrl values with= out stripping control characters or encoding embedded values, allowing atta= ckers to inject arbitrary ANSI codes into terminal sessions. Attackers can = embed ESC+backslash sequences in the current working directory or branch UR=
    L to execute malicious ANSI codes including text color changes, forged prom= pts, and OSC 52 clipboard writes, or trigger outbound HTTP requests to atta= cker-controlled remotes when hyperlinks are clicked.</td>
    <td>2026-05-18</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47090" target=3D= "_blank" rel=3D"noopener">CVE-2026-47090</a></td>

    <a href=3D"https://github.com/jarrodwatts/claude-hud/issues/485" target=3D"= _blank" rel=3D"noopener">https://github.com/jarrodwatts/claude-hud/issues/4= 85</a><br><a href=3D"https://github.com/jarrodwatts/claude-hud/pull/487" ta= rget=3D"_blank" rel=3D"noopener">https://github.com/jarrodwatts/claude-hud/= pull/487</a><br><a href=3D"https://github.com/jarrodwatts/claude-hud/commit= /234d9aad919b51326a43bcf90b45ae35c23afc30" target=3D"_blank" rel=3D"noopene= r">https://github.com/jarrodwatts/claude-hud/commit/234d9aad919b51326a43bcf= 90b45ae35c23afc30</a><br><a href=3D"https://www.vulncheck.com/advisories/cl= aude-hud-terminal-injection-via-osc-8-hyperlinks" target=3D"_blank" rel=3D"= noopener">https://www.vulncheck.com/advisories/claude-hud-terminal-injectio= n-via-osc-8-hyperlinks</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">javibola--JaviBola Custom Theme Test</td>
    <td>The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cr= oss-Site Request Forgery in all versions up to, and including, 2.0.5. This =
    is due to missing or incorrect nonce validation on the options page. This m= akes it possible for unauthenticated attackers to change the site's active = theme by modifying the jbct_theme option via a forged request granted they = can trick a site administrator into performing an action such as clicking o=
    n a link.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8423" target=3D"= _blank" rel=3D"noopener">CVE-2026-8423</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/68a8a2= 77-2ea6-4d75-b8cd-4d20eb17b3aa?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/68a8a277-2ea= 6-4d75-b8cd-4d20eb17b3aa?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/javibola-custom-theme/trunk/javibola-custom-theme.p= hp#L41" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.o= rg/browser/javibola-custom-theme/trunk/javibola-custom-theme.php#L41</a><br= ><a href=3D"https://plugins.trac.wordpress.org/browser/javibola-custom-them= e/tags/2.0.5/javibola-custom-theme.php#L41" target=3D"_blank" rel=3D"noopen= er">https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2= .0.5/javibola-custom-theme.php#L41</a><br><a href=3D"https://plugins.trac.w= ordpress.org/browser/javibola-custom-theme/trunk/javibola-custom-theme.php#= L40" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/= browser/javibola-custom-theme/trunk/javibola-custom-theme.php#L40</a><br><a=
    href=3D"https://plugins.trac.wordpress.org/browser/javibola-custom-theme/t= ags/2.0.5/javibola-custom-theme.php#L40" target=3D"_blank" rel=3D"noopener"= >https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.= 5/javibola-custom-theme.php#L40</a><br><a href=3D"https://plugins.trac.word= press.org/browser/javibola-custom-theme/trunk/javibola-custom-theme.php#L54=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/bro= wser/javibola-custom-theme/trunk/javibola-custom-theme.php#L54</a><br><a hr= ef=3D"https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags= /2.0.5/javibola-custom-theme.php#L54" target=3D"_blank" rel=3D"noopener">ht= tps://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5/j= avibola-custom-theme.php#L54</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">jay_patel--Remove Yellow BGBOX</td>
    <td>The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Sit=
    e Request Forgery in all versions up to, and including, 1.0. This is due to=
    missing or incorrect nonce validation on the 'rybb_api_settings' page. Thi=
    s makes it possible for unauthenticated attackers to reset the plugin's sto= red settings by overwriting its configuration via a forged request granted = they can trick a site administrator into performing an action such as click= ing on a link.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8424" target=3D"= _blank" rel=3D"noopener">CVE-2026-8424</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5b30d= 27-a3f8-4535-a47f-675c939ec648?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/c5b30d27-a3f= 8-4535-a47f-675c939ec648?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/remove-yellow-bgbox/trunk/admin/rybb_api_settings.p= hp#L5" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.or= g/browser/remove-yellow-bgbox/trunk/admin/rybb_api_settings.php#L5</a><br><=
    a href=3D"https://plugins.trac.wordpress.org/browser/remove-yellow-bgbox/ta= gs/1.0/admin/rybb_api_settings.php#L5" target=3D"_blank" rel=3D"noopener">h= ttps://plugins.trac.wordpress.org/browser/remove-yellow-bgbox/tags/1.0/admi= n/rybb_api_settings.php#L5</a><br><a href=3D"https://plugins.trac.wordpress= .org/browser/remove-yellow-bgbox/trunk/includes/functions.php#L16" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/rem= ove-yellow-bgbox/trunk/includes/functions.php#L16</a><br><a href=3D"https:/= /plugins.trac.wordpress.org/browser/remove-yellow-bgbox/tags/1.0/includes/f= unctions.php#L16" target=3D"_blank" rel=3D"noopener">https://plugins.trac.w= ordpress.org/browser/remove-yellow-bgbox/tags/1.0/includes/functions.php#L1= 6</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">jetmonsters--MotoPress Hotel Booking</td>
    <td>The MotoPress Hotel Booking plugin for WordPress is vulnerable to autho= rization bypass in all versions up to, and including, 6.0.1. This is due to=
    the plugin not properly verifying that a user is authorized to perform an = action. This makes it possible for unauthenticated attackers to overwrite o=
    r delete the internal notes (_mphb_booking_internal_notes) of any booking b=
    y supplying an arbitrary booking ID. The nonce for this action is output in=
    the HTML source of every public page through wp_localize_script (MPHB._dat= a.nonces), so any unauthenticated visitor can obtain a valid nonce and perf= orm the action without any account or prior interaction.</td> <td>2026-05-22</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8684" target=3D"= _blank" rel=3D"noopener">CVE-2026-8684</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/6567e6= 3c-3129-47b2-a734-733eb599821a?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/6567e63c-312= 9-47b2-a734-733eb599821a?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/motopress-hotel-booking-lite/tags/6.0.1/includes/aj= ax-api/ajax-actions/update-booking-notes.php#L83" target=3D"_blank" rel=3D"= noopener">https://plugins.trac.wordpress.org/browser/motopress-hotel-bookin= g-lite/tags/6.0.1/includes/ajax-api/ajax-actions/update-booking-notes.php#L= 83</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/motopress-h= otel-booking-lite/tags/6.0.1/includes/ajax-api/ajax-actions/abstract-ajax-a= pi-action.php#L34" target=3D"_blank" rel=3D"noopener">https://plugins.trac.= wordpress.org/browser/motopress-hotel-booking-lite/tags/6.0.1/includes/ajax= -api/ajax-actions/abstract-ajax-api-action.php#L34</a><br><a href=3D"https:= //plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tags/6.0.= 1/includes/ajax-api/ajax-api-handler.php#L43" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-li= te/tags/6.0.1/includes/ajax-api/ajax-api-handler.php#L43</a><br><a href=3D"= https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tag= s/5.4.1/includes/ajax-api/ajax-actions/update-booking-notes.php#L83" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/mot= opress-hotel-booking-lite/tags/5.4.1/includes/ajax-api/ajax-actions/update-= booking-notes.php#L83</a><br><a href=3D"https://plugins.trac.wordpress.org/= browser/motopress-hotel-booking-lite/tags/5.4.1/includes/ajax-api/ajax-acti= ons/abstract-ajax-api-action.php#L34" target=3D"_blank" rel=3D"noopener">ht= tps://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/tags/= 5.4.1/includes/ajax-api/ajax-actions/abstract-ajax-api-action.php#L34</a><b= r><a href=3D"https://plugins.trac.wordpress.org/browser/motopress-hotel-boo= king-lite/tags/5.4.1/includes/ajax-api/ajax-api-handler.php#L43" target=3D"= _blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/motopre= ss-hotel-booking-lite/tags/5.4.1/includes/ajax-api/ajax-api-handler.php#L43= </a><br><a href=3D"https://plugins.trac.wordpress.org/changeset/3537354/mot= opress-hotel-booking-lite/trunk/includes/ajax-api/ajax-actions/update-booki= ng-notes.php" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordp= ress.org/changeset/3537354/motopress-hotel-booking-lite/trunk/includes/ajax= -api/ajax-actions/update-booking-notes.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Jomres--Jomres</td>
    <td>Joomla Component jomres 9.11.2 contains a cross-site request forgery vu= lnerability that allows attackers to modify user account information by tri= cking authenticated users into visiting malicious pages. Attackers can craf=
    t HTML forms targeting the account/index endpoint with hidden fields to cha= nge passwords, email addresses, and profile details without user consent.</=

    <td>2026-05-23</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25354" target=3D= "_blank" rel=3D"noopener">CVE-2018-25354</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44901" target=3D"_blank" rel= =3D"noopener">ExploitDB-44901</a><br><a href=3D"https://www.jomres.net/" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://extensions.joomla.org/extension/jomres/" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com= /advisories/joomla-component-jomres-cross-site-request-forgery" target=3D"_= blank" rel=3D"noopener">VulnCheck Advisory: Joomla Component jomres 9.11.2 = Cross-Site Request Forgery</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">jupyterhub--jupyterhub</td>
    <td>JupyterHub is software that allows users to create a multi-user server = for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (up= dated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-co=
    rs as same-origin requests, bypassing XSRF checks. The JSON API is not affe= cted, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, m= eaning attackers could trigger server spawn (but not access the server) and=
    if the attacker is a JupyterHub user permitted to share access to their se= rver, cause a user to accept a share and have access to the attacker's serv= er. This issue has been fixed in version 5.4.5. If developers are unable to=
    immediately upgrade, they can temporarily mitigate this issue by dropping = requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a rev= erse proxy.</td>
    <td>2026-05-22</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40864" target=3D= "_blank" rel=3D"noopener">CVE-2026-40864</a></td>

    <a href=3D"https://github.com/jupyterhub/jupyterhub/security/advisories/GHS= A-m68r-v472-jgq9" target=3D"_blank" rel=3D"noopener">https://github.com/jup= yterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9</a><br><a href= =3D"https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c= 8117efa77bd941127" target=3D"_blank" rel=3D"noopener">https://github.com/ju= pyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">kasparsd--Widget Context</td>
    <td>The Widget Context plugin for WordPress is vulnerable to Cross-Site Req= uest Forgery in all versions up to, and including, 1.3.3. This is due to mi= ssing or incorrect nonce validation on the save_widget_context_settings fun= ction. This makes it possible for unauthenticated attackers to modify widge=
    t visibility context settings stored in the WordPress options table via a f= orged POST request to /wp-admin/widgets.php via a forged request granted th=
    ey can trick a site administrator into performing an action such as clickin=
    g on a link.</td>
    <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7615" target=3D"= _blank" rel=3D"noopener">CVE-2026-7615</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c4346= 37-4bf9-46ee-9a6d-35eab7ef11a1?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/3c434637-4bf= 9-46ee-9a6d-35eab7ef11a1?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/widget-context/trunk/src/WidgetContext.php#L311" ta= rget=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser= /widget-context/trunk/src/WidgetContext.php#L311</a><br><a href=3D"https://= plugins.trac.wordpress.org/browser/widget-context/tags/1.3.3/src/WidgetCont= ext.php#L311" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordp= ress.org/browser/widget-context/tags/1.3.3/src/WidgetContext.php#L311</a><b= r><a href=3D"https://plugins.trac.wordpress.org/browser/widget-context/trun= k/src/WidgetContext.php#L282" target=3D"_blank" rel=3D"noopener">https://pl= ugins.trac.wordpress.org/browser/widget-context/trunk/src/WidgetContext.php= #L282</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/widget-c= ontext/tags/1.3.3/src/WidgetContext.php#L282" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/widget-context/tags/1.3.3/= src/WidgetContext.php#L282</a><br><a href=3D"https://plugins.trac.wordpress= .org/browser/widget-context/trunk/src/WidgetContext.php#L91" target=3D"_bla= nk" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/widget-cont= ext/trunk/src/WidgetContext.php#L91</a><br><a href=3D"https://plugins.trac.= wordpress.org/browser/widget-context/tags/1.3.3/src/WidgetContext.php#L91" = target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brows= er/widget-context/tags/1.3.3/src/WidgetContext.php#L91</a><br><a href=3D"ht= tps://github.com/kasparsd/widget-context-wporg/pull/73" target=3D"_blank" r= el=3D"noopener">https://github.com/kasparsd/widget-context-wporg/pull/73</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Kieback &amp; Peter--DDC4002</td>
    <td>The affected=C2=A0Kieback &amp; Peter DDC building controllers=C2=A0are=
    vulnerable to cross-site scripting, enabling JavaScript to be executed by = the victim's browser, which allows the attacker to control the browser.</td=

    <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4293" target=3D"= _blank" rel=3D"noopener">CVE-2026-4293</a></td>

    <a href=3D"https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05" = target=3D"_blank" rel=3D"noopener">https://www.cisa.gov/news-events/ics-adv= isories/icsa-26-139-05</a><br><a href=3D"https://github.com/cisagov/CSAF/bl= ob/develop/csaf_files/OT/white/2026/icsa-26-139-05.json" target=3D"_blank" = rel=3D"noopener">https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT= /white/2026/icsa-26-139-05.json</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ktulhu--Bigfishgames Syndicate</td>
    <td>The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-= Site Request Forgery in all versions up to, and including, 1.2. This is due=
    to missing or incorrect nonce validation on the bigfishgames_syndicate_sub= menu() function. This makes it possible for unauthenticated attackers to re= set plugin settings and update them via a forged request granted they can t= rick a site administrator into performing an action such as clicking on a l= ink.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6452" target=3D"= _blank" rel=3D"noopener">CVE-2026-6452</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/67877a= 2e-a45d-4674-b749-05d9217ef6bf?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/67877a2e-a45= d-4674-b749-05d9217ef6bf?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/bigfishgames-syndicate/trunk/bigfishgames-syndicate= .php#L238" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpres= s.org/browser/bigfishgames-syndicate/trunk/bigfishgames-syndicate.php#L238<= /a><br><a href=3D"https://plugins.trac.wordpress.org/browser/bigfishgames-s= yndicate/tags/1.2/bigfishgames-syndicate.php#L238" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/browser/bigfishgames-syndicat= e/tags/1.2/bigfishgames-syndicate.php#L238</a><br><a href=3D"https://plugin= s.trac.wordpress.org/browser/bigfishgames-syndicate/trunk/bigfishgames-synd= icate.php#L169" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wor= dpress.org/browser/bigfishgames-syndicate/trunk/bigfishgames-syndicate.php#= L169</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/bigfishga= mes-syndicate/tags/1.2/bigfishgames-syndicate.php#L169" target=3D"_blank" r= el=3D"noopener">https://plugins.trac.wordpress.org/browser/bigfishgames-syn= dicate/tags/1.2/bigfishgames-syndicate.php#L169</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">langgenius--dify</td>
    <td>Dify version 1.14.1 and prior contain an authorization bypass vulnerabi= lity in the file preview endpoint that allows any authenticated user to rea=
    d up to 3,000 characters of any uploaded document across all tenants and wo= rkspaces using only the file's UUID. Attackers can access the /console/api/= files/{file_id}/preview endpoint with an intercepted file UUID to extract s= ensitive content from documents without ownership or workspace permission v= erification. NOTE: Dify Cloud allows unauthenticated free self-registration=
    , making account creation trivially accessible to any attacker.</td> <td>2026-05-18</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41949" target=3D= "_blank" rel=3D"noopener">CVE-2026-41949</a></td>

    <a href=3D"https://huntr.com/bounties/d50a0240-7951-4939-b989-9bded66c7682"=
    target=3D"_blank" rel=3D"noopener">https://huntr.com/bounties/d50a0240-795= 1-4939-b989-9bded66c7682</a><br><a href=3D"https://github.com/langgenius/di= fy/pull/35797" target=3D"_blank" rel=3D"noopener">https://github.com/langge= nius/dify/pull/35797</a><br><a href=3D"https://www.vulncheck.com/advisories= /dify-authorization-bypass-via-file-preview-endpoint" target=3D"_blank" rel= =3D"noopener">https://www.vulncheck.com/advisories/dify-authorization-bypas= s-via-file-preview-endpoint</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">laurent22--joplin</td>
    <td>Joplin is an open source note-taking and to-do application that organis=
    es notes and lists into notebooks. Versions 3.6.14 and prior contain a Deni=
    al of Service (DoS) vulnerability in the title input functionality due to a=
    lack of proper length validation. This flaw allows an attacker to cause an=
    Out Of Memory (OOM) error and subsequent program termination by inserting =
    an excessively long string into a note's title. This can be triggered eithe=
    r through direct user interface (UI) input or programmatically via the loca=
    l web service API after compromising an authentication token. There are 2 p= rimary methods of exploitation: via User Interface (UI) Input, and the Loca=
    l Web Service API. A local user can directly type or paste an extremely lon=
    g string into the title field when creating or editing a note Joplin runs a=
    local web service (typically on port 41184) that allows programmatic inter= action, such as creating or editing notes via HTTP API calls. If an attacke=
    r manages to exfiltrate or compromise the user's authentication token (e.g.=
    , through malware on the local system, or other local vulnerabilities), the=
    y can then send a crafted HTTP POST request to this local API. By including=
    an excessively long string in the title parameter of this request, the app= lication will attempt to allocate an unbounded amount of memory. This issue=
    has been patched in version 3.7.1.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-57798" target=3D= "_blank" rel=3D"noopener">CVE-2025-57798</a></td>

    <a href=3D"https://github.com/laurent22/joplin/security/advisories/GHSA-6jm= 8-gr87-q69x" target=3D"_blank" rel=3D"noopener">https://github.com/laurent2= 2/joplin/security/advisories/GHSA-6jm8-gr87-q69x</a><br><a href=3D"https://= github.com/laurent22/joplin/commit/5b8795da446a5a40c9e212c98b35e368ffce628e=
    " target=3D"_blank" rel=3D"noopener">https://github.com/laurent22/joplin/co= mmit/5b8795da446a5a40c9e212c98b35e368ffce628e</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">laurent22--joplin</td>
    <td>Joplin is an open source note-taking and to-do application that organis=
    es notes and lists into notebooks. Versions 3.5.2 and prior contain a logic=
    error in the delta API that allows share recipients to download notes that=
    are no longer shared with them, related to but not fully fixed by the prio=
    r patch in #14289. In ChangeModel.delta, when DELTA_INCLUDES_ITEMS is enabl=
    ed (the default), the latest state of items is attached to delta output wit= hout verifying that those items are still shared with the requesting user, = and the existing removal logic only filters items deleted for all users. Ad= ditionally, the change compression logic incorrectly reduces create - delet=
    e to NOOP, which is unsafe because compression is applied per page and an i= tem can have multiple create events; if an earlier create falls on a separa=
    te page from a later create -&gt; delete pair, the deletion is dropped and = the sequence collapses to a create. As a result, the delta API returns a cr= eate event for a deleted item with the full latest content attached, exposi=
    ng notes the user no longer has access to. This issue has been fixed in ver= sion 3.5.3.</td>
    <td>2026-05-19</td>
    <td>5.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34600" target=3D= "_blank" rel=3D"noopener">CVE-2026-34600</a></td>

    <a href=3D"https://github.com/laurent22/joplin/security/advisories/GHSA-88x= 4-77rc-jw94" target=3D"_blank" rel=3D"noopener">https://github.com/laurent2= 2/joplin/security/advisories/GHSA-88x4-77rc-jw94</a><br><a href=3D"https://= github.com/laurent22/joplin/issues/14110" target=3D"_blank" rel=3D"noopener= ">https://github.com/laurent22/joplin/issues/14110</a><br><a href=3D"https:= //github.com/laurent22/joplin/pull/14289" target=3D"_blank" rel=3D"noopener= ">https://github.com/laurent22/joplin/pull/14289</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Ledger--Ledger Bitcoin app</td>
    <td>Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivati=
    on vulnerability that allows attackers to cause incorrect Bitcoin addresses=
    to be displayed by exploiting improper handling of miniscript policies con= taining the a: fragment. Attackers can craft malicious miniscript policies = that cause the device to derive and display incorrect receiving addresses, = potentially leading to funds being sent to unintended addresses.</td> <td>2026-05-20</td>
    <td>4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-7346" target=3D"= _blank" rel=3D"noopener">CVE-2023-7346</a></td>

    <a href=3D"https://donjon.ledger.com/lsb/019/" target=3D"_blank" rel=3D"noo= pener">Ledger Security Bulletin 019</a><br><a href=3D"https://www.vulncheck= .com/advisories/ledger-bitcoin-app-address-derivation-error-via-miniscript"=
    target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/le= dger-bitcoin-app-address-derivation-error-via-miniscript</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">Ledger--Ledger Nano X</td>
    <td>Ledger Nano X, Flex, and Stax devices contain a denial of service vulne= rability in the MCU firmware update process due to missing validation of th=
    e reset_handler parameter during firmware flashing. An attacker can provide=
    a crafted reset_handler address pointing to invalid memory or attacker-con= trolled code to cause the device to enter an unrecoverable fault state duri=
    ng boot, resulting in permanent loss of operability.</td>
    <td>2026-05-19</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15645" target=3D= "_blank" rel=3D"noopener">CVE-2025-15645</a></td>

    <a href=3D"https://donjon.ledger.com/lsb/021/" target=3D"_blank" rel=3D"noo= pener">Ledger Security Bulletin 021</a><br><a href=3D"https://www.vulncheck= .com/advisories/ledger-nano-x-flex-stax-mcu-firmware-update-denial-of-servi= ce" target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories= /ledger-nano-x-flex-stax-mcu-firmware-update-denial-of-service</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Ledger--ledgerhq/hw-app-eth</td>
    <td>Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.= 34.7 contains an integer parsing vulnerability that allows attackers to man= ipulate EIP-712 typed data messages by exploiting incorrect hexadecimal fie=
    ld parsing when values contain an odd number of characters. Attackers can o= btain signatures on truncated or misinterpreted message values to authorize=
    unintended blockchain transactions, such as asset transfers at incorrect a= mounts.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-7345" target=3D"= _blank" rel=3D"noopener">CVE-2023-7345</a></td>

    <a href=3D"https://donjon.ledger.com/lsb/020/" target=3D"_blank" rel=3D"noo= pener">Ledger Security Bulletin 020</a><br><a href=3D"https://www.vulncheck= .com/advisories/ledger-live-hw-app-eth-eip-712-message-parsing-integer-trun= cation" target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/adviso= ries/ledger-live-hw-app-eth-eip-712-message-parsing-integer-truncation</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">linlinjava--litemall</td>
    <td>A security vulnerability has been detected in linlinjava litemall up to=
    1.8.0. Affected by this vulnerability is the function backup/load of the f= ile litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java o=
    f the component Database Setting Handler. The manipulation of the argument = db/password leads to argument injection. The attack is possible to be carri=
    ed out remotely. The exploit has been disclosed publicly and may be used. T=
    he vendor was contacted early about this disclosure but did not respond in = any way.</td>
    <td>2026-05-18</td>
    <td>4.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8773" target=3D"= _blank" rel=3D"noopener">CVE-2026-8773</a></td>

    <a href=3D"https://vuldb.com/vuln/364398" target=3D"_blank" rel=3D"noopener= ">VDB-364398 | linlinjava litemall Database Setting DbUtil.java load argume=
    nt injection</a><br><a href=3D"https://vuldb.com/vuln/364398/cti" target=3D= "_blank" rel=3D"noopener">VDB-364398 | CTI Indicators (IOB, IOC, TTP, IOA)<= /a><br><a href=3D"https://vuldb.com/submit/811469" target=3D"_blank" rel=3D= "noopener">Submit #811469 | linlinjava litemall up to 1.8.0 Argument Inject= ion</a><br><a href=3D"https://gist.github.com/A1AAAAAAAAAA1/d5ae30a17744459= e7cc5902fff32a35b" target=3D"_blank" rel=3D"noopener">https://gist.github.c= om/A1AAAAAAAAAA1/d5ae30a17744459e7cc5902fff32a35b</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Live Networks, Inc.--LIVE555</td>
    <td>LIVE555 before 2026.04.22 contains an authorization bypass vulnerabilit=
    y in RTSP session command handling that allows attackers to replay valid Se= ssion tokens from unauthenticated connections. Attackers who obtain a valid=
    Session token can issue PLAY and TEARDOWN commands from a second TCP conne= ction without authentication, causing server crashes through virtual functi=
    on call errors or disrupting active streams by terminating victim sessions.= </td>
    <td>2026-05-19</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41470" target=3D= "_blank" rel=3D"noopener">CVE-2026-41470</a></td>

    <a href=3D"https://gist.github.com/yhcho0405/ee9b67a96808ef19f22e8a4ee88c79= 5f" target=3D"_blank" rel=3D"noopener">https://gist.github.com/yhcho0405/ee= 9b67a96808ef19f22e8a4ee88c795f</a><br><a href=3D"https://download.live555.c= om/" target=3D"_blank" rel=3D"noopener">https://download.live555.com/</a><b= r><a href=3D"https://www.vulncheck.com/advisories/live555-rtsp-server-autho= rization-bypass-via-session-token" target=3D"_blank" rel=3D"noopener">https= ://www.vulncheck.com/advisories/live555-rtsp-server-authorization-bypass-vi= a-session-token</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">lykich--Correct Prices</td>
    <td>The Correct Prices plugin for WordPress is vulnerable to Reflected Cros= s-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to an=
    d including 1.0. This is due to the correct_prices_page() function echoing = $_SERVER['PHP_SELF'] into a form's action attribute without any input sanit= ization or output escaping (such as esc_url() or esc_attr()). Because PHP_S= ELF reflects attacker-controlled path-info appended to the script URL, an a= ttacker can break out of the attribute and inject arbitrary markup. This ma= kes it possible for unauthenticated attackers to inject arbitrary web scrip=
    ts in pages that execute if they can successfully trick a user into perform= ing an action such as clicking on a specially crafted link.</td> <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8627" target=3D"= _blank" rel=3D"noopener">CVE-2026-8627</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/605c6c= 53-6920-42ba-8784-b3a186bbf821?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/605c6c53-692= 0-42ba-8784-b3a186bbf821?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/correct-prices/trunk/correct_prices.php#L134" targe= t=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/co= rrect-prices/trunk/correct_prices.php#L134</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Magepeople inc.--WpBookingly</td>
    <td>Missing Authorization vulnerability in Magepeople inc. WpBookingly allo=
    ws Exploiting Incorrectly Configured Access Control Security Levels. This i= ssue affects WpBookingly: from n/a through 1.2.9.</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27405" target=3D= "_blank" rel=3D"noopener">CVE-2026-27405</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/service-booking= -manager/vulnerability/wordpress-wpbookingly-plugin-1-2-9-broken-access-con= trol-vulnerability?_s_id=3Dcve" target=3D"_blank" rel=3D"noopener">https://= patchstack.com/database/wordpress/plugin/service-booking-manager/vulnerabil= ity/wordpress-wpbookingly-plugin-1-2-9-broken-access-control-vulnerability?= _s_id=3Dcve</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">makeplane--plane</td>
    <td>Plane is an open-source project management tool. In versions 1.3.0 and = below, SavedAnalyticEndpoint passes the user-controlled segment query param= eter directly to a Django F() expression without validation (unlike the reg= ular AnalyticsEndpoint, which checks against an allowlist), causing ORM Fie=
    ld Reference Injection. An authenticated workspace MEMBER can send GET /api= /workspaces/&lt;slug&gt;/saved-analytic-view/&lt;analytic_id&gt;/ with a cr= afted segment value that is forwarded into build_graph_plot() and traverses=
    foreign-key relationships (e.g. workspace__owner__password) before being p= rojected via .values("dimension", "segment"), returning the referenced fiel=
    d values directly in the JSON response. This exposes sensitive data such as=
    bcrypt password hashes, API tokens, and related users' email addresses, ma= king it a stronger primitive than the related order_by injection where valu=
    es are only leaked through ordering. This issue has been fixed in version 1= .3.1.</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40102" target=3D= "_blank" rel=3D"noopener">CVE-2026-40102</a></td>

    <a href=3D"https://github.com/makeplane/plane/security/advisories/GHSA-93x3= -ghh7-72j3" target=3D"_blank" rel=3D"noopener">https://github.com/makeplane= /plane/security/advisories/GHSA-93x3-ghh7-72j3</a><br><a href=3D"https://gi= thub.com/makeplane/plane/releases/tag/v1.3.1" target=3D"_blank" rel=3D"noop= ener">https://github.com/makeplane/plane/releases/tag/v1.3.1</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">manchumahara--CBX 5 Star Rating &amp; Review</=

    <td>The CBX 5 Star Rating &amp; Review plugin for WordPress is vulnerable t=
    o Reflected Cross-Site Scripting via the 'page' parameter in all versions u=
    p to, and including, 1.0.7 due to insufficient input sanitization and outpu=
    t escaping. This makes it possible for unauthenticated attackers to inject = arbitrary web scripts in pages that execute if they can successfully trick =
    an administrator into performing an action such as clicking on a link.</td> <td>2026-05-22</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6864" target=3D"= _blank" rel=3D"noopener">CVE-2026-6864</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee11e= 19-21a6-45df-a118-f6dec3b55bc1?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee11e19-21a= 6-45df-a118-f6dec3b55bc1?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/cbxscratingreview/tags/1.0.7/templates/admin/admin-= rating-review-rating-avg-logs.php#L41" target=3D"_blank" rel=3D"noopener">h= ttps://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.7/temp= lates/admin/admin-rating-review-rating-avg-logs.php#L41</a><br><a href=3D"h= ttps://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.7/temp= lates/admin/admin-rating-review-review-logs.php#L41" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/cbxscratingreview/= tags/1.0.7/templates/admin/admin-rating-review-review-logs.php#L41</a><br><=
    a href=3D"https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags= /1.0.8/templates/admin/admin-rating-review-review-logs.php" target=3D"_blan=
    k" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/cbxscratingr= eview/tags/1.0.8/templates/admin/admin-rating-review-review-logs.php</a><br= ><a href=3D"https://plugins.trac.wordpress.org/browser/cbxscratingreview/ta= gs/1.0.8/templates/admin/admin-rating-review-rating-avg-logs.php" target=3D= "_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/cbxscr= atingreview/tags/1.0.8/templates/admin/admin-rating-review-rating-avg-logs.= php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and below contain flawed logic that causes improper escaping of a t= extarea custom field's contents in the Update Issue page, (bug_update_page.= php) allowing an attacker to inject HTML and, if CSP settings permit, execu=
    te arbitrary JavaScript when the page is loaded. This facilitates session t= heft, leading to admin account takeover, full project data access. In order=
    to exploit this issue, a textarea-type custom field must be configured for=
    the project, the attack must be carried out by an authenticated user with = bug report permission (low privilege). This can affect any user viewing the=
    bug edit form, including administrators. The issue has been fixed in versi=
    on 2.28.2. If users cannot immediately upgrade, they can work around the is= sue by using the default Content-Security Policy, which blocks script execu= tion.</td>
    <td>2026-05-20</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39960" target=3D= "_blank" rel=3D"noopener">CVE-2026-39960</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-qj= 6w-v29q-4rgx" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-qj6w-v29q-4rgx</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/5fec0f448b7a7d7d539a6adb6dccceac4e4e4= ab7" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/5fec0f448b7a7d7d539a6adb6dccceac4e4e4ab7</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and prior allow an authenticated user to upload attachments to priv= ate Issues they are not authorized to access. This issue has been fixed in = version 2.28.2.</td>
    <td>2026-05-19</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34754" target=3D= "_blank" rel=3D"noopener">CVE-2026-34754</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4= x5-gvx6-3rwc" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a6275= 206" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/b262b4d2835b81394d75356dead66e52a6275206</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36976" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36976</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost Mobile Apps versions &lt;=3D2.37 11.4 2.0.37 11.0.4 11.1.3 1= 1.3.2 10.11.11.0 fail to properly validate the SSO authentication callback = origin which allows an attacker controlling a malicious Mattermost server t=
    o steal user credentials for a legitimate Mattermost server via relaying th=
    e SSO code exchange flow through the mobile application. Mattermost Advisor=
    y ID: MMSA-2025-00564</td>
    <td>2026-05-21</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22880" target=3D= "_blank" rel=3D"noopener">CVE-2026-22880</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2025-00564</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost Plugins versions &lt;=3D11.5 11.1.5 10.13.11 11.3.4.0 fail t=
    o properly check for permissions when processing commands in the Gitlab plu= gin which allows normal users to uninstall instances or setup webhook conne= ctions via the {{gitlab instance {option}}} or the {{/gitlab webhook {optio= n}}} commands. Mattermost Advisory ID: MMSA-2026-00600</td>
    <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3117" target=3D"= _blank" rel=3D"noopener">CVE-2026-3117</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00600</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost Desktop App versions &lt;=3D6.1 6.0.1 5.4.13.0 fail to preve=
    nt an invalid URL from loading in a pop-up window in the Mattermost Desktop=
    App which allows a malicious server owner to repeated crash the applicatio=
    n via calling {{window.open('javascript:alert()');}}. Mattermost Advisory I=
    D: MMSA-2026-00618</td>
    <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3471" target=3D"= _blank" rel=3D"noopener">CVE-2026-3471</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00618</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to archive the channel befo=
    re removing persistent notifications which allows authenticated user to cra=
    sh the server via timing the creation of persistent notification message be= tween the server deleting existing persistent notifications and archiving t=
    he channel.. Mattermost Advisory ID: MMSA-2026-00637</td>
    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4635" target=3D"= _blank" rel=3D"noopener">CVE-2026-4635</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00637</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1 fail to verify channel member= ship when processing AI-assisted message rewrites which allows an authentic= ated attacker to read the content of threads in private channels and direct=
    messages they do not have access to via a crafted request to the post rewr= ite endpoint.. Mattermost Advisory ID: MMSA-2026-00645</td>
    <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5163" target=3D"= _blank" rel=3D"noopener">CVE-2026-5163</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00645</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.2, 11.5.=
    x &lt;=3D 11.5.3, 11.4.x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to v= alidate the TIFF IFD offset in the image header before allocating memory, w= hich allows authenticated users with file upload or posting permissions to = cause a denial of service (server OOM) via uploading a crafted TIFF file or=
    posting a URL that serves one.. Mattermost Advisory ID: MMSA-2026-00648</t=

    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5755" target=3D"= _blank" rel=3D"noopener">CVE-2026-5755</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00648</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail prevent disclosure of created user password which = allows a malicious attacker to impersonate a user via the use of some of th= ose passwords.. Mattermost Advisory ID: MMSA-2026-00614</td> <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6345" target=3D"= _blank" rel=3D"noopener">CVE-2026-6345</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00614</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to validate the OAuth token=
    scope on the callback which allows an authenticated Mattermost user to gai=
    n access to private repositories via modifying the scope parameter in the G= itHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628</td> <td>2026-05-22</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28735" target=3D= "_blank" rel=3D"noopener">CVE-2026-28735</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00628</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to validate file ownership = and access control, which allows an authenticated user to access and downlo=
    ad files belonging to other users or teams via crafted Boards API requests = using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620</td> <td>2026-05-22</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3473" target=3D"= _blank" rel=3D"noopener">CVE-2026-3473</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00620</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to limit the size of the request body on the start=
    meeting API endpoint, which allows an authenticated attacker to cause reso= urce exhaustion or denial of service via a crafted oversized HTTP POST requ= est to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608</td> <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2325" target=3D"= _blank" rel=3D"noopener">CVE-2026-2325</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00608</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 Fail to enforce slash command trigger-word uniqueness d= uring command updates which allows an authenticated team member with Manage=
    Own Slash Commands permission to hijack and impersonate existing system or=
    custom slash commands via editing their own slash command trigger to an al= ready-registered trigger through the command update API. Mattermost Advisor=
    y ID: MMSA-2026-00597</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28732" target=3D= "_blank" rel=3D"noopener">CVE-2026-28732</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00597</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to validate that a remote cluster has access to a = channel before processing membership removal requests during shared channel=
    membership sync, which allows a malicious remote cluster to remove any use=
    r from any channel, including private channels, via crafted membership sync=
    messages targeting channels the remote cluster is not authorized to access=
    . Mattermost Advisory ID: MMSA-2026-00576</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28759" target=3D= "_blank" rel=3D"noopener">CVE-2026-28759</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00576</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to sanitize team member dat=
    a when returned via API to users without elevated permissions which allows =
    a user without permissions to get data about team members roles via invokin=
    g various team API endpoints.. Mattermost Advisory ID: MMSA-2026-00626</td> <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3636" target=3D"= _blank" rel=3D"noopener">CVE-2026-3636</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00626</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to check the create_post channel permission during=
    post edit operations which allows an authenticated attacker with revoked p= osting privileges to modify their existing posts via direct API requests to=
    the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00= 627</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3637" target=3D"= _blank" rel=3D"noopener">CVE-2026-3637</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00627</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1 fail to validate team-level r= un_create permission against the target team when creating a playbook run w= hich allows an authenticated team member to create runs in teams where they=
    lack permission via specifying a different team ID in the run creation API=
    request. Mattermost Advisory ID: MMSA-2026-00629</td>
    <td>2026-05-21</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4055" target=3D"= _blank" rel=3D"noopener">CVE-2026-4055</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00629</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to validate user-supplied i= nput in API request handlers which allows an authenticated attacker to cras=
    h the plugin process via a crafted HTTP request to the PR details endpoint.=
    . Mattermost Advisory ID: MMSA-2026-00638</td>
    <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4646" target=3D"= _blank" rel=3D"noopener">CVE-2026-4646</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00638</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.6.x &lt;=3D 11.6.0, 11.5.x &lt;=3D 11.5.3, 11.4.=
    x &lt;=3D 11.4.4, 10.11.x &lt;=3D 10.11.14 fail to enforce request body siz=
    e limits on plugin HTTP endpoints which allows an attacker to cause a denia=
    l of service via crafted oversized HTTP requests.. Mattermost Advisory ID: = MMSA-2026-00646</td>
    <td>2026-05-22</td>
    <td>4.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5308" target=3D"= _blank" rel=3D"noopener">CVE-2026-5308</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00646</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 11.4.x &lt;=3D 11.4.3 fail t=
    o validate the X-Requested-With header on the burn-on-read reveal endpoint = which allows an authenticated channel member to force the reveal of a burn-= on-read message without recipient consent via a crafted Markdown image tag.=
    . Mattermost Advisory ID: MMSA-2026-00636</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6339" target=3D"= _blank" rel=3D"noopener">CVE-2026-6339</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00636</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to validate 7zip archive structure before processi=
    ng which allows an authenticated attacker to cause server memory exhaustion=
    and denial of service via uploading a specially crafted 7zip file with exc= essive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573</td> <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6340" target=3D"= _blank" rel=3D"noopener">CVE-2026-6340</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00573</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost Plugins versions &lt;=3D11.5 11.1.5 10.13.11 11.3.4.0 fail t=
    o have API-level checks on which groups the user can create issues or attac=
    h comments to which allows a user that is member of multiple groups to crea=
    te issues to a locked group via direct API requests. Mattermost Advisory ID=
    : MMSA-2026-00602</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6341" target=3D"= _blank" rel=3D"noopener">CVE-2026-6341</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00602</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost Plugins versions &lt;=3D11.5 11.1.5 10.13.11 11.3.4.0 fail t=
    o appropriately check for valid namespaces which allows plugin users to cre= ate subscriptions to groups that were not whitelisted via creating groups t= hat share the same prefix as a whitelisted group. Mattermost Advisory ID: M= MSA-2026-00601</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6342" target=3D"= _blank" rel=3D"noopener">CVE-2026-6342</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00601</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13, 11= .4.x &lt;=3D 11.4.3 fail to check public/private permissions which allows m= embers without these permissions to access public playbooks via /get.. Matt= ermost Advisory ID: MMSA-2026-00591</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6343" target=3D"= _blank" rel=3D"noopener">CVE-2026-6343</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00591</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mcinvale--Faces of Users</td>
    <td>The Faces of Users plugin for WordPress is vulnerable to Stored Cross-S= ite Scripting via the 'default' shortcode attribute in the 'facesofusers' s= hortcode in all versions up to, and including, 0.0.3 due to insufficient in= put sanitization and output escaping. This makes it possible for authentica= ted attackers, with Contributor-level access and above, to inject arbitrary=
    web scripts in pages that will execute whenever a user accesses an injecte=
    d page.</td>
    <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8038" target=3D"= _blank" rel=3D"noopener">CVE-2026-8038</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/ea39d2= 49-0345-4028-af58-31b298376950?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/ea39d249-034= 5-4028-af58-31b298376950?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/faces-of-users/trunk/faces-of.php#L62" target=3D"_b= lank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/faces-of-= users/trunk/faces-of.php#L62</a><br><a href=3D"https://plugins.trac.wordpre= ss.org/browser/faces-of-users/tags/0.0.3/faces-of.php#L62" target=3D"_blank=
    " rel=3D"noopener">https://plugins.trac.wordpress.org/browser/faces-of-user= s/tags/0.0.3/faces-of.php#L62</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mesalvo--Meona Client Launcher Component</td> <td>Cleartext Storage of Sensitive Information in Memory vulnerability in M= esalvo Meona Client Launcher Component, Mesalvo Meona Server Component. Thi=
    s issue affects Meona Client Launcher Component: through 19.06.2020 15:11:4=
    9; Meona Server Component: through 2025.04 5+323020.</td>
    <td>2026-05-20</td>
    <td>6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-0857" target=3D"= _blank" rel=3D"noopener">CVE-2026-0857</a></td>

    <a href=3D"https://seccore.at/blog/cves-meona/" target=3D"_blank" rel=3D"no= opener">https://seccore.at/blog/cves-meona/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mesalvo--Meona Client Launcher Component</td> <td>Insufficient Verification of Data Authenticity vulnerability in Mesalvo=
    Meona Client Launcher Component, Mesalvo Meona Server Component makes it p= ossible to send messages to any email address.=C2=A0This issue affects Meon=
    a Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Comp= onent: through 2025.04 5+323020.</td>
    <td>2026-05-20</td>
    <td>4.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25602" target=3D= "_blank" rel=3D"noopener">CVE-2026-25602</a></td>

    <a href=3D"https://seccore.at/blog/cves-meona/" target=3D"_blank" rel=3D"no= opener">https://seccore.at/blog/cves-meona/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft 365 Copilot</td>
    <td>Improper neutralization of special elements used in a command ('command=
    injection') in M365 Copilot allows an unauthorized attacker to disclose in= formation over a network.</td>
    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42827" target=3D= "_blank" rel=3D"noopener">CVE-2026-42827</a></td>

    <a href=3D"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4= 2827" target=3D"_blank" rel=3D"noopener">M365 Copilot Information Disclosur=
    e Vulnerability</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Defender Antimalware Plat= form</td>
    <td>Microsoft Defender Denial of Service Vulnerability</td>
    <td>2026-05-20</td>
    <td>4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45498" target=3D= "_blank" rel=3D"noopener">CVE-2026-45498</a></td>

    <a href=3D"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4= 5498" target=3D"_blank" rel=3D"noopener">Microsoft Defender Denial of Servi=
    ce Vulnerability</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=

    <td>Improper input validation in Microsoft Edge (Chromium-based) allows an = unauthorized attacker to bypass a security feature over a network.</td> <td>2026-05-18</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45492" target=3D= "_blank" rel=3D"noopener">CVE-2026-45492</a></td>

    <a href=3D"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4= 5492" target=3D"_blank" rel=3D"noopener">Microsoft Edge (Chromium-based) Se= curity Feature Bypass Vulnerability</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=

    <td>Microsoft Edge (Chromium-based) Spoofing Vulnerability</td> <td>2026-05-18</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45494" target=3D= "_blank" rel=3D"noopener">CVE-2026-45494</a></td>

    <a href=3D"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4= 5494" target=3D"_blank" rel=3D"noopener">Microsoft Edge (Chromium-based) Sp= oofing Vulnerability</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Microsoft--Windows 11 Version 24H2</td> <td>Microsoft is aware of a security feature bypass vulnerability in Window=
    s publicly referred to as &amp;quot;YellowKey&amp;quot;. The proof of conce=
    pt for this vulnerability has been made public violating coordinated vulner= ability best practices. We are issuing this CVE to provide mitigation guida= nce that can be implemented to protect against this vulnerability until the=
    security update is made available. Mitigation FAQs Should I leverage the t= emporary mitigation? Microsoft recommends that you consider implementing th= ese mitigations if you are concerned your devices and data are at risk of b= eing compromised or stolen. For example, if your organization's employees t= ake their work devices home or on business travel. What impact to service a= vailability/management could be caused by implementing the mitigations? Imp= lementing these mitigations will not impact service availability or managem= ent operations. Do customers need to revert the changes made to mitigate th=
    e vulnerability once the security update to protect against this vulnerabil= ity is available? No. The security update will maintain the mitigation's be= havior once the security update is installed. I am using TPM+PIN, am I at r= isk of this vulnerability being exploited No, if you are using TPM+PIN the = vulnerability is not exploitable.</td>
    <td>2026-05-19</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45585" target=3D= "_blank" rel=3D"noopener">CVE-2026-45585</a></td>

    <a href=3D"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4= 5585" target=3D"_blank" rel=3D"noopener">Windows BitLocker Security Feature=
    Bypass Vulnerability</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">MongoDB, Inc.--C Driver</td>
    <td>The MongoDB C Driver's legacy GridFS API accepts malformed file metadat=
    a from the database without adequate validation. Crafted documents in a Gri= dFS collection may cause any application that reads those files via the leg= acy API to either crash (via a division-by-zero) or silently leak process m= emory contents (via an out-of-bounds read).</td>
    <td>2026-05-20</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9100" target=3D"= _blank" rel=3D"noopener">CVE-2026-9100</a></td>

    <a href=3D"https://jira.mongodb.org/browse/CDRIVER-6281" target=3D"_blank" = rel=3D"noopener">https://jira.mongodb.org/browse/CDRIVER-6281</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">MongoDB, Inc.--Compass</td>
    <td>Prototype pollution in csv parsing logic during import can lead to untr= usted file paths (but not arguments) entering shell.openExternal after spec= ific user behavior leading to "1-click" command execution.</td> <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9101" target=3D"= _blank" rel=3D"noopener">CVE-2026-9101</a></td>

    <a href=3D"https://jira.mongodb.org/browse/COMPASS-10657" target=3D"_blank"=
    rel=3D"noopener">https://jira.mongodb.org/browse/COMPASS-10657</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">MongoDB, Inc.--MongoDB Server</td>
    <td>Creating a "2dsphere_bucket" index on a non-timeseries bucket collectio=
    n will succeed, but any subsequent attempt to insert a document which trigg= ers updating that index will crash the server. A similar issue occurs when = creating "queryable_encrypted_range" indices. This issue affects MongoDB Se= rver v7.0 versions prior to 7.0.32, v8.0 versions prior to 8.0.21 and v8.2 = versions prior to 8.2.6</td>
    <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8843" target=3D"= _blank" rel=3D"noopener">CVE-2026-8843</a></td>

    <a href=3D"https://jira.mongodb.org/browse/SERVER-116327" target=3D"_blank"=
    rel=3D"noopener">https://jira.mongodb.org/browse/SERVER-116327</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">mrdollar4444--GSheet For Woo Importer</td>
    <td>The GSheet For Woo Importer plugin for WordPress is vulnerable to unaut= horized loss of data due to a missing capability check on the process_ajax_= restore_action() function in all versions up to, and including, 2.3.1. This=
    makes it possible for authenticated attackers, with Subscriber-level acces=
    s and above, to delete the plugin's Google Sheets API token and configurati=
    on options.</td>
    <td>2026-05-21</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4843" target=3D"= _blank" rel=3D"noopener">CVE-2026-4843</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0d609= 91-0675-4efa-9427-380e6b59fe28?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/b0d60991-067= 5-4efa-9427-380e6b59fe28?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/import-products-from-gsheet-for-woo-importer/tags/2= .3.1/src/Actions/AdminSettingsAction.php#L391" target=3D"_blank" rel=3D"noo= pener">https://plugins.trac.wordpress.org/browser/import-products-from-gshe= et-for-woo-importer/tags/2.3.1/src/Actions/AdminSettingsAction.php#L391</a>= <br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--Ettercap</td>
    <td>A vulnerability has been found in Ettercap up to 0.8.3. The affected el= ement is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of th=
    e component GG Dissector. The manipulation of the argument gg leads to heap= -based buffer overflow. The attack is possible to be carried out remotely. = The complexity of an attack is rather high. The exploitability is described=
    as difficult. The exploit has been disclosed to the public and may be used=
    . Upgrading to version 0.8.4 is sufficient to fix this issue. The identifie=
    r of the patch is feeae6fa366e01a3dd9f1857ec6aae847b2ae00c. It is suggested=
    to upgrade the affected component.</td>
    <td>2026-05-24</td>
    <td>5.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9365" target=3D"= _blank" rel=3D"noopener">CVE-2026-9365</a></td>

    <a href=3D"https://vuldb.com/vuln/365328" target=3D"_blank" rel=3D"noopener= ">VDB-365328 | Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overfl= ow</a><br><a href=3D"https://vuldb.com/vuln/365328/cti" target=3D"_blank" r= el=3D"noopener">VDB-365328 | CTI Indicators (IOB, IOC, IOA)</a><br><a href= =3D"https://vuldb.com/submit/813142" target=3D"_blank" rel=3D"noopener">Sub= mit #813142 | Ettercap &lt;=3Dv0.8.4 Heap-based Buffer Overflow</a><br><a h= ref=3D"https://github.com/Ettercap/ettercap/issues/1306" target=3D"_blank" = rel=3D"noopener">https://github.com/Ettercap/ettercap/issues/1306</a><br><a=
    href=3D"https://github.com/Ettercap/ettercap/pull/1307" target=3D"_blank" = rel=3D"noopener">https://github.com/Ettercap/ettercap/pull/1307</a><br><a h= ref=3D"https://github.com/Ettercap/ettercap/commit/feeae6fa366e01a3dd9f1857= ec6aae847b2ae00c" target=3D"_blank" rel=3D"noopener">https://github.com/Ett= ercap/ettercap/commit/feeae6fa366e01a3dd9f1857ec6aae847b2ae00c</a><br><a hr= ef=3D"https://github.com/Ettercap/ettercap/" target=3D"_blank" rel=3D"noope= ner">https://github.com/Ettercap/ettercap/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--exifreader</td>
    <td>Versions of the package exifreader before 4.39.0 are vulnerable to Impr= oper Handling of Highly Compressed Data (Data Amplification) due to decompr= essing PNG zTXt metadata without enforcing a built-in maximum decompressed = output size. When asynchronous parsing is enabled, a crafted PNG file conta= ining a highly compressed zTXt chunk can cause ExifReader to materialize a = disproportionately large Comment value in memory.</td>
    <td>2026-05-19</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8814" target=3D"= _blank" rel=3D"noopener">CVE-2026-8814</a></td>

    <a href=3D"https://security.snyk.io/vuln/SNYK-JS-EXIFREADER-16689340" targe= t=3D"_blank" rel=3D"noopener">https://security.snyk.io/vuln/SNYK-JS-EXIFREA= DER-16689340</a><br><a href=3D"https://gist.github.com/yuki-matsuhashi/cad1= a45d936062438b4ab24613c34c55" target=3D"_blank" rel=3D"noopener">https://gi= st.github.com/yuki-matsuhashi/cad1a45d936062438b4ab24613c34c55</a><br><a hr= ef=3D"https://github.com/mattiasw/ExifReader/commit/5f116128adc19f674902f8b= f582bfe7dd0a36375" target=3D"_blank" rel=3D"noopener">https://github.com/ma= ttiasw/ExifReader/commit/5f116128adc19f674902f8bf582bfe7dd0a36375</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--JPress</td>
    <td>A vulnerability was determined in JPress up to 1.0.3. The affected elem= ent is an unknown function of the file /ucenter/article/doWriteSave of the = component UCenter Article Submission Endpoint. Executing a manipulation of = the argument id/userId can lead to improper authorization. The attack may b=
    e performed from remote. The exploit has been publicly disclosed and may be=
    utilized. The project was informed of the problem early through an issue r= eport but has not responded yet.</td>
    <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9376" target=3D"= _blank" rel=3D"noopener">CVE-2026-9376</a></td>

    <a href=3D"https://vuldb.com/vuln/365339" target=3D"_blank" rel=3D"noopener= ">VDB-365339 | JPress UCenter Article Submission Endpoint doWriteSave impro= per authorization</a><br><a href=3D"https://vuldb.com/vuln/365339/cti" targ= et=3D"_blank" rel=3D"noopener">VDB-365339 | CTI Indicators (IOB, IOC, TTP, = IOA)</a><br><a href=3D"https://vuldb.com/submit/813253" target=3D"_blank" r= el=3D"noopener">Submit #813253 | JPress 1.0.3 Improper Authorization</a><br= ><a href=3D"https://github.com/JPressProjects/jpress/issues/194" target=3D"= _blank" rel=3D"noopener">https://github.com/JPressProjects/jpress/issues/19= 4</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--postcss</td>
    <td>A vulnerability was determined in postcss up to 7.1.1. Affected is the = function toString of the file src/selectors/container.js of the component A=
    ST Serialization. Executing a manipulation can lead to uncontrolled recursi= on. It is possible to launch the attack remotely. The exploit has been publ= icly disclosed and may be utilized. The vendor explains, that according to = his definition "DoS on server-side on user-generated CSS is low risk for us=
    (since most users compile own CSS with PostCSS)."</td>
    <td>2026-05-24</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9358" target=3D"= _blank" rel=3D"noopener">CVE-2026-9358</a></td>

    <a href=3D"https://vuldb.com/vuln/365321" target=3D"_blank" rel=3D"noopener= ">VDB-365321 | postcss AST Serialization container.js toString recursion</a= ><br><a href=3D"https://vuldb.com/vuln/365321/cti" target=3D"_blank" rel=3D= "noopener">VDB-365321 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href= =3D"https://vuldb.com/submit/813080" target=3D"_blank" rel=3D"noopener">Sub= mit #813080 | postcss-selector-parser postcss &lt;=3D 7.1.1 CWE-674: Uncont= rolled Recursion</a><br><a href=3D"https://gist.github.com/bx33661/581e3a38= 134601c04e19b4dfc9b459b9" target=3D"_blank" rel=3D"noopener">https://gist.g= ithub.com/bx33661/581e3a38134601c04e19b4dfc9b459b9</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">nanomq--nanomq</td>
    <td>NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. I=
    n versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnec=
    t traffic using a reconnect-collision payload, the broker can crash due to =
    a NULL pointer dereference during MQTT session resumption for clean_start=
    =3D0 clients. The transport's p_peer callback (tcptran_pipe_peer()) iterate=
    s cpipe-&gt;subinfol while copying session metadata from the cached old pip=
    e to the new reconnecting pipe, without checking whether the pointer is NUL=
    L. Under a reconnect race, cpipe-&gt;subinfol can be freed and set to NULL = before session restore invokes this function, resulting in a remote unauthe= nticated Denial-of-Service (process crash) condition. This issue has been f= ixed in version 0.24.11.</td>
    <td>2026-05-19</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32134" target=3D= "_blank" rel=3D"noopener">CVE-2026-32134</a></td>

    <a href=3D"https://github.com/nanomq/nanomq/security/advisories/GHSA-q36f-8= 3mh-pcv2" target=3D"_blank" rel=3D"noopener">https://github.com/nanomq/nano= mq/security/advisories/GHSA-q36f-83mh-pcv2</a><br><a href=3D"https://github= .com/nanomq/nanomq/issues/2241" target=3D"_blank" rel=3D"noopener">https://= github.com/nanomq/nanomq/issues/2241</a><br><a href=3D"https://github.com/n= anomq/NanoNNG/commit/522ec62e29e60d1122f2aedaa6e702dcf089f7bb" target=3D"_b= lank" rel=3D"noopener">https://github.com/nanomq/NanoNNG/commit/522ec62e29e= 60d1122f2aedaa6e702dcf089f7bb</a><br><a href=3D"https://github.com/nanomq/n= anomq/releases/tag/0.24.11" target=3D"_blank" rel=3D"noopener">https://gith= ub.com/nanomq/nanomq/releases/tag/0.24.11</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NeoRazorX--facturascripts</td>
    <td>FacturaScripts is an open source accounting and invoicing software. In = versions prior to 2026, the Library module stores and serves uploaded image=
    s byte-for-byte, without stripping EXIF/XMP/IPTC metadata. Any authenticate=
    d user who downloaded an image could extract the uploader's embedded metada= ta, which included GPS coordinates, device information, timestamps, embedde=
    d comments/notes, thumbnail previews, and other personally identifiable inf= ormation (PII) preserved in the image metadata. Of all FacturaScripts' imag=
    e upload features, only the Library module combined unrestricted uploads, p= ersistent storage, authenticated download access, and a total lack of serve= r-side metadata sanitization. This vulnerability carries significant real-w= orld impact: an employee uploading a photo taken at their home inadvertentl=
    y discloses their precise home address to every user with Library download = access. This issue has been fixed in version 2026.</td>
    <td>2026-05-18</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27892" target=3D= "_blank" rel=3D"noopener">CVE-2026-27892</a></td>

    <a href=3D"https://github.com/NeoRazorX/facturascripts/security/advisories/= GHSA-q7f2-rv22-2xgr" target=3D"_blank" rel=3D"noopener">https://github.com/= NeoRazorX/facturascripts/security/advisories/GHSA-q7f2-rv22-2xgr</a><br><a = href=3D"https://github.com/NeoRazorX/facturascripts/commit/b0725147a61a9a37= 7b7180589af33ff52b4751e2" target=3D"_blank" rel=3D"noopener">https://github= .com/NeoRazorX/facturascripts/commit/b0725147a61a9a377b7180589af33ff52b4751= e2</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from = predictable process IDs, which allows a remote authenticated attacker to ca= use a denial of service by exploiting the reconnect mechanism.</td> <td>2026-05-21</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44054" target=3D= "_blank" rel=3D"noopener">CVE-2026-44054</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44054" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44054</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.=
    2 allows a remote authenticated attacker to cause a denial of service, obta=
    in limited information, or modify limited data.</td>
    <td>2026-05-21</td>
    <td>6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44056" target=3D= "_blank" rel=3D"noopener">CVE-2026-44056</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44056" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44056</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 = allows a remote privileged user to authenticate as an arbitrary user via th=
    e admin auth user mechanism.</td>
    <td>2026-05-21</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44058" target=3D= "_blank" rel=3D"noopener">CVE-2026-44058</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44058" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44058</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4=
    .2 allows a local privileged user to inject OS commands and execute arbitra=
    ry code via a crafted volume path.</td>
    <td>2026-05-21</td>
    <td>6.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44076" target=3D= "_blank" rel=3D"noopener">CVE-2026-44076</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44076" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44076</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a tim= ing side channel, which allows a remote attacker to recover authentication = credentials via timing analysis.</td>
    <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44061" target=3D= "_blank" rel=3D"noopener">CVE-2026-44061</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44061" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44061</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows =
    a remote authenticated attacker to manipulate LDAP queries and obtain limit=
    ed information or modify LDAP entries via crafted filter input.</td> <td>2026-05-21</td>
    <td>4.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44063" target=3D= "_blank" rel=3D"noopener">CVE-2026-44063</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44063" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44063</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check th=
    e return value of seteuid(), which may allow a remote authenticated attacke=
    r to retain elevated privileges under error conditions.</td> <td>2026-05-21</td>
    <td>4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44073" target=3D= "_blank" rel=3D"noopener">CVE-2026-44073</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44073" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44073</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">NetBSD--src</td>
    <td>NetBSD prior to commit ec8451e contains a signed integer overflow vulne= rability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where=
    the local variable iov_len is declared as a signed int but assigned from a=
    n unsigned cop-&gt;dst_len value, causing undefined behavior when cop-&gt;d= st_len exceeds INT_MAX. A local attacker with access to /dev/crypto and a c= ompression session type can exploit this vulnerability by providing a dst_l=
    en value exceeding INT_MAX to trigger a kernel panic through NULL pointer d= ereference when CONFIG_SVS is disabled and corrupted UIO pointer arithmetic= .</td>
    <td>2026-05-18</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32849" target=3D= "_blank" rel=3D"noopener">CVE-2026-32849</a></td>

    <a href=3D"https://nasm.re/posts/uaf_netbsd_crypto/" target=3D"_blank" rel= =3D"noopener">https://nasm.re/posts/uaf_netbsd_crypto/</a><br><a href=3D"ht= tps://github.com/NetBSD/src/commit/ec8451efc1565516aba9e7047e1a1a1ce7953a2f=
    " target=3D"_blank" rel=3D"noopener">https://github.com/NetBSD/src/commit/e= c8451efc1565516aba9e7047e1a1a1ce7953a2f</a><br><a href=3D"https://www.vulnc= heck.com/advisories/netbsd-signed-integer-overflow-in-cryptodev-op-via-cryp= todev-c" target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advis= ories/netbsd-signed-integer-overflow-in-cryptodev-op-via-cryptodev-c</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NetBSD--src</td>
    <td>NetBSD prior to commit ec8451e contains a race condition vulnerability =
    in cryptodev_op() within the opencrypto subsystem that allows local attacke=
    rs to trigger a double-free condition by concurrently issuing CIOCCRYPT ope= rations on the same session identifier on SMP systems. Attackers can exploi=
    t mutable per-operation state embedded in the csession struct to corrupt ke= rnel heap memory.</td>
    <td>2026-05-18</td>
    <td>4.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32848" target=3D= "_blank" rel=3D"noopener">CVE-2026-32848</a></td>

    <a href=3D"https://nasm.re/posts/uaf_netbsd_crypto/" target=3D"_blank" rel= =3D"noopener">https://nasm.re/posts/uaf_netbsd_crypto/</a><br><a href=3D"ht= tps://github.com/NetBSD/src/commit/ec8451efc1565516aba9e7047e1a1a1ce7953a2f=
    " target=3D"_blank" rel=3D"noopener">https://github.com/NetBSD/src/commit/e= c8451efc1565516aba9e7047e1a1a1ce7953a2f</a><br><a href=3D"https://www.vulnc= heck.com/advisories/netbsd-cryptodev-race-condition-double-free-via-cryptod= ev-op" target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisor= ies/netbsd-cryptodev-race-condition-double-free-via-cryptodev-op</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">nimiq--core-rs-albatross</td>
    <td>nimiq-blockchain provides persistent block storage for Nimiq's Rust imp= lementation. In versions 1.3.0 and prior, network-libp2p discovery accepts = signed PeerContact updates from untrusted peers and stores them in a peer c= ontact book, eventually leading to address book crash. A PeerContact can le= gally contain an empty addresses list (no intrinsic validation enforces non= -empty). Later, PeerContactBook::known_peers builds an address book by taki=
    ng addresses.first().expect("every peer should have at least one address").=
    If the attacker has inserted a signed peer contact with addresses=3D[], an=
    y call to get_address_book (RPC/web client) can panic and crash the node/RP=
    C task depending on panic settings. This issue has been fixed in version 1.= 4.0.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40094" target=3D= "_blank" rel=3D"noopener">CVE-2026-40094</a></td>

    <a href=3D"https://github.com/nimiq/core-rs-albatross/security/advisories/G= HSA-c45m-6x25-3cjq" target=3D"_blank" rel=3D"noopener">https://github.com/n= imiq/core-rs-albatross/security/advisories/GHSA-c45m-6x25-3cjq</a><br><a hr= ef=3D"https://github.com/nimiq/core-rs-albatross/pull/3715" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/nimiq/core-rs-albatross/pull/3715</a= ><br><a href=3D"https://github.com/nimiq/core-rs-albatross/releases/tag/v1.= 4.0" target=3D"_blank" rel=3D"noopener">https://github.com/nimiq/core-rs-al= batross/releases/tag/v1.4.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A security flaw has been discovered in NousResearch hermes-agent up to = 2026.4.16. This vulnerability affects the function _is_blocked_device of th=
    e file tools/file_tools.py of the component read_file Tool. Performing a ma= nipulation results in path traversal. The attack may be initiated remotely.=
    The exploit has been released to the public and may be used for attacks. T=
    he vendor was contacted early about this disclosure but did not respond in = any way.</td>
    <td>2026-05-24</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9351" target=3D"= _blank" rel=3D"noopener">CVE-2026-9351</a></td>

    <a href=3D"https://vuldb.com/vuln/365314" target=3D"_blank" rel=3D"noopener= ">VDB-365314 | NousResearch hermes-agent read_file Tool file_tools.py _is_b= locked_device path traversal</a><br><a href=3D"https://vuldb.com/vuln/36531= 4/cti" target=3D"_blank" rel=3D"noopener">VDB-365314 | CTI Indicators (IOB,=
    IOC, TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/812214" target= =3D"_blank" rel=3D"noopener">Submit #812214 | NousResearch hermes-agent 202= 6.4.16 Path Traversal (CWE-22)</a><br><a href=3D"https://gist.github.com/YL= Chen-007/1d1aeff404cb88e06ec2fb3377f49fef" target=3D"_blank" rel=3D"noopene= r">https://gist.github.com/YLChen-007/1d1aeff404cb88e06ec2fb3377f49fef</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A vulnerability was detected in NousResearch hermes-agent up to 2026.4.= 16. The affected element is an unknown function of the component Slack Agen= t/Mattermost Agent. The manipulation of the argument format_message results=
    in escaping of output. The attack can be executed remotely. The exploit is=
    now public and may be used. The vendor was contacted early about this disc= losure but did not respond in any way.</td>
    <td>2026-05-24</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9354" target=3D"= _blank" rel=3D"noopener">CVE-2026-9354</a></td>

    <a href=3D"https://vuldb.com/vuln/365317" target=3D"_blank" rel=3D"noopener= ">VDB-365317 | NousResearch hermes-agent Slack Agent/Mattermost Agent escap=
    e output</a><br><a href=3D"https://vuldb.com/vuln/365317/cti" target=3D"_bl= ank" rel=3D"noopener">VDB-365317 | CTI Indicators (IOB, IOC, IOA)</a><br><a=
    href=3D"https://vuldb.com/submit/812226" target=3D"_blank" rel=3D"noopener= ">Submit #812226 | NousResearch hermes-agent 2026.4.16 Improper Encoding or=
    Escaping of Output (CWE-116)</a><br><a href=3D"https://gist.github.com/YLC= hen-007/e90fb38ac03284176bae49898a3a46a4" target=3D"_blank" rel=3D"noopener= ">https://gist.github.com/YLChen-007/e90fb38ac03284176bae49898a3a46a4</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A weakness has been identified in NousResearch hermes-agent up to 2026.= 4.23. This issue affects the function _make_run_env of the file tools/envir= onments/local.py of the component Messaging Gateway Handler. Executing a ma= nipulation can lead to information disclosure. The attack may be launched r= emotely. The exploit has been made available to the public and could be use=
    d for attacks. The vendor was contacted early about this disclosure but did=
    not respond in any way.</td>
    <td>2026-05-24</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9352" target=3D"= _blank" rel=3D"noopener">CVE-2026-9352</a></td>

    <a href=3D"https://vuldb.com/vuln/365315" target=3D"_blank" rel=3D"noopener= ">VDB-365315 | NousResearch hermes-agent Messaging Gateway local.py _make_r= un_env information disclosure</a><br><a href=3D"https://vuldb.com/vuln/3653= 15/cti" target=3D"_blank" rel=3D"noopener">VDB-365315 | CTI Indicators (IOB=
    , IOC, TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/812215" target= =3D"_blank" rel=3D"noopener">Submit #812215 | NousResearch hermes-agent 202= 6.4.23 Exposure of Sensitive Information (CWE-200)</a><br><a href=3D"https:= //gist.github.com/YLChen-007/760b3940f708990e535214529c0c7a27" target=3D"_b= lank" rel=3D"noopener">https://gist.github.com/YLChen-007/760b3940f708990e5= 35214529c0c7a27</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NousResearch--hermes-agent</td>
    <td>A security flaw has been discovered in NousResearch hermes-agent 2026.4= .23. Affected is the function _discover_dashboard_plugins of the file herme= s_cli/web_server.py of the component CLI web-dashboard Interface. Performin=
    g a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in i= ncorrect comparison. The attack is only possible with local access. The exp= loit has been released to the public and may be used for attacks. The vendo=
    r was contacted early about this disclosure but did not respond in any way.= </td>
    <td>2026-05-24</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9369" target=3D"= _blank" rel=3D"noopener">CVE-2026-9369</a></td>

    <a href=3D"https://vuldb.com/vuln/365332" target=3D"_blank" rel=3D"noopener= ">VDB-365332 | NousResearch hermes-agent CLI web-dashboard web_server.py _d= iscover_dashboard_plugins comparison</a><br><a href=3D"https://vuldb.com/vu= ln/365332/cti" target=3D"_blank" rel=3D"noopener">VDB-365332 | CTI Indicato=
    rs (IOB, IOC, IOA)</a><br><a href=3D"https://vuldb.com/submit/812230" targe= t=3D"_blank" rel=3D"noopener">Submit #812230 | NousResearch hermes-agent 20= 26.4.23 Incorrect Comparison (CWE-697)</a><br><a href=3D"https://gist.githu= b.com/YLChen-007/062b77ceac6aa9844842a616f5d2ef30" target=3D"_blank" rel=3D= "noopener">https://gist.github.com/YLChen-007/062b77ceac6aa9844842a616f5d2e= f30</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Nozomi Networks--Guardian</td>
    <td>A Stored HTML Injection vulnerability was discovered in the Smart Polli=
    ng functionality due to improper validation of an input parameter. An authe= nticated user with limited privileges can push malicious remote strategies = containing HTML tags through the sync. When a victim views the affected rem= ote strategy in the Smart Polling functionality, the injected HTML renders =
    in their browser, enabling phishing and possibly open redirect attacks. Ful=
    l XSS exploitation and direct information disclosure are prevented by the e= xisting input validation and Content Security Policy configuration.</td> <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-40904" target=3D= "_blank" rel=3D"noopener">CVE-2025-40904</a></td>

    <a href=3D"https://security.nozominetworks.com/NN-2026:7-01" target=3D"_bla= nk" rel=3D"noopener">https://security.nozominetworks.com/NN-2026:7-01</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Nozomi Networks--Guardian</td>
    <td>A Stored HTML Injection vulnerability was discovered in the Credentials=
    Manager functionality due to improper validation of an input parameter. An=
    authenticated user with administrative privileges can define a malicious i= dentity containing HTML tags. When a victim attempts to delete the affected=
    identity, the injected HTML renders in their browser, enabling phishing an=
    d possibly open redirect attacks. Full XSS exploitation and direct informat= ion disclosure are prevented by the existing input validation and Content S= ecurity Policy configuration.</td>
    <td>2026-05-19</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-40901" target=3D= "_blank" rel=3D"noopener">CVE-2025-40901</a></td>

    <a href=3D"https://security.nozominetworks.com/NN-2026:4-01" target=3D"_bla= nk" rel=3D"noopener">https://security.nozominetworks.com/NN-2026:4-01</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Nozomi Networks--Guardian</td>
    <td>A Stored HTML Injection vulnerability was discovered in the Users funct= ionality due to improper validation of an input parameter. An authenticated=
    user with administrative privileges can create a malicious user whose user= name contains HTML tags. When a victim attempts to delete a group containin=
    g the affected user, the injected HTML renders in their browser, enabling p= hishing and possibly open redirect attacks. Full XSS exploitation and direc=
    t information disclosure are prevented by the existing input validation and=
    Content Security Policy configuration.</td>
    <td>2026-05-19</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-40902" target=3D= "_blank" rel=3D"noopener">CVE-2025-40902</a></td>

    <a href=3D"https://security.nozominetworks.com/NN-2026:5-01" target=3D"_bla= nk" rel=3D"noopener">https://security.nozominetworks.com/NN-2026:5-01</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Nozomi Networks--Guardian</td>
    <td>A Stored HTML Injection vulnerability was discovered in the Schedule Re= store Archive functionality due to improper validation of an input paramete=
    r. An authenticated user with administrative privileges can define a malici= ous restore schedule containing HTML tags. When a victim views the affected=
    schedule, the injected HTML renders in their browser, enabling phishing an=
    d possibly open redirect attacks. Full XSS exploitation and direct informat= ion disclosure are prevented by the existing input validation and Content S= ecurity Policy configuration.</td>
    <td>2026-05-19</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-40903" target=3D= "_blank" rel=3D"noopener">CVE-2025-40903</a></td>

    <a href=3D"https://security.nozominetworks.com/NN-2026:6-01" target=3D"_bla= nk" rel=3D"noopener">https://security.nozominetworks.com/NN-2026:6-01</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Nozomi Networks--Guardian</td>
    <td>An Angular template injection vulnerability was discovered in the Repor=
    ts functionality due to improper validation of an input parameter. An authe= nticated user with report privileges can define a malicious report containi=
    ng an Angular template payload, or a victim can be socially engineered to i= mport a malicious report template. When the victim views or imports the rep= ort, the Angular template executes in their browser context, allowing the a= ttacker to modify application data, or disrupt application availability. Fu=
    ll XSS exploitation and direct information disclosure are prevented by the = existing input validation and Content Security Policy configuration.</td> <td>2026-05-19</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-40900" target=3D= "_blank" rel=3D"noopener">CVE-2025-40900</a></td>

    <a href=3D"https://security.nozominetworks.com/NN-2026:3-01" target=3D"_bla= nk" rel=3D"noopener">https://security.nozominetworks.com/NN-2026:3-01</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">npitre--cramfs-tools</td>
    <td>A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected=
    is the function change_file_status of the file cramfsck.c. Performing a ma= nipulation results in symlink following. The attack requires a local approa= ch. The exploit is now public and may be used. The patch is named b4a3a695c= 9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix = this issue.</td>
    <td>2026-05-18</td>
    <td>4.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8784" target=3D"= _blank" rel=3D"noopener">CVE-2026-8784</a></td>

    <a href=3D"https://vuldb.com/vuln/364408" target=3D"_blank" rel=3D"noopener= ">VDB-364408 | npitre cramfs-tools cramfsck.c change_file_status symlink</a= ><br><a href=3D"https://vuldb.com/vuln/364408/cti" target=3D"_blank" rel=3D= "noopener">VDB-364408 | CTI Indicators (IOB, IOC, IOA)</a><br><a href=3D"ht= tps://vuldb.com/submit/811897" target=3D"_blank" rel=3D"noopener">Submit #8= 11897 | GNU cramfs-tools below v2.2 Symlink Following</a><br><a href=3D"htt= ps://github.com/npitre/cramfs-tools/issues/13" target=3D"_blank" rel=3D"noo= pener">https://github.com/npitre/cramfs-tools/issues/13</a><br><a href=3D"h= ttps://github.com/npitre/cramfs-tools/issues/13#issuecomment-4306102583" ta= rget=3D"_blank" rel=3D"noopener">https://github.com/npitre/cramfs-tools/iss= ues/13#issuecomment-4306102583</a><br><a href=3D"https://github.com/npitre/= cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f" target=3D"_bl= ank" rel=3D"noopener">https://github.com/npitre/cramfs-tools/commit/b4a3a69= 5c9873f824907bd15659f2a6ac7667b4f</a><br><a href=3D"https://github.com/npit= re/cramfs-tools/" target=3D"_blank" rel=3D"noopener">https://github.com/npi= tre/cramfs-tools/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--TensorRT-LLM</td>
    <td>NVIDIA TRT-LLM for any platform contains a deserialization vulnerabilit=
    y and unsafe serialized handle. A successful exploit of this vulnerability = might lead to code execution, data tampering, and information disclosure.</=

    <td>2026-05-20</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24142" target=3D= "_blank" rel=3D"noopener">CVE-2026-24142</a></td>

    <a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2026-24142" target=3D"_blan=
    k" rel=3D"noopener">https://nvd.nist.gov/vuln/detail/CVE-2026-24142</a><br>=
    <a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24142" target=3D"_bl= ank" rel=3D"noopener">https://www.cve.org/CVERecord?id=3DCVE-2026-24142</a>= <br><a href=3D"https://nvidia.custhelp.com/app/answers/detail/a_id/5805" ta= rget=3D"_blank" rel=3D"noopener">https://nvidia.custhelp.com/app/answers/de= tail/a_id/5805</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--TensorRT-LLM</td>
    <td>NVIDIA TRT-LLM for any platform contains a vulnerability where an attac= ker could cause an unchecked return value to a null pointer dereference. A = successful exploit of this vulnerability might lead to denial of service.</=

    <td>2026-05-20</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24160" target=3D= "_blank" rel=3D"noopener">CVE-2026-24160</a></td>

    <a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2026-24160" target=3D"_blan=
    k" rel=3D"noopener">https://nvd.nist.gov/vuln/detail/CVE-2026-24160</a><br>=
    <a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24160" target=3D"_bl= ank" rel=3D"noopener">https://www.cve.org/CVERecord?id=3DCVE-2026-24160</a>= <br><a href=3D"https://nvidia.custhelp.com/app/answers/detail/a_id/5805" ta= rget=3D"_blank" rel=3D"noopener">https://nvidia.custhelp.com/app/answers/de= tail/a_id/5805</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability where an attack=
    er could cause a path traversal issue. A successful exploit of this vulnera= bility might lead to denial of service.</td>
    <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24208" target=3D= "_blank" rel=3D"noopener">CVE-2026-24208</a></td>

    <a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2026-24208" target=3D"_blan=
    k" rel=3D"noopener">https://nvd.nist.gov/vuln/detail/CVE-2026-24208</a><br>=
    <a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24208" target=3D"_bl= ank" rel=3D"noopener">https://www.cve.org/CVERecord?id=3DCVE-2026-24208</a>= <br><a href=3D"https://nvidia.custhelp.com/app/answers/detail/a_id/5828" ta= rget=3D"_blank" rel=3D"noopener">https://nvidia.custhelp.com/app/answers/de= tail/a_id/5828</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NVIDIA--Triton Inference Server</td>
    <td>NVIDIA Triton Inference Server contains a vulnerability in the DALI bac= kend, where an attacker could cause uncontrolled resource consumption. A su= ccessful exploit of this vulnerability might lead to denial of service.</td=

    <td>2026-05-20</td>
    <td>5.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24215" target=3D= "_blank" rel=3D"noopener">CVE-2026-24215</a></td>

    <a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2026-24215" target=3D"_blan=
    k" rel=3D"noopener">https://nvd.nist.gov/vuln/detail/CVE-2026-24215</a><br>=
    <a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24215" target=3D"_bl= ank" rel=3D"noopener">https://www.cve.org/CVERecord?id=3DCVE-2026-24215</a>= <br><a href=3D"https://nvidia.custhelp.com/app/answers/detail/a_id/5828" ta= rget=3D"_blank" rel=3D"noopener">https://nvidia.custhelp.com/app/answers/de= tail/a_id/5828</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">oliverpos--Oliver POS A WooCommerce Point of S= ale (POS)</td>
    <td>The Oliver POS - A WooCommerce Point of Sale (POS) plugin for WordPress=
    is vulnerable to Authorization Bypass Through User-Controlled Key in all v= ersions up to and including 2.4.2.6. The plugin protects its entire /wp-jso= n/pos-bridge/* REST API namespace through the oliver_pos_rest_authenticatio= n() permission callback, which uses a loose PHP comparison (=3D=3D) to comp= are the attacker-supplied 'OliverAuth' header value against the 'oliver_pos= _authorization_token' option. On fresh installations where the admin has no=
    t yet completed the connection flow, this option is unset (get_option retur=
    ns false). Due to PHP's type juggling, the loose comparison '0' =3D=3D fals=
    e evaluates to true, allowing an unauthenticated attacker to bypass authent= ication by sending 'OliverAuth: 0'. This grants full access to all POS API = endpoints, enabling attackers to read user data (including administrator de= tails), update user profiles (including email addresses), and delete non-ad= min users. An admin account email reset can lead to site takeover.</td> <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6072" target=3D"= _blank" rel=3D"noopener">CVE-2026-6072</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca6aa9= 22-9c58-445c-b88a-3d1d1c95102c?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/ca6aa922-9c5= 8-445c-b88a-3d1d1c95102c?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/oliver-pos/trunk/includes/class-pos-bridge.php#L167=
    9" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/br= owser/oliver-pos/trunk/includes/class-pos-bridge.php#L1679</a><br><a href= =3D"https://plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/incl= udes/class-pos-bridge.php#L1679" target=3D"_blank" rel=3D"noopener">https:/= /plugins.trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes/class-= pos-bridge.php#L1679</a><br><a href=3D"https://plugins.trac.wordpress.org/b= rowser/oliver-pos/trunk/includes/class-pos-bridge.php#L1677" target=3D"_bla= nk" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/oliver-pos/= trunk/includes/class-pos-bridge.php#L1677</a><br><a href=3D"https://plugins= .trac.wordpress.org/browser/oliver-pos/tags/2.4.2.6/includes/class-pos-brid= ge.php#L1677" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordp= ress.org/browser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge.php#L167= 7</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/oliver-pos/t= runk/includes/class-pos-bridge-user.php#L170" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/= class-pos-bridge-user.php#L170</a><br><a href=3D"https://plugins.trac.wordp= ress.org/browser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge-user.php= #L170" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.or= g/browser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge-user.php#L170</= a><br><a href=3D"https://plugins.trac.wordpress.org/browser/oliver-pos/trun= k/includes/class-pos-bridge-user.php#L195" target=3D"_blank" rel=3D"noopene= r">https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/cla= ss-pos-bridge-user.php#L195</a><br><a href=3D"https://plugins.trac.wordpres= s.org/browser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge-user.php#L1= 95" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/b= rowser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge-user.php#L195</a><= br><a href=3D"https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/i= ncludes/class-pos-bridge-user.php#L231" target=3D"_blank" rel=3D"noopener">= https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/class-= pos-bridge-user.php#L231</a><br><a href=3D"https://plugins.trac.wordpress.o= rg/browser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge-user.php#L231"=
    target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brow= ser/oliver-pos/tags/2.4.2.6/includes/class-pos-bridge-user.php#L231</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">olivesystem--</td>
    <td>The =C3=A8=C2=A8=C2=BA=C3=A6=E2=80=93=C2=AD=C3=A3=E2=80=9A=C2=B8=C3=A3= =E2=80=9A=C2=A7=C3=A3=C6=92=C2=8D=C3=A3=C6=92=C2=AC=C3=A3=C6=92=C2=BC=C3=A3= =E2=80=9A=C2=BF=C3=A4=C2=BD=C5=93=C3=A6=CB=86=C2=90=C3=A3=C6=92=E2=80=94=C3= =A3=C6=92=C2=A9=C3=A3=E2=80=9A=C2=B0=C3=A3=E2=80=9A=C2=A4=C3=A3=C6=92=C2=B3=
    (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-S= ite Scripting via the 'js' parameter in versions up to and including 1.4.16=
    . This is due to missing authorization checks and insufficient input saniti= zation in the themeFunc() function. The function is hooked to 'admin_init' = and processes theme update requests without verifying user capabilities, al= lowing any authenticated user (including subscribers) to save malicious Jav= aScript to theme files. Additionally, the save() function uses stripslashes=
    () which removes WordPress's magic quotes protection. This makes it possibl=
    e for authenticated attackers, with subscriber-level access and above, to i= nject arbitrary web scripts in theme files that will execute whenever a use=
    r accesses a page containing the diagnosis form shortcode.</td> <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5293" target=3D"= _blank" rel=3D"noopener">CVE-2026-5293</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5293c= 0f-90b0-41df-a623-90297d998c41?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/c5293c0f-90b= 0-41df-a623-90297d998c41?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/os-diagnosis-generator/trunk/diagnosisAdminClass.ph= p#L409" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.o= rg/browser/os-diagnosis-generator/trunk/diagnosisAdminClass.php#L409</a><br= ><a href=3D"https://plugins.trac.wordpress.org/browser/os-diagnosis-generat= or/tags/1.4.16/diagnosisAdminClass.php#L409" target=3D"_blank" rel=3D"noope= ner">https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags= /1.4.16/diagnosisAdminClass.php#L409</a><br><a href=3D"https://plugins.trac= .wordpress.org/browser/os-diagnosis-generator/trunk/class/themeClass.php#L2=
    6" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/br= owser/os-diagnosis-generator/trunk/class/themeClass.php#L26</a><br><a href= =3D"https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/= 1.4.16/class/themeClass.php#L26" target=3D"_blank" rel=3D"noopener">https:/= /plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/1.4.16/clas= s/themeClass.php#L26</a><br><a href=3D"https://plugins.trac.wordpress.org/b= rowser/os-diagnosis-generator/trunk/class/themeClass.php#L39" target=3D"_bl= ank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/os-diagnos= is-generator/trunk/class/themeClass.php#L39</a><br><a href=3D"https://plugi= ns.trac.wordpress.org/browser/os-diagnosis-generator/tags/1.4.16/class/them= eClass.php#L39" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wor= dpress.org/browser/os-diagnosis-generator/tags/1.4.16/class/themeClass.php#= L39</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/os-diagnos= is-generator/trunk/include_files/user-viewFormPage.php#L102" target=3D"_bla= nk" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/os-diagnosi= s-generator/trunk/include_files/user-viewFormPage.php#L102</a><br><a href= =3D"https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/tags/= 1.4.16/include_files/user-viewFormPage.php#L102" target=3D"_blank" rel=3D"n= oopener">https://plugins.trac.wordpress.org/browser/os-diagnosis-generator/= tags/1.4.16/include_files/user-viewFormPage.php#L102</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A vulnerability was detected in omec-project amf up to 2.1.1. Affected =
    by this vulnerability is an unknown functionality of the component PathSwit= chRequest Handler. The manipulation results in memory corruption. The attac=
    k may be launched remotely. The exploit is now public and may be used. It i=
    s advisable to implement a patch to correct this issue.</td> <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9298" target=3D"= _blank" rel=3D"noopener">CVE-2026-9298</a></td>

    <a href=3D"https://vuldb.com/vuln/365245" target=3D"_blank" rel=3D"noopener= ">VDB-365245 | omec-project amf PathSwitchRequest memory corruption</a><br>=
    <a href=3D"https://vuldb.com/vuln/365245/cti" target=3D"_blank" rel=3D"noop= ener">VDB-365245 | CTI Indicators (IOB, IOC)</a><br><a href=3D"https://vuld= b.com/submit/811684" target=3D"_blank" rel=3D"noopener">Submit #811684 | Li= nux Foundation Projects SD-Core 2.1.1 Memory Corruption</a><br><a href=3D"h= ttps://github.com/omec-project/amf/issues/680" target=3D"_blank" rel=3D"noo= pener">https://github.com/omec-project/amf/issues/680</a><br><a href=3D"htt= ps://github.com/omec-project/amf/pull/666" target=3D"_blank" rel=3D"noopene= r">https://github.com/omec-project/amf/pull/666</a><br><a href=3D"https://g= ithub.com/omec-project/amf/" target=3D"_blank" rel=3D"noopener">https://git= hub.com/omec-project/amf/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A flaw has been found in omec-project amf up to 2.1.1. Affected by this=
    issue is the function PDUSessionResourceModifyIndication of the file /go/s= rc/amf/ngap/handler.go. This manipulation causes memory corruption. Remote = exploitation of the attack is possible. The exploit has been published and = may be used. Applying a patch is the recommended action to fix this issue.<=

    <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9299" target=3D"= _blank" rel=3D"noopener">CVE-2026-9299</a></td>

    <a href=3D"https://vuldb.com/vuln/365246" target=3D"_blank" rel=3D"noopener= ">VDB-365246 | omec-project amf handler.go PDUSessionResourceModifyIndicati=
    on memory corruption</a><br><a href=3D"https://vuldb.com/vuln/365246/cti" t= arget=3D"_blank" rel=3D"noopener">VDB-365246 | CTI Indicators (IOB, IOC, IO= A)</a><br><a href=3D"https://vuldb.com/submit/811829" target=3D"_blank" rel= =3D"noopener">Submit #811829 | Linux Foundation Projects SD-Core 2.1.1 Memo=
    ry Corruption</a><br><a href=3D"https://github.com/omec-project/amf/issues/= 681" target=3D"_blank" rel=3D"noopener">https://github.com/omec-project/amf= /issues/681</a><br><a href=3D"https://github.com/omec-project/amf/pull/666"=
    target=3D"_blank" rel=3D"noopener">https://github.com/omec-project/amf/pul= l/666</a><br><a href=3D"https://github.com/omec-project/amf/" target=3D"_bl= ank" rel=3D"noopener">https://github.com/omec-project/amf/</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A vulnerability has been found in omec-project amf up to 2.1.1. This af= fects an unknown part of the component NGSetupRequest Handler. Such manipul= ation leads to memory corruption. The attack can be executed remotely. The = exploit has been disclosed to the public and may be used. It is best practi=
    ce to apply a patch to resolve this issue.</td>
    <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9300" target=3D"= _blank" rel=3D"noopener">CVE-2026-9300</a></td>

    <a href=3D"https://vuldb.com/vuln/365247" target=3D"_blank" rel=3D"noopener= ">VDB-365247 | omec-project amf NGSetupRequest memory corruption</a><br><a = href=3D"https://vuldb.com/vuln/365247/cti" target=3D"_blank" rel=3D"noopene= r">VDB-365247 | CTI Indicators (IOB, IOC)</a><br><a href=3D"https://vuldb.c= om/submit/811841" target=3D"_blank" rel=3D"noopener">Submit #811841 | Linux=
    Foundation Projects SD-Core 2.1.1 Memory Corruption</a><br><a href=3D"http= s://github.com/omec-project/amf/issues/679" target=3D"_blank" rel=3D"noopen= er">https://github.com/omec-project/amf/issues/679</a><br><a href=3D"https:= //github.com/omec-project/amf/pull/666" target=3D"_blank" rel=3D"noopener">= https://github.com/omec-project/amf/pull/666</a><br><a href=3D"https://gith= ub.com/omec-project/amf/" target=3D"_blank" rel=3D"noopener">https://github= .com/omec-project/amf/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A vulnerability was found in omec-project amf up to 2.1.1. This vulnera= bility affects unknown code of the component NGReset Message Handler. Perfo= rming a manipulation results in memory corruption. The attack is possible t=
    o be carried out remotely. The exploit has been made public and could be us= ed. It is recommended to apply a patch to fix this issue.</td> <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9301" target=3D"= _blank" rel=3D"noopener">CVE-2026-9301</a></td>

    <a href=3D"https://vuldb.com/vuln/365248" target=3D"_blank" rel=3D"noopener= ">VDB-365248 | omec-project amf NGReset Message memory corruption</a><br><a=
    href=3D"https://vuldb.com/vuln/365248/cti" target=3D"_blank" rel=3D"noopen= er">VDB-365248 | CTI Indicators (IOB, IOC)</a><br><a href=3D"https://vuldb.= com/submit/811842" target=3D"_blank" rel=3D"noopener">Submit #811842 | Linu=
    x Foundation Projects SD-Core 2.1.1 Memory Corruption</a><br><a href=3D"htt= ps://github.com/omec-project/amf/issues/678" target=3D"_blank" rel=3D"noope= ner">https://github.com/omec-project/amf/issues/678</a><br><a href=3D"https= ://github.com/omec-project/amf/pull/666" target=3D"_blank" rel=3D"noopener"= >https://github.com/omec-project/amf/pull/666</a><br><a href=3D"https://git= hub.com/omec-project/amf/" target=3D"_blank" rel=3D"noopener">https://githu= b.com/omec-project/amf/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A vulnerability was determined in omec-project amf up to 2.1.3-dev. Imp= acted is the function NGSetupRequest of the file ngap/handler.go. Executing=
    a manipulation of the argument InformationElement can lead to memory corru= ption. The attack can be launched remotely. The exploit has been publicly d= isclosed and may be utilized. Upgrading to version 2.2.0 is recommended to = address this issue. The affected component should be upgraded. The same pul=
    l request fixes multiple security issues.</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8779" target=3D"= _blank" rel=3D"noopener">CVE-2026-8779</a></td>

    <a href=3D"https://vuldb.com/vuln/364403" target=3D"_blank" rel=3D"noopener= ">VDB-364403 | omec-project amf handler.go NGSetupRequest memory corruption= </a><br><a href=3D"https://vuldb.com/vuln/364403/cti" target=3D"_blank" rel= =3D"noopener">VDB-364403 | CTI Indicators (IOB, IOC, IOA)</a><br><a href=3D= "https://vuldb.com/submit/811616" target=3D"_blank" rel=3D"noopener">Submit=
    #811616 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption</a><br= ><a href=3D"https://github.com/omec-project/amf/issues/671" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/omec-project/amf/issues/671</a><br><=
    a href=3D"https://github.com/omec-project/amf/pull/666" target=3D"_blank" r= el=3D"noopener">https://github.com/omec-project/amf/pull/666</a><br><a href= =3D"https://github.com/omec-project/amf/releases/tag/v2.2.0" target=3D"_bla= nk" rel=3D"noopener">https://github.com/omec-project/amf/releases/tag/v2.2.= 0</a><br><a href=3D"https://github.com/omec-project/amf/" target=3D"_blank"=
    rel=3D"noopener">https://github.com/omec-project/amf/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A vulnerability was identified in omec-project amf up to 2.1.3-dev. The=
    affected element is an unknown function of the file ngap/dispatcher.go of = the component NGAP Message Handler. The manipulation leads to memory corrup= tion. The attack may be initiated remotely. The exploit is publicly availab=
    le and might be used. Upgrading to version 2.2.0 is sufficient to fix this = issue. It is suggested to upgrade the affected component. The same pull req= uest fixes multiple security issues.</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8780" target=3D"= _blank" rel=3D"noopener">CVE-2026-8780</a></td>

    <a href=3D"https://vuldb.com/vuln/364404" target=3D"_blank" rel=3D"noopener= ">VDB-364404 | omec-project amf NGAP Message dispatcher.go memory corruptio= n</a><br><a href=3D"https://vuldb.com/vuln/364404/cti" target=3D"_blank" re= l=3D"noopener">VDB-364404 | CTI Indicators (IOB, IOC, IOA)</a><br><a href= =3D"https://vuldb.com/submit/811617" target=3D"_blank" rel=3D"noopener">Sub= mit #811617 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption</a>= <br><a href=3D"https://github.com/omec-project/amf/issues/670" target=3D"_b= lank" rel=3D"noopener">https://github.com/omec-project/amf/issues/670</a><b= r><a href=3D"https://github.com/omec-project/amf/pull/666" target=3D"_blank=
    " rel=3D"noopener">https://github.com/omec-project/amf/pull/666</a><br><a h= ref=3D"https://github.com/omec-project/amf/releases/tag/v2.2.0" target=3D"_= blank" rel=3D"noopener">https://github.com/omec-project/amf/releases/tag/v2= .2.0</a><br><a href=3D"https://github.com/omec-project/amf/" target=3D"_bla= nk" rel=3D"noopener">https://github.com/omec-project/amf/</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A security flaw has been discovered in omec-project amf up to 2.1.3-dev=
    . The impacted element is the function RANConfiguration of the file ngap/ha= ndler.go. The manipulation results in null pointer dereference. The attack = may be launched remotely. The exploit has been released to the public and m=
    ay be used for attacks. Upgrading to version 2.2.0 is sufficient to resolve=
    this issue. Upgrading the affected component is recommended. The same pull=
    request fixes multiple security issues.</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8781" target=3D"= _blank" rel=3D"noopener">CVE-2026-8781</a></td>

    <a href=3D"https://vuldb.com/vuln/364405" target=3D"_blank" rel=3D"noopener= ">VDB-364405 | omec-project amf handler.go RANConfiguration null pointer de= reference</a><br><a href=3D"https://vuldb.com/vuln/364405/cti" target=3D"_b= lank" rel=3D"noopener">VDB-364405 | CTI Indicators (IOB, IOC, IOA)</a><br><=
    a href=3D"https://vuldb.com/submit/811653" target=3D"_blank" rel=3D"noopene= r">Submit #811653 | Linux Foundation Projects SD-Core 2.1.1 Memory Corrupti= on</a><br><a href=3D"https://github.com/omec-project/amf/issues/673" target= =3D"_blank" rel=3D"noopener">https://github.com/omec-project/amf/issues/673= </a><br><a href=3D"https://github.com/omec-project/amf/pull/666" target=3D"= _blank" rel=3D"noopener">https://github.com/omec-project/amf/pull/666</a><b= r><a href=3D"https://github.com/omec-project/amf/releases/tag/v2.2.0" targe= t=3D"_blank" rel=3D"noopener">https://github.com/omec-project/amf/releases/= tag/v2.2.0</a><br><a href=3D"https://github.com/omec-project/amf/" target= =3D"_blank" rel=3D"noopener">https://github.com/omec-project/amf/</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A weakness has been identified in omec-project amf up to 2.1.3-dev. Thi=
    s affects an unknown function of the file ngap/handler.go of the component = NGAP Message Handler. This manipulation causes null pointer dereference. Re= mote exploitation of the attack is possible. The exploit has been made avai= lable to the public and could be used for attacks. Upgrading to version 2.2=
    .0 mitigates this issue. It is recommended to upgrade the affected componen=
    t. The same pull request fixes multiple security issues.</td> <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8782" target=3D"= _blank" rel=3D"noopener">CVE-2026-8782</a></td>

    <a href=3D"https://vuldb.com/vuln/364406" target=3D"_blank" rel=3D"noopener= ">VDB-364406 | omec-project amf NGAP Message handler.go null pointer derefe= rence</a><br><a href=3D"https://vuldb.com/vuln/364406/cti" target=3D"_blank=
    " rel=3D"noopener">VDB-364406 | CTI Indicators (IOB, IOC, IOA)</a><br><a hr= ef=3D"https://vuldb.com/submit/811654" target=3D"_blank" rel=3D"noopener">S= ubmit #811654 | Linux Foundation Projects SD-Core 2.1.1 Memory Corruption</= a><br><a href=3D"https://github.com/omec-project/amf/issues/674" target=3D"= _blank" rel=3D"noopener">https://github.com/omec-project/amf/issues/674</a>= <br><a href=3D"https://github.com/omec-project/amf/pull/666" target=3D"_bla= nk" rel=3D"noopener">https://github.com/omec-project/amf/pull/666</a><br><a=
    href=3D"https://github.com/omec-project/amf/releases/tag/v2.2.0" target=3D= "_blank" rel=3D"noopener">https://github.com/omec-project/amf/releases/tag/= v2.2.0</a><br><a href=3D"https://github.com/omec-project/amf/" target=3D"_b= lank" rel=3D"noopener">https://github.com/omec-project/amf/</a><br>=C2=A0</=

    </tr>

    <td class=3D"vendor-product">omec-project--amf</td>
    <td>A security vulnerability has been detected in omec-project amf up to 2.= 1.3-dev. This impacts the function UERadioCapabilityCheckResponse of the fi=
    le ngap/dispatcher.go. Such manipulation leads to null pointer dereference.=
    The attack can be executed remotely. The exploit has been disclosed public=
    ly and may be used. Upgrading to version 2.2.0 will fix this issue. Upgradi=
    ng the affected component is advised. The same pull request fixes multiple = security issues.</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8783" target=3D"= _blank" rel=3D"noopener">CVE-2026-8783</a></td>

    <a href=3D"https://vuldb.com/vuln/364407" target=3D"_blank" rel=3D"noopener= ">VDB-364407 | omec-project amf dispatcher.go UERadioCapabilityCheckRespons=
    e null pointer dereference</a><br><a href=3D"https://vuldb.com/vuln/364407/= cti" target=3D"_blank" rel=3D"noopener">VDB-364407 | CTI Indicators (IOB, I= OC, IOA)</a><br><a href=3D"https://vuldb.com/submit/811655" target=3D"_blan=
    k" rel=3D"noopener">Submit #811655 | Linux Foundation Projects SD-Core 2.1.=
    1 Memory Corruption</a><br><a href=3D"https://github.com/omec-project/amf/i= ssues/675" target=3D"_blank" rel=3D"noopener">https://github.com/omec-proje= ct/amf/issues/675</a><br><a href=3D"https://github.com/omec-project/amf/pul= l/666" target=3D"_blank" rel=3D"noopener">https://github.com/omec-project/a= mf/pull/666</a><br><a href=3D"https://github.com/omec-project/amf/releases/= tag/v2.2.0" target=3D"_blank" rel=3D"noopener">https://github.com/omec-proj= ect/amf/releases/tag/v2.2.0</a><br><a href=3D"https://github.com/omec-proje= ct/amf/" target=3D"_blank" rel=3D"noopener">https://github.com/omec-project= /amf/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in add.php that allows authenticated attackers to inject a= rbitrary JavaScript by passing an unsanitized value through the ticket_id P= OST parameter directly into an HTML form input value attribute. Attackers c=
    an craft a malicious request containing a JavaScript payload that executes =
    in the victim's browser when the response is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48213" target=3D= "_blank" rel=3D"noopener">CVE-2026-48213</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-add-php-ticket-id-parameter" target=3D"_blank" rel= =3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-reflec= ted-xss-via-add-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in add_nm.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the ticket_i=
    d POST parameter directly into an HTML form input value attribute and an in= line JavaScript string literal. Attackers can craft a malicious request con= taining a JavaScript payload that executes in the victim's browser when the=
    response is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48214" target=3D= "_blank" rel=3D"noopener">CVE-2026-48214</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-add-nm-php-ticket-id-parameter" target=3D"_blank" r= el=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-refl= ected-xss-via-add-nm-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in circle.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the frm_id P= OST parameter directly into an HTML form input value attribute. Attackers c=
    an craft a malicious request containing a JavaScript payload that executes =
    in the victim's browser when the response is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48215" target=3D= "_blank" rel=3D"noopener">CVE-2026-48215</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-circle-php-frm-id-parameter" target=3D"_blank" rel= =3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-reflec= ted-xss-via-circle-php-frm-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in db_loader.php that allows authenticated attackers to in= ject arbitrary JavaScript by passing an unsanitized value through the multi= ple POST parameters (ticketshost, ticketsdb, ticketsuser, ticketspassword, = ticketsprefix, db_schema) directly into HTML form input value attributes. A= ttackers can craft a malicious request containing a JavaScript payload that=
    executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48216" target=3D= "_blank" rel=3D"noopener">CVE-2026-48216</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-db-loader-php-multiple-parameters" target=3D"_blank=
    " rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-r= eflected-xss-via-db-loader-php-multiple-parameters</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in delete_module.php that allows authenticated attackers t=
    o inject arbitrary JavaScript by passing an unsanitized value through the m= ultiple POST parameters (module_choice, flag, confirmation) directly into r= endered HTML content and form action attributes. Attackers can craft a mali= cious request containing a JavaScript payload that executes in the victim's=
    browser when the response is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48217" target=3D= "_blank" rel=3D"noopener">CVE-2026-48217</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-delete-module-php-multiple-parameters" target=3D"_b= lank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-ticke= ts-reflected-xss-via-delete-module-php-multiple-parameters</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in icons/buttons/landb.php that allows authenticated attac= kers to inject arbitrary JavaScript by passing an unsanitized value through=
    the frm_name and frm_id POST parameters directly into rendered HTML conten=
    t and inline JavaScript. Attackers can craft a malicious request containing=
    a JavaScript payload that executes in the victim's browser when the respon=
    se is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48218" target=3D= "_blank" rel=3D"noopener">CVE-2026-48218</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-icons-buttons-landb-php-frm-name-and-frm-id-paramet= ers" target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisorie= s/open-ises-tickets-reflected-xss-via-icons-buttons-landb-php-frm-name-and-= frm-id-parameters</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ics202.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the frm_add_= str POST parameter directly into an HTML form hidden input value attribute.=
    Attackers can craft a malicious request containing a JavaScript payload th=
    at executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48219" target=3D= "_blank" rel=3D"noopener">CVE-2026-48219</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ics202-php-frm-add-str-parameter" target=3D"_blank"=
    rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-re= flected-xss-via-ics202-php-frm-add-str-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ics205.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the frm_add_= str POST parameter directly into an HTML form hidden input value attribute.=
    Attackers can craft a malicious request containing a JavaScript payload th=
    at executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48220" target=3D= "_blank" rel=3D"noopener">CVE-2026-48220</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ics205-php-frm-add-str-parameter" target=3D"_blank"=
    rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-re= flected-xss-via-ics205-php-frm-add-str-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ics205a.php that allows authenticated attackers to inje=
    ct arbitrary JavaScript by passing an unsanitized value through the frm_add= _str POST parameter directly into an HTML form hidden input value attribute=
    . Attackers can craft a malicious request containing a JavaScript payload t= hat executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48221" target=3D= "_blank" rel=3D"noopener">CVE-2026-48221</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ics205a-php-frm-add-str-parameter" target=3D"_blank=
    " rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-r= eflected-xss-via-ics205a-php-frm-add-str-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ics213.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the frm_add_= str POST parameter directly into an HTML form hidden input value attribute.=
    Attackers can craft a malicious request containing a JavaScript payload th=
    at executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48222" target=3D= "_blank" rel=3D"noopener">CVE-2026-48222</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ics213-php-frm-add-str-parameter" target=3D"_blank"=
    rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-re= flected-xss-via-ics213-php-frm-add-str-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ics213rr.php that allows authenticated attackers to inj= ect arbitrary JavaScript by passing an unsanitized value through the frm_ad= d_str POST parameter directly into an HTML form hidden input value attribut=
    e. Attackers can craft a malicious request containing a JavaScript payload = that executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48223" target=3D= "_blank" rel=3D"noopener">CVE-2026-48223</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ics213rr-php-frm-add-str-parameter" target=3D"_blan=
    k" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-= reflected-xss-via-ics213rr-php-frm-add-str-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ics214.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the frm_add_= str POST parameter directly into an HTML form hidden input value attribute.=
    Attackers can craft a malicious request containing a JavaScript payload th=
    at executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48224" target=3D= "_blank" rel=3D"noopener">CVE-2026-48224</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ics214-php-frm-add-str-parameter" target=3D"_blank"=
    rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-re= flected-xss-via-ics214-php-frm-add-str-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in landb.php that allows authenticated attackers to inject=
    arbitrary JavaScript by passing an unsanitized value through the _type POS=
    T parameter directly into an HTML form hidden input value attribute. Attack= ers can craft a malicious request containing a JavaScript payload that exec= utes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48225" target=3D= "_blank" rel=3D"noopener">CVE-2026-48225</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-landb-php-type-parameter" target=3D"_blank" rel=3D"= noopener">https://www.vulncheck.com/advisories/open-ises-tickets-reflected-= xss-via-landb-php-type-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in os_watch.php that allows authenticated attackers to inj= ect arbitrary JavaScript by passing an unsanitized value through the ref an=
    d mode_orig POST parameters directly into HTML form hidden input value attr= ibutes. Attackers can craft a malicious request containing a JavaScript pay= load that executes in the victim's browser when the response is rendered.</=

    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48226" target=3D= "_blank" rel=3D"noopener">CVE-2026-48226</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-os-watch-php-ref-and-mode-orig-parameters" target= =3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises= -tickets-reflected-xss-via-os-watch-php-ref-and-mode-orig-parameters</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in patient.php that allows authenticated attackers to inje=
    ct arbitrary JavaScript by passing an unsanitized value through the id and = ticket_id GET parameters directly into an HTML form action URL. Attackers c=
    an craft a malicious request containing a JavaScript payload that executes =
    in the victim's browser when the response is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48227" target=3D= "_blank" rel=3D"noopener">CVE-2026-48227</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-patient-php-id-and-ticket-id-parameters" target=3D"= _blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tic= kets-reflected-xss-via-patient-php-id-and-ticket-id-parameters</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in patient_w.php that allows authenticated attackers to in= ject arbitrary JavaScript by passing an unsanitized value through the id an=
    d ticket_id GET parameters directly into an HTML form action URL. Attackers=
    can craft a malicious request containing a JavaScript payload that execute=
    s in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48228" target=3D= "_blank" rel=3D"noopener">CVE-2026-48228</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-patient-w-php-id-and-ticket-id-parameters" target= =3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises= -tickets-reflected-xss-via-patient-w-php-id-and-ticket-id-parameters</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in routes_i.php that allows authenticated attackers to inj= ect arbitrary JavaScript by passing an unsanitized value through the ticket= _id GET parameter directly into HTML form hidden input value attributes. At= tackers can craft a malicious request containing a JavaScript payload that = executes in the victim's browser when the response is rendered.</td> <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48229" target=3D= "_blank" rel=3D"noopener">CVE-2026-48229</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-routes-i-php-ticket-id-parameter" target=3D"_blank"=
    rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-re= flected-xss-via-routes-i-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in ticketsmdb_import.php that allows authenticated attacke=
    rs to inject arbitrary JavaScript by passing an unsanitized value through t=
    he multiple POST parameters (mdbhost, mdbdb, mdbuser, mdbpassword, mdbprefi=
    x, ticketshost, ticketsdb, ticketsuser, ticketspassword, ticketsprefix) dir= ectly into HTML form hidden input value attributes. Attackers can craft a m= alicious request containing a JavaScript payload that executes in the victi= m's browser when the response is rendered.</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48230" target=3D= "_blank" rel=3D"noopener">CVE-2026-48230</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-ticketsmdb-import-php-multiple-parameters" target= =3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises= -tickets-reflected-xss-via-ticketsmdb-import-php-multiple-parameters</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-p= hone API key in wp1.php that is committed to the public source repository. = Any actor with read access to the source tree can extract the key and use i=
    t to make third-party API calls billed to or rate-limited against the origi= nal owner's WhitePages account.</td>
    <td>2026-05-21</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48243" target=3D= "_blank" rel=3D"noopener">CVE-2026-48243</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-hardcoded-whitepages-api-key-in-wp1-php" target=3D"_blank" rel=3D"noo= pener">https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-whi= tepages-api-key-in-wp1-php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key =
    in settings.inc.php that is committed to the public source repository. The = key can be extracted by anyone with read access to the source and used to m= ake Google Maps Platform requests billed against the original owner's Googl=
    e Cloud project.</td>
    <td>2026-05-21</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48244" target=3D= "_blank" rel=3D"noopener">CVE-2026-48244</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-hardcoded-google-maps-api-key-in-settings-inc-php" target=3D"_blank" = rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-har= dcoded-google-maps-api-key-in-settings-inc-php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key =
    in tables.php that is committed to the public source repository. The key ca=
    n be extracted by anyone with read access to the source and used to make Go= ogle Maps Platform requests billed against the original owner's Google Clou=
    d project.</td>
    <td>2026-05-21</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48245" target=3D= "_blank" rel=3D"noopener">CVE-2026-48245</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-hardcoded-google-maps-api-key-in-tables-php" target=3D"_blank" rel=3D= "noopener">https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded= -google-maps-api-key-in-tables-php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 disables TLS certificate verification i=
    n ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not sett= ing CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google=
    Maps Directions API lookups during incident report generation. An attacker=
    positioned on the network path between the server and the remote endpoint = can present a forged certificate to intercept, monitor, or modify the reque=
    st and response, including any API keys or session-bearing data in transit.= </td>
    <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48246" target=3D= "_blank" rel=3D"noopener">CVE-2026-48246</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-disabled-tls-certificate-verification-in-ajax-reports-php" target=3D"= _blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tic= kets-disabled-tls-certificate-verification-in-ajax-reports-php</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 disables TLS certificate verification i=
    n incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and no=
    t setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for = general-purpose outbound HTTPS requests issued by the shared helper functio= ns. An attacker positioned on the network path between the server and the r= emote endpoint can present a forged certificate to intercept, monitor, or m= odify the request and response, including any API keys or session-bearing d= ata in transit.</td>
    <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48247" target=3D= "_blank" rel=3D"noopener">CVE-2026-48247</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-disabled-tls-certificate-verification-in-incs-functions-inc-php" targ= et=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-is= es-tickets-disabled-tls-certificate-verification-in-incs-functions-inc-php<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 disables TLS certificate verification i=
    n incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not se= tting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued d= uring the login/authentication flow. An attacker positioned on the network = path between the server and the remote endpoint can present a forged certif= icate to intercept, monitor, or modify the request and response, including = any API keys or session-bearing data in transit.</td>
    <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48248" target=3D= "_blank" rel=3D"noopener">CVE-2026-48248</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-disabled-tls-certificate-verification-in-incs-login-inc-php" target= =3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises= -tickets-disabled-tls-certificate-verification-in-incs-login-inc-php</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Open ISES--Tickets</td>
    <td>Open ISES Tickets before 3.44.2 disables TLS certificate verification i=
    n rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (= and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS request=
    s issued during the mobile (RouteMate) login flow. An attacker positioned o=
    n the network path between the server and the remote endpoint can present a=
    forged certificate to intercept, monitor, or modify the request and respon= se, including any API keys or session-bearing data in transit.</td> <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48249" target=3D= "_blank" rel=3D"noopener">CVE-2026-48249</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-disabled-tls-certificate-verification-in-rm-incs-mobile-login-inc-php=
    " target=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/o= pen-ises-tickets-disabled-tls-certificate-verification-in-rm-incs-mobile-lo= gin-inc-php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary=
    code execution.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28733" target=3D= "_blank" rel=3D"noopener">CVE-2026-28733</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-05.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 05.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause inf= ormation leak</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25850" target=3D= "_blank" rel=3D"noopener">CVE-2026-25850</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-05.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 05.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause inf= ormation leak.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27766" target=3D= "_blank" rel=3D"noopener">CVE-2026-27766</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-05.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 05.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in single_unit.php that allows authenticated attackers to = inject arbitrary JavaScript by passing an unsanitized value through the id = GET parameter directly into an HTML attribute. Attackers can craft a malici= ous URL containing a JavaScript payload in the id parameter that executes i=
    n the victim's browser when the URL is visited.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35007" target=3D= "_blank" rel=3D"noopener">CVE-2026-35007</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-single-unit-php-id-parameter" target=3D"_blank" rel= =3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-reflec= ted-xss-via-single-unit-php-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in single.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the ticket_i=
    d GET parameter directly into an HTML attribute. Attackers can craft a mali= cious URL containing a JavaScript payload in the id parameter that executes=
    in the victim's browser when the URL is visited.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35008" target=3D= "_blank" rel=3D"noopener">CVE-2026-35008</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-single-php-ticket-id-parameter" target=3D"_blank" r= el=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-refl= ected-xss-via-single-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in add_note.php that allows authenticated attackers to inj= ect arbitrary JavaScript by passing an unsanitized value through the ticket= _id GET parameter directly into a hidden input field VALUE attribute. Attac= kers can craft a malicious URL containing a JavaScript payload in the ticke= t_id parameter that executes in the victim's browser when the URL is visite= d.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35009" target=3D= "_blank" rel=3D"noopener">CVE-2026-35009</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-add-note-php-ticket-id-parameter" target=3D"_blank"=
    rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-re= flected-xss-via-add-note-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in patient_JF.php that allows authenticated attackers to i= nject arbitrary JavaScript by passing an unsanitized value through the tick= et_id GET parameter directly into a JavaScript variable assignment. Attacke=
    rs can craft a malicious URL containing a JavaScript payload in the ticket_=
    id parameter that executes in the victim's browser when the URL is visited.= </td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35010" target=3D= "_blank" rel=3D"noopener">CVE-2026-35010</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-patient-jf-php-ticket-id-parameter" target=3D"_blan=
    k" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-= reflected-xss-via-patient-jf-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in opena.php that allows authenticated attackers to inject=
    arbitrary JavaScript by passing an unsanitized value through the frm_call = GET parameter directly into page output. Attackers can craft a malicious UR=
    L containing a JavaScript payload in the frm_call parameter that executes i=
    n the victim's browser when the URL is visited.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35011" target=3D= "_blank" rel=3D"noopener">CVE-2026-35011</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-opena-php-frm-call-parameter" target=3D"_blank" rel= =3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-reflec= ted-xss-via-opena-php-frm-call-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in add_facnote.php that allows authenticated attackers to = inject arbitrary JavaScript by passing an unsanitized value through the tic= ket_id GET parameter directly into a hidden input field VALUE attribute. At= tackers can craft a malicious URL containing a JavaScript payload in the ti= cket_id parameter that executes in the victim's browser when the URL is vis= ited.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35012" target=3D= "_blank" rel=3D"noopener">CVE-2026-35012</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-add-facnote-php-ticket-id-parameter" target=3D"_bla= nk" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets= -reflected-xss-via-add-facnote-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in street_view.php that allows authenticated attackers to = inject arbitrary JavaScript by passing unsanitized values through the thela=
    t and thelng GET parameters directly into JavaScript variable assignments. = Attackers can craft a malicious URL containing a JavaScript payload in eith=
    er parameter that executes in the victim's browser when the URL is visited.= </td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35013" target=3D= "_blank" rel=3D"noopener">CVE-2026-35013</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-street-view-php-thelat-and-thelng-parameters" targe= t=3D"_blank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ise= s-tickets-reflected-xss-via-street-view-php-thelat-and-thelng-parameters</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in routes_nm.php that allows authenticated attackers to in= ject arbitrary JavaScript by passing an unsanitized value through the ticke= t_id GET parameter directly into a hidden input field VALUE attribute. Atta= ckers can craft a malicious URL containing a JavaScript payload in the tick= et_id parameter that executes in the victim's browser when the URL is visit= ed.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35014" target=3D= "_blank" rel=3D"noopener">CVE-2026-35014</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-routes-nm-php-ticket-id-parameter" target=3D"_blank=
    " rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-r= eflected-xss-via-routes-nm-php-ticket-id-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in do_unit_mail.php that allows authenticated attackers to=
    inject arbitrary JavaScript by passing an unsanitized value through the th= e_ticket GET parameter directly into a JavaScript variable assignment. Atta= ckers can craft a malicious URL containing a JavaScript payload in the the_= ticket parameter that executes in the victim's browser when the URL is visi= ted.</td>
    <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35015" target=3D= "_blank" rel=3D"noopener">CVE-2026-35015</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-do-unit-mail-php-the-ticket-parameter" target=3D"_b= lank" rel=3D"noopener">https://www.vulncheck.com/advisories/open-ises-ticke= ts-reflected-xss-via-do-unit-mail-php-the-ticket-parameter</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">openises--tickets</td>
    <td>Open ISES Tickets before 3.44.2 contains a reflected cross-site scripti=
    ng vulnerability in search.php that allows authenticated attackers to injec=
    t arbitrary JavaScript by passing an unsanitized value through the frm_quer=
    y POST parameter directly into an HTML input field VALUE attribute. Attacke=
    rs can craft a malicious request containing a JavaScript payload in the frm= _query parameter that executes in the victim's browser when submitted.</td> <td>2026-05-20</td>
    <td>4.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35016" target=3D= "_blank" rel=3D"noopener">CVE-2026-35016</a></td>

    <a href=3D"https://github.com/openises/tickets/releases/tag/v3.44.2" target= =3D"_blank" rel=3D"noopener">https://github.com/openises/tickets/releases/t= ag/v3.44.2</a><br><a href=3D"https://github.com/openises/tickets/commit/ecf= eb406a016766cae81c749e14b5145a9f2dbff" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a= 9f2dbff</a><br><a href=3D"https://www.vulncheck.com/advisories/open-ises-ti= ckets-reflected-xss-via-search-php-frm-query-parameter" target=3D"_blank" r= el=3D"noopener">https://www.vulncheck.com/advisories/open-ises-tickets-refl= ected-xss-via-search-php-frm-query-parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">opensourcepos--Open Source Point of Sale</td> <td>A vulnerability was detected in opensourcepos Open Source Point of Sale=
    up to 3.4.2. This issue affects the function getPicThumb of the file app/C= ontrollers/Items.php. The manipulation of the argument pic_filename results=
    in path traversal. The attack may be launched remotely. The patch is ident= ified as def0c27a0e252668df8d942fc31e16d1edfd7323. A patch should be applie=
    d to remediate this issue. The vendor was contacted early about this disclo= sure.</td>
    <td>2026-05-18</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8802" target=3D"= _blank" rel=3D"noopener">CVE-2026-8802</a></td>

    <a href=3D"https://vuldb.com/vuln/364435" target=3D"_blank" rel=3D"noopener= ">VDB-364435 | opensourcepos Open Source Point of Sale Items.php getPicThum=
    b path traversal</a><br><a href=3D"https://vuldb.com/vuln/364435/cti" targe= t=3D"_blank" rel=3D"noopener">VDB-364435 | CTI Indicators (IOB, IOC, TTP, I= OA)</a><br><a href=3D"https://vuldb.com/submit/802559" target=3D"_blank" re= l=3D"noopener">Submit #802559 | opensourcepos Open Source Point of Sale 3.4=
    .1 Path Traversal</a><br><a href=3D"https://github.com/opensourcepos/openso= urcepos/security/advisories/GHSA-xq63-3v4g-39r5" target=3D"_blank" rel=3D"n= oopener">https://github.com/opensourcepos/opensourcepos/security/advisories= /GHSA-xq63-3v4g-39r5</a><br><a href=3D"https://github.com/opensourcepos/ope= nsourcepos/pull/4545" target=3D"_blank" rel=3D"noopener">https://github.com= /opensourcepos/opensourcepos/pull/4545</a><br><a href=3D"https://github.com= /opensourcepos/opensourcepos/commit/def0c27a0e252668df8d942fc31e16d1edfd732=
    3" target=3D"_blank" rel=3D"noopener">https://github.com/opensourcepos/open= sourcepos/commit/def0c27a0e252668df8d942fc31e16d1edfd7323</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">owencutajar--SponsorMe</td>
    <td>The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Sit=
    e Scripting via PHP_SELF Parameter in all versions up to, and including, 0.= 5.2 due to insufficient input sanitization and output escaping. This makes =
    it possible for unauthenticated attackers to inject arbitrary web scripts i=
    n pages that execute if they can successfully trick a user into performing =
    an action such as clicking on a link. The PHP_SELF value is reflected in tw=
    o separate locations within the vulnerable function - a form action attribu=
    te and an anchor href attribute - both of which can be exploited by appendi=
    ng a crafted payload to the wp-admin/admin.php URL path.</td> <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8626" target=3D"= _blank" rel=3D"noopener">CVE-2026-8626</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/7df7f5= 41-b8aa-46fa-bfca-b333beea27f9?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/7df7f541-b8a= a-46fa-bfca-b333beea27f9?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/sponsorme/trunk/sponsorme.php#L440" target=3D"_blan=
    k" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/sponsorme/tr= unk/sponsorme.php#L440</a><br><a href=3D"https://plugins.trac.wordpress.org= /browser/sponsorme/trunk/sponsorme.php#L475" target=3D"_blank" rel=3D"noope= ner">https://plugins.trac.wordpress.org/browser/sponsorme/trunk/sponsorme.p= hp#L475</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">pftool--Alfie Feed Plugin</td>
    <td>The Alfie - Feed Plugin plugin for WordPress is vulnerable to Cross-Sit=
    e Request Forgery in all versions up to, and including, 1.2.1. This is due =
    to missing nonce validation on the alfie_manage() function which handles fe=
    ed deletion via the 'delete' GET parameter. This makes it possible for unau= thenticated attackers to delete arbitrary plugin feed data (from alfie_coli= ndex, alfie_producten, alfie_reactions, and alfie_searchproduct tables) via=
    a forged request granted they can trick a site administrator into performi=
    ng an action such as clicking on a link.</td>
    <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4070" target=3D"= _blank" rel=3D"noopener">CVE-2026-4070</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/af3671= 9a-8f7d-46dc-a697-cfcbb08e45e2?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/af36719a-8f7= d-46dc-a697-cfcbb08e45e2?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/alfie-the-productfeedtool-wp-plugin/trunk/include/a= lfie-manage.php#L60" target=3D"_blank" rel=3D"noopener">https://plugins.tra= c.wordpress.org/browser/alfie-the-productfeedtool-wp-plugin/trunk/include/a= lfie-manage.php#L60</a><br><a href=3D"https://plugins.trac.wordpress.org/br= owser/alfie-the-productfeedtool-wp-plugin/tags/1.2.1/include/alfie-manage.p= hp#L60" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.o= rg/browser/alfie-the-productfeedtool-wp-plugin/tags/1.2.1/include/alfie-man= age.php#L60</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/al= fie-the-productfeedtool-wp-plugin/trunk/include/alfie-manage.php#L58" targe= t=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/al= fie-the-productfeedtool-wp-plugin/trunk/include/alfie-manage.php#L58</a><br= ><a href=3D"https://plugins.trac.wordpress.org/browser/alfie-the-productfee= dtool-wp-plugin/tags/1.2.1/include/alfie-manage.php#L58" target=3D"_blank" = rel=3D"noopener">https://plugins.trac.wordpress.org/browser/alfie-the-produ= ctfeedtool-wp-plugin/tags/1.2.1/include/alfie-manage.php#L58</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">PowerDNS--Authoritative</td>
    <td>Insufficient Validation of Names During AXFR</td>
    <td>2026-05-21</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42000" target=3D= "_blank" rel=3D"noopener">CVE-2026-42000</a></td>

    <a href=3D"https://docs.powerdns.com/authoritative/security-advisories/powe= rdns-advisory-powerdns-2026-06.html" target=3D"_blank" rel=3D"noopener">htt= ps://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-= powerdns-2026-06.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">PowerDNS--Authoritative</td>
    <td>Concurrency and locking defects in GSS-TSIG</td>
    <td>2026-05-21</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42002" target=3D= "_blank" rel=3D"noopener">CVE-2026-42002</a></td>

    <a href=3D"https://docs.powerdns.com/authoritative/security-advisories/powe= rdns-advisory-powerdns-2026-06.html" target=3D"_blank" rel=3D"noopener">htt= ps://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-= powerdns-2026-06.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">PowerDNS--Authoritative</td>
    <td>Incorrect Behaviour of Views with TCP PROXY Requests</td> <td>2026-05-21</td>
    <td>4.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41999" target=3D= "_blank" rel=3D"noopener">CVE-2026-41999</a></td>

    <a href=3D"https://docs.powerdns.com/authoritative/security-advisories/powe= rdns-advisory-powerdns-2026-06.html" target=3D"_blank" rel=3D"noopener">htt= ps://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-= powerdns-2026-06.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">PowerDNS--Authoritative</td>
    <td>Insufficient Validation of Member Zone Data May Cause Catalog Zone Tran= sfer to Fail</td>
    <td>2026-05-21</td>
    <td>4.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42396" target=3D= "_blank" rel=3D"noopener">CVE-2026-42396</a></td>

    <a href=3D"https://docs.powerdns.com/authoritative/security-advisories/powe= rdns-advisory-powerdns-2026-06.html" target=3D"_blank" rel=3D"noopener">htt= ps://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-= powerdns-2026-06.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Progress Software--MOVEit Automation</td> <td>Incorrect default permissions vulnerability in Progress Software MOVEit=
    Automation allows Retrieve Embedded Sensitive Data. This issue affects MOV= Eit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.</td> <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8487" target=3D"= _blank" rel=3D"noopener">CVE-2026-8487</a></td>

    <a href=3D"https://docs.progress.com/bundle/moveit-automation-release-notes= -2026/page/Fixed-Issues-2026.html" target=3D"_blank" rel=3D"noopener">https= ://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed= -Issues-2026.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Progress Software--MOVEit Automation</td> <td>Uncontrolled Memory Allocation vulnerability in Progress Software MOVEi=
    t Automation allows Excessive Allocation. This issue affects MOVEit Automat= ion: before 2025.0.11, from 2025.1.0 before 2025.1.7.</td>
    <td>2026-05-20</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8485" target=3D"= _blank" rel=3D"noopener">CVE-2026-8485</a></td>

    <a href=3D"https://docs.progress.com/bundle/moveit-automation-release-notes= -2026/page/Fixed-Issues-2026.html" target=3D"_blank" rel=3D"noopener">https= ://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed= -Issues-2026.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Progress Software--MOVEit Automation</td> <td>Allocation of resources without limits or throttling vulnerability in P= rogress Software MOVEit Automation allows Flooding. This issue affects MOVE=
    it Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.</td> <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8486" target=3D"= _blank" rel=3D"noopener">CVE-2026-8486</a></td>

    <a href=3D"https://docs.progress.com/bundle/moveit-automation-release-notes= -2026/page/Fixed-Issues-2026.html" target=3D"_blank" rel=3D"noopener">https= ://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed= -Issues-2026.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Progress Software--MOVEit Automation</td> <td>Allocation of resources without limits or throttling vulnerability in P= rogress Software MOVEit Automation allows Excessive Allocation. This issue = affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.= </td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8488" target=3D"= _blank" rel=3D"noopener">CVE-2026-8488</a></td>

    <a href=3D"https://docs.progress.com/bundle/moveit-automation-release-notes= -2026/page/Fixed-Issues-2026.html" target=3D"_blank" rel=3D"noopener">https= ://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed= -Issues-2026.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">QuantumNous--new-api</td>
    <td>A weakness has been identified in QuantumNous new-api up to 0.12.1. The=
    impacted element is the function SearchUserTopUps/SearchAllTopUps of the f= ile model/topup.go of the component self Endpoint. This manipulation causes=
    sql injection. The attack can be initiated remotely. The exploit has been = made available to the public and could be used for attacks. The vendor was = contacted early about this disclosure but did not respond in any way.</td> <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9305" target=3D"= _blank" rel=3D"noopener">CVE-2026-9305</a></td>

    <a href=3D"https://vuldb.com/vuln/365252" target=3D"_blank" rel=3D"noopener= ">VDB-365252 | QuantumNous new-api self Endpoint topup.go SearchAllTopUps s=
    ql injection</a><br><a href=3D"https://vuldb.com/vuln/365252/cti" target=3D= "_blank" rel=3D"noopener">VDB-365252 | CTI Indicators (IOB, IOC, TTP, IOA)<= /a><br><a href=3D"https://vuldb.com/submit/812192" target=3D"_blank" rel=3D= "noopener">Submit #812192 | QuantumNous new-api [Needs Manual Input] SQL In= jection (CWE-89)</a><br><a href=3D"https://vuldb.com/submit/812195" target= =3D"_blank" rel=3D"noopener">Submit #812195 | QuantumNous new-api 0.12.1 Im= proper Neutralization of Data Query Logic (CWE-943) (Duplicate)</a><br><a h= ref=3D"https://gist.github.com/YLChen-007/cf501d0a66c81298b2f97e854f3813db"=
    target=3D"_blank" rel=3D"noopener">https://gist.github.com/YLChen-007/cf50= 1d0a66c81298b2f97e854f3813db</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">rdbeach--BLOGCHAT Chat System</td>
    <td>The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Si=
    te Request Forgery in all versions up to, and including, 1.3.6.3. This is d=
    ue to missing or incorrect nonce validation on a function. This makes it po= ssible for unauthenticated attackers to update settings and inject maliciou=
    s web scripts via a forged request granted they can trick a site administra= tor into performing an action such as clicking on a link.</td> <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8420" target=3D"= _blank" rel=3D"noopener">CVE-2026-8420</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/a62186= aa-19aa-445b-8fdc-b029bdafd58f?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/a62186aa-19a= a-445b-8fdc-b029bdafd58f?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/blogchat-chat-system/trunk/wp-blogchat-widget.php#L= 208" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/= browser/blogchat-chat-system/trunk/wp-blogchat-widget.php#L208</a><br><a hr= ef=3D"https://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/= 1.3.6.3/wp-blogchat-widget.php#L208" target=3D"_blank" rel=3D"noopener">htt= ps://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.3/w= p-blogchat-widget.php#L208</a><br><a href=3D"https://plugins.trac.wordpress= .org/browser/blogchat-chat-system/trunk/wp-blogchat-widget.php#L215" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/blo= gchat-chat-system/trunk/wp-blogchat-widget.php#L215</a><br><a href=3D"https= ://plugins.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.3/wp-= blogchat-widget.php#L215" target=3D"_blank" rel=3D"noopener">https://plugin= s.trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.3/wp-blogchat-= widget.php#L215</a><br><a href=3D"https://plugins.trac.wordpress.org/browse= r/blogchat-chat-system/trunk/wp-blogchat-widget.php#L222" target=3D"_blank"=
    rel=3D"noopener">https://plugins.trac.wordpress.org/browser/blogchat-chat-= system/trunk/wp-blogchat-widget.php#L222</a><br><a href=3D"https://plugins.= trac.wordpress.org/browser/blogchat-chat-system/tags/1.3.6.3/wp-blogchat-wi= dget.php#L222" target=3D"_blank" rel=3D"noopener">https://plugins.trac.word= press.org/browser/blogchat-chat-system/tags/1.3.6.3/wp-blogchat-widget.php#= L222</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/blogchat-= chat-system/trunk/wp-blogchat-widget.php#L293" target=3D"_blank" rel=3D"noo= pener">https://plugins.trac.wordpress.org/browser/blogchat-chat-system/trun= k/wp-blogchat-widget.php#L293</a><br><a href=3D"https://plugins.trac.wordpr= ess.org/browser/blogchat-chat-system/tags/1.3.6.3/wp-blogchat-widget.php#L2= 93" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/b= rowser/blogchat-chat-system/tags/1.3.6.3/wp-blogchat-widget.php#L293</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Build of Keycloak</td>
    <td>A flaw was found in Keycloak. The cross-session verification proof is k= eyed only by (local userId, idpAlias) and is not bound to the upstream iden= tity that was actually verified, so a second upstream account on the same I=
    dP can consume it and get linked to the victim's local account.</td> <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9087" target=3D"= _blank" rel=3D"noopener">CVE-2026-9087</a></td>

    <a href=3D"https://access.redhat.com/security/cve/CVE-2026-9087" target=3D"= _blank" rel=3D"noopener">https://access.redhat.com/security/cve/CVE-2026-90= 87</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cgi?id=3D2480172"=
    target=3D"_blank" rel=3D"noopener">RHBZ#2480172</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Build of Keycloak</td>
    <td>A flaw was found in Keycloak. When both realm-level and client-level `n= otBefore` revocation policies are configured, Keycloak's OpenID Connect (OI= DC) Introspection feature fails to properly honor the realm-level policy. T= his allows tokens that should have been revoked to remain active, potential=
    ly leading to unauthorized access or continued session validity. This could=
    impact the security of systems utilizing Keycloak for identity and access = management.</td>
    <td>2026-05-19</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8922" target=3D"= _blank" rel=3D"noopener">CVE-2026-8922</a></td>

    <a href=3D"https://access.redhat.com/security/cve/CVE-2026-8922" target=3D"= _blank" rel=3D"noopener">https://access.redhat.com/security/cve/CVE-2026-89= 22</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cgi?id=3D2479586"=
    target=3D"_blank" rel=3D"noopener">RHBZ#2479586</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Build of Keycloak</td>
    <td>A flaw was found in Keycloak. An authenticated user can bypass configur=
    ed WebAuthn policies during credential registration by manipulating client-= side JavaScript. This occurs because the server-side processAction() fails =
    to validate that the newly created credential's parameters, such as public = key algorithms, match the realm's configured WebAuthn policies. This could = lead to the creation of credentials that do not adhere to administrative se= curity requirements, potentially weakening the overall security posture of = the system by allowing non-compliant authentication methods.</td> <td>2026-05-19</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8830" target=3D"= _blank" rel=3D"noopener">CVE-2026-8830</a></td>

    <a href=3D"https://access.redhat.com/security/cve/CVE-2026-8830" target=3D"= _blank" rel=3D"noopener">https://access.redhat.com/security/cve/CVE-2026-88= 30</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cgi?id=3D2479565"=
    target=3D"_blank" rel=3D"noopener">RHBZ#2479565</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.4</td>
    <td>A flaw was found in Keycloak. This access control vulnerability in Keyc= loak's OpenID Connect (OIDC) token introspection endpoint allows a confiden= tial client to bypass audience restrictions. An attacker-controlled client = with valid credentials can retrieve sensitive token claims intended for oth=
    er resource servers, compromising the confidentiality of lightweight access=
    tokens. This issue can be exploited remotely by any confidential client in=
    the realm with valid credentials.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-37979" target=3D= "_blank" rel=3D"noopener">CVE-2026-37979</a></td>

    <a href=3D"https://access.redhat.com/errata/RHSA-2026:19596" target=3D"_bla= nk" rel=3D"noopener">RHSA-2026:19596</a><br><a href=3D"https://access.redha= t.com/errata/RHSA-2026:19597" target=3D"_blank" rel=3D"noopener">RHSA-2026:= 19597</a><br><a href=3D"https://access.redhat.com/security/cve/CVE-2026-379= 79" target=3D"_blank" rel=3D"noopener">https://access.redhat.com/security/c= ve/CVE-2026-37979</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cg= i?id=3D2455328" target=3D"_blank" rel=3D"noopener">RHBZ#2455328</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.4</td>
    <td>A flaw was found in Keycloak. This authentication vulnerability allows =
    a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycl= oak's WebAuthn (Web Authentication) flow. By intercepting an execute-action=
    s email link, an attacker can register their own authenticator to a victim'=
    s account. This leads to unauthorized enrollment of a hardware-backed crede= ntial, enabling persistent account takeover.</td>
    <td>2026-05-19</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-37982" target=3D= "_blank" rel=3D"noopener">CVE-2026-37982</a></td>

    <a href=3D"https://access.redhat.com/errata/RHSA-2026:19596" target=3D"_bla= nk" rel=3D"noopener">RHSA-2026:19596</a><br><a href=3D"https://access.redha= t.com/errata/RHSA-2026:19597" target=3D"_blank" rel=3D"noopener">RHSA-2026:= 19597</a><br><a href=3D"https://access.redhat.com/security/cve/CVE-2026-379= 82" target=3D"_blank" rel=3D"noopener">https://access.redhat.com/security/c= ve/CVE-2026-37982</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cg= i?id=3D2455329" target=3D"_blank" rel=3D"noopener">RHBZ#2455329</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.4</td>
    <td>A flaw was found in Keycloak. An authenticated client could exploit an = Insecure Direct Object Reference (IDOR) vulnerability in the Authorization = Services Protection API endpoint. By knowing or obtaining a resource's uniq=
    ue identifier (UUID) belonging to another Resource Server within the same r= ealm, the client could bypass authorization checks. This allows the client =
    to perform unauthorized GET, PUT, and DELETE operations on resources, leadi=
    ng to information disclosure and potential unauthorized modification or del= etion of data.</td>
    <td>2026-05-19</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4630" target=3D"= _blank" rel=3D"noopener">CVE-2026-4630</a></td>

    <a href=3D"https://access.redhat.com/errata/RHSA-2026:19596" target=3D"_bla= nk" rel=3D"noopener">RHSA-2026:19596</a><br><a href=3D"https://access.redha= t.com/errata/RHSA-2026:19597" target=3D"_blank" rel=3D"noopener">RHSA-2026:= 19597</a><br><a href=3D"https://access.redhat.com/security/cve/CVE-2026-463=
    0" target=3D"_blank" rel=3D"noopener">https://access.redhat.com/security/cv= e/CVE-2026-4630</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cgi?= id=3D2450245" target=3D"_blank" rel=3D"noopener">RHBZ#2450245</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.4</td>
    <td>A flaw was found in Keycloak. A low-privilege administrator with the 'v= iew-clients' role can exploit this by invoking the 'evaluate-scopes' Admin = API endpoints with an arbitrary user ID (userId) parameter. This vulnerabil= ity allows for cross-role personally identifiable information (PII) leakage=
    , enabling unauthorized visibility into user identities and authorizations = across the realm. Exploitation is possible remotely via network access to t=
    he Admin API.</td>
    <td>2026-05-19</td>
    <td>4.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-37978" target=3D= "_blank" rel=3D"noopener">CVE-2026-37978</a></td>

    <a href=3D"https://access.redhat.com/errata/RHSA-2026:19596" target=3D"_bla= nk" rel=3D"noopener">RHSA-2026:19596</a><br><a href=3D"https://access.redha= t.com/errata/RHSA-2026:19597" target=3D"_blank" rel=3D"noopener">RHSA-2026:= 19597</a><br><a href=3D"https://access.redhat.com/security/cve/CVE-2026-379= 78" target=3D"_blank" rel=3D"noopener">https://access.redhat.com/security/c= ve/CVE-2026-37978</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cg= i?id=3D2455327" target=3D"_blank" rel=3D"noopener">RHBZ#2455327</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat build of Keycloak 26.4</td>
    <td>A flaw was found in Keycloak. A broken access control vulnerability in = the Account Resources user lookup endpoint allows a remote authenticated us= er, who owns at least one User-Managed Access (UMA) resource, to enumerate = and harvest personally identifiable information (PII) for all realm users. =
    By sending crafted requests with arbitrary usernames or email values, the e= ndpoint returns full profile objects for unrelated users. This leads to bro=
    ad profile-level information disclosure.</td>
    <td>2026-05-19</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-37981" target=3D= "_blank" rel=3D"noopener">CVE-2026-37981</a></td>

    <a href=3D"https://access.redhat.com/errata/RHSA-2026:19596" target=3D"_bla= nk" rel=3D"noopener">RHSA-2026:19596</a><br><a href=3D"https://access.redha= t.com/errata/RHSA-2026:19597" target=3D"_blank" rel=3D"noopener">RHSA-2026:= 19597</a><br><a href=3D"https://access.redhat.com/security/cve/CVE-2026-379= 81" target=3D"_blank" rel=3D"noopener">https://access.redhat.com/security/c= ve/CVE-2026-37981</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cg= i?id=3D2455326" target=3D"_blank" rel=3D"noopener">RHBZ#2455326</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
    <td>A flaw was found in libsolv. This heap buffer overflow vulnerability oc= curs when a victim processes a specially crafted `.solv` file containing ne= gative size values in the `repo_add_solv` function. This leads to an unders= ized memory allocation and a subsequent out-of-bounds write. An attacker co= uld exploit this to cause a denial of service (DoS).</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9149" target=3D"= _blank" rel=3D"noopener">CVE-2026-9149</a></td>

    <a href=3D"https://access.redhat.com/security/cve/CVE-2026-9149" target=3D"= _blank" rel=3D"noopener">https://access.redhat.com/security/cve/CVE-2026-91= 49</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cgi?id=3D2460380"=
    target=3D"_blank" rel=3D"noopener">RHBZ#2460380</a><br><a href=3D"https://= github.com/openSUSE/libsolv/pull/617" target=3D"_blank" rel=3D"noopener">ht= tps://github.com/openSUSE/libsolv/pull/617</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
    <td>A flaw was found in libsolv. This stack-based buffer overflow vulnerabi= lity occurs in libsolv's Debian metadata parser when processing specially c= rafted Debian repository metadata. An attacker could exploit this by provid= ing malicious SHA384 or SHA512 checksum tags, leading to memory corruption = and a denial of service (DoS) in the affected system.</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9150" target=3D"= _blank" rel=3D"noopener">CVE-2026-9150</a></td>

    <a href=3D"https://access.redhat.com/security/cve/CVE-2026-9150" target=3D"= _blank" rel=3D"noopener">https://access.redhat.com/security/cve/CVE-2026-91= 50</a><br><a href=3D"https://bugzilla.redhat.com/show_bug.cgi?id=3D2460379"=
    target=3D"_blank" rel=3D"noopener">RHBZ#2460379</a><br><a href=3D"https://= github.com/openSUSE/libsolv/pull/616" target=3D"_blank" rel=3D"noopener">ht= tps://github.com/openSUSE/libsolv/pull/616</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">registrationformbuilder--Vedrixa Forms User Re= gistration Form, Signup Form &amp; Drag &amp; Drop Form Builder</td>
    <td>The Vedrixa Forms - User Registration Form, Signup Form &amp; Drag &amp=
    ; Drop Form Builder plugin for WordPress is vulnerable to authorization byp= ass in all versions up to, and including, 1.1.1. This is due to the plugin = not properly verifying that a user is authorized to perform an action. This=
    makes it possible for authenticated attackers, with subscriber-level acces=
    s and above, to overwrite the structure of any form - adding, removing, or = altering fields - by writing attacker-controlled data to the plugin's FORMS=
    database table. The 'ajax-nonce' nonce used by this handler is injected in=
    to the public frontend via wp_localize_script(), so any authenticated user = who visits a page containing a form shortcode can obtain it without any ele= vated access.</td>
    <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8692" target=3D"= _blank" rel=3D"noopener">CVE-2026-8692</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b3b8a= 6c-1c84-4abe-ad4a-02302b04987b?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/1b3b8a6c-1c8= 4-4abe-ad4a-02302b04987b?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/vedrixa-forms-registration-builder/tags/1.1.1/admin= /class-registration-form-builder-admin.php#L866" target=3D"_blank" rel=3D"n= oopener">https://plugins.trac.wordpress.org/browser/vedrixa-forms-registrat= ion-builder/tags/1.1.1/admin/class-registration-form-builder-admin.php#L866= </a><br><a href=3D"https://plugins.trac.wordpress.org/browser/vedrixa-forms= -registration-builder/tags/1.1.1/includes/class-registration-form-builder.p= hp#L174" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.= org/browser/vedrixa-forms-registration-builder/tags/1.1.1/includes/class-re= gistration-form-builder.php#L174</a><br><a href=3D"https://plugins.trac.wor= dpress.org/browser/vedrixa-forms-registration-builder/tags/1.1.1/public/cla= ss-registration-form-builder-public.php#L121" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration= -builder/tags/1.1.1/public/class-registration-form-builder-public.php#L121<= /a><br><a href=3D"https://plugins.trac.wordpress.org/browser/vedrixa-forms-= registration-builder/tags/1.0.0/admin/class-registration-form-builder-admin= .php#L866" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpres= s.org/browser/vedrixa-forms-registration-builder/tags/1.0.0/admin/class-reg= istration-form-builder-admin.php#L866</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/vedrixa-forms-registration-builder/tags/1.0.0/inclu= des/class-registration-form-builder.php#L174" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration= -builder/tags/1.0.0/includes/class-registration-form-builder.php#L174</a><b= r><a href=3D"https://plugins.trac.wordpress.org/browser/vedrixa-forms-regis= tration-builder/tags/1.0.0/public/class-registration-form-builder-public.ph= p#L121" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.o= rg/browser/vedrixa-forms-registration-builder/tags/1.0.0/public/class-regis= tration-form-builder-public.php#L121</a><br><a href=3D"https://plugins.trac= .wordpress.org/changeset?sfp_email=3D&sfph_mail=3D&reponame=3D&old=3D354054= 3%40vedrixa-forms-registration-builder&new=3D3540543%40vedrixa-forms-regist= ration-builder&sfp_email=3D&sfph_mail=3D" target=3D"_blank" rel=3D"noopener= ">https://plugins.trac.wordpress.org/changeset?sfp_email=3D&sfph_mail=3D&re= poname=3D&old=3D3540543%40vedrixa-forms-registration-builder&new=3D3540543%= 40vedrixa-forms-registration-builder&sfp_email=3D&sfph_mail</a><br>=C2=A0</=

    </tr>

    <td class=3D"vendor-product">Revolution Slider--Slider Revolution</td>
    <td>The Slider Revolution plugin for WordPress is vulnerable to Sensitive I= nformation Exposure in versions up to, and including, 7.0.9 via the 'get_st= ream_data()' function. This makes it possible for unauthenticated attackers=
    to extract sensitive data including published password-protected post, pag=
    e, and product content.</td>
    <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6728" target=3D"= _blank" rel=3D"noopener">CVE-2026-6728</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/3cd7be= 2c-9ba9-4d25-8907-610898df5834?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/3cd7be2c-9ba= 9-4d25-8907-610898df5834?source=3Dcve</a><br><a href=3D"https://www.sliderr= evolution.com/changelog/" target=3D"_blank" rel=3D"noopener">https://www.sl= iderrevolution.com/changelog/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">RsyncProject--rsync</td>
    <td>Rsync version=C2=A03.4.2 and prior contain symlink race condition vulne= rabilities in path-based system calls including chmod, lchown, utimes, rena= me, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local = attackers to redirect operations to files outside the exported rsync module=
    . Attackers with local filesystem access can exploit the timing window betw= een path resolution and syscall execution by swapping symlinks to apply sen= der-supplied permissions, ownership, timestamps, or filenames to arbitrary = files outside the intended module boundary on rsync daemons configured with=
    'use chroot =3D no'.</td>
    <td>2026-05-20</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43619" target=3D= "_blank" rel=3D"noopener">CVE-2026-43619</a></td>

    <a href=3D"https://github.com/RsyncProject/rsync/security/advisories/GHSA-4= h9m-w5ff-j735" target=3D"_blank" rel=3D"noopener">https://github.com/RsyncP= roject/rsync/security/advisories/GHSA-4h9m-w5ff-j735</a><br><a href=3D"http= s://github.com/RsyncProject/rsync/releases/tag/v3.4.3" target=3D"_blank" re= l=3D"noopener">https://github.com/RsyncProject/rsync/releases/tag/v3.4.3</a= ><br><a href=3D"https://www.vulncheck.com/advisories/rsync-symlink-race-con= dition-via-path-based-syscalls" target=3D"_blank" rel=3D"noopener">https://= www.vulncheck.com/advisories/rsync-symlink-race-condition-via-path-based-sy= scalls</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">RsyncProject--rsync</td>
    <td>Rsync version=C2=A03.4.2 and prior contain a receiver-side out-of-bound=
    s array read vulnerability in recv_files() in receiver.c that allows a mali= cious rsync server to crash the rsync client process. Attackers can exploit=
    the vulnerability by setting CF_INC_RECURSE in compatibility flags and sen= ding a specially crafted file list where the first sorted entry is not the = leading dot directory, followed by a transfer record with ndx=3D0 and an if= lag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before=
    the allocated pointer array and dereference an invalid pointer at an unmap= ped address, resulting in a deterministic SIGSEGV crash of the rsync client= .</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43620" target=3D= "_blank" rel=3D"noopener">CVE-2026-43620</a></td>

    <a href=3D"https://github.com/RsyncProject/rsync/security/advisories/GHSA-2= 8pw-r563-rxvm" target=3D"_blank" rel=3D"noopener">https://github.com/RsyncP= roject/rsync/security/advisories/GHSA-28pw-r563-rxvm</a><br><a href=3D"http= s://github.com/RsyncProject/rsync/releases/tag/v3.4.3" target=3D"_blank" re= l=3D"noopener">https://github.com/RsyncProject/rsync/releases/tag/v3.4.3</a= ><br><a href=3D"https://www.vulncheck.com/advisories/rsync-out-of-bounds-ar= ray-read-via-recv-files" target=3D"_blank" rel=3D"noopener">https://www.vul= ncheck.com/advisories/rsync-out-of-bounds-array-read-via-recv-files</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">RsyncProject--rsync</td>
    <td>Rsync version=C2=A03.4.2 and prior contain an authorization bypass vuln= erability in the rsync daemon's hostname-based access control list enforcem= ent when configured with chroot. Attackers can bypass hostname-based deny r= ules by controlling the PTR record for their source IP address, allowing co= nnections from hostnames that administrators intended to deny when reverse = DNS resolution fails and defaults to UNKNOWN.</td>
    <td>2026-05-20</td>
    <td>4.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43617" target=3D= "_blank" rel=3D"noopener">CVE-2026-43617</a></td>

    <a href=3D"https://github.com/RsyncProject/rsync/security/advisories/GHSA-r= jfm-3w2m-jf4f" target=3D"_blank" rel=3D"noopener">https://github.com/RsyncP= roject/rsync/security/advisories/GHSA-rjfm-3w2m-jf4f</a><br><a href=3D"http= s://github.com/RsyncProject/rsync/releases/tag/v3.4.3" target=3D"_blank" re= l=3D"noopener">https://github.com/RsyncProject/rsync/releases/tag/v3.4.3</a= ><br><a href=3D"https://www.vulncheck.com/advisories/rsync-authorization-by= pass-via-hostname-resolution" target=3D"_blank" rel=3D"noopener">https://ww= w.vulncheck.com/advisories/rsync-authorization-bypass-via-hostname-resoluti= on</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td> <td>Uncontrolled Recursion vulnerability in Samsung Open Source Escargot al= lows Oversized Serialized Data Payloads. This issue affects Escargot: 59034= 5cc6258317c5da850d846ce6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47309" target=3D= "_blank" rel=3D"noopener">CVE-2026-47309</a></td>

    <a href=3D"https://github.com/Samsung/escargot/pull/1565" target=3D"_blank"=
    rel=3D"noopener">https://github.com/Samsung/escargot/pull/1565</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td>
    <td>Release of invalid pointer or reference vulnerability in Samsung Open S= ource Escargot allows Buffer Manipulation. This issue affects Escargot: 590= 345cc6258317c5da850d846ce6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47312" target=3D= "_blank" rel=3D"noopener">CVE-2026-47312</a></td>

    <a href=3D"https://github.com/Samsung/escargot/pull/1565" target=3D"_blank"=
    rel=3D"noopener">https://github.com/Samsung/escargot/pull/1565</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td>
    <td>Memory allocation with excessive size value vulnerability in Samsung Op=
    en Source Escargot allows Excessive Allocation. This issue affects Escargot=
    : 590345cc6258317c5da850d846ce6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47313" target=3D= "_blank" rel=3D"noopener">CVE-2026-47313</a></td>

    <a href=3D"https://github.com/Samsung/escargot/pull/1565" target=3D"_blank"=
    rel=3D"noopener">https://github.com/Samsung/escargot/pull/1565</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td>
    <td>Improper Check for Unusual or Exceptional Conditions vulnerability in S= amsung Open Source Escargot allows Input Data Manipulation. This issue affe= cts Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.</td> <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47315" target=3D= "_blank" rel=3D"noopener">CVE-2026-47315</a></td>

    <a href=3D"https://github.com/Samsung/escargot/pull/1565" target=3D"_blank"=
    rel=3D"noopener">https://github.com/Samsung/escargot/pull/1565</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td>
    <td>Improper Check or Handling of Exceptional Conditions vulnerability in S= amsung Open Source Escargot allows Input Data Manipulation. This issue affe= cts Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.</td> <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47316" target=3D= "_blank" rel=3D"noopener">CVE-2026-47316</a></td>

    <a href=3D"https://github.com/Samsung/escargot/pull/1565" target=3D"_blank"=
    rel=3D"noopener">https://github.com/Samsung/escargot/pull/1565</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Escargot</td> <td>Uncontrolled Recursion vulnerability in Samsung Open Source Escargot al= lows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da= 850d846ce6baaf2afc2d3.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47317" target=3D= "_blank" rel=3D"noopener">CVE-2026-47317</a></td>

    <a href=3D"https://github.com/Samsung/escargot/pull/1565" target=3D"_blank"=
    rel=3D"noopener">https://github.com/Samsung/escargot/pull/1565</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Walrus</td>
    <td>NULL pointer dereference vulnerability in Samsung Open Source Walrus al= lows an attacker to cause a denial of service via a crafted WebAssembly mod= ule containing deeply nested instructions. This issue affects Walrus: f339b= 8ee4ea701772e8ae640b3d1b12ac02b1ae9.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47307" target=3D= "_blank" rel=3D"noopener">CVE-2026-47307</a></td>

    <a href=3D"https://github.com/Samsung/walrus/pull/409" target=3D"_blank" re= l=3D"noopener">https://github.com/Samsung/walrus/pull/409</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Samsung Open Source--Walrus</td>
    <td>NULL pointer dereference vulnerability in Samsung Open Source Walrus al= lows Pointer Manipulation. This issue affects Walrus: f339b8ee4ea701772e8ae= 640b3d1b12ac02b1ae9.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47308" target=3D= "_blank" rel=3D"noopener">CVE-2026-47308</a></td>

    <a href=3D"https://github.com/Samsung/walrus/pull/409" target=3D"_blank" re= l=3D"noopener">https://github.com/Samsung/walrus/pull/409</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">shapedplugin--Location Weather WordPress Weath=
    er Forecast, AQI, Temperature and Weather Widget</td>
    <td>The Location Weather plugin for WordPress is vulnerable to unauthorized=
    modification of data due to missing capability checks on the `splw_update_= block_options()` and `lwp_clean_weather_transients()` functions in all vers= ions up to, and including, 3.0.2. This makes it possible for authenticated = attackers, with Contributor-level access and above, to disable all weather = blocks and purge all weather cache transients. The nonce required for these=
    actions is exposed to all authenticated users via `wp_localize_script()` o=
    n the `init` hook.</td>
    <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7249" target=3D"= _blank" rel=3D"noopener">CVE-2026-7249</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/d47201= 1d-1623-4791-9d56-715d90fe0469?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/d472011d-162= 3-4791-9d56-715d90fe0469?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/location-weather/tags/3.0.2/includes/Admin/AdminDas= hboard/Splw_Blocks_Page_Wrapper.php#L256" target=3D"_blank" rel=3D"noopener= ">https://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.2/in= cludes/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L256</a><br><a hre= f=3D"https://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.2= /includes/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L331" target=3D= "_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/locati= on-weather/tags/3.0.2/includes/Admin/AdminDashboard/Splw_Blocks_Page_Wrappe= r.php#L331</a><br><a href=3D"https://wordpress.org/plugins/location-weather=
    /" target=3D"_blank" rel=3D"noopener">https://wordpress.org/plugins/locatio= n-weather/</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/loc= ation-weather/tags/3.0.3/includes/Admin/AdminDashboard/Splw_Blocks_Page_Wra= pper.php#L256" target=3D"_blank" rel=3D"noopener">https://plugins.trac.word= press.org/browser/location-weather/tags/3.0.3/includes/Admin/AdminDashboard= /Splw_Blocks_Page_Wrapper.php#L256</a><br><a href=3D"https://plugins.trac.w= ordpress.org/browser/location-weather/tags/3.0.3/includes/Admin/AdminDashbo= ard/Splw_Blocks_Page_Wrapper.php#L332" target=3D"_blank" rel=3D"noopener">h= ttps://plugins.trac.wordpress.org/browser/location-weather/tags/3.0.3/inclu= des/Admin/AdminDashboard/Splw_Blocks_Page_Wrapper.php#L332</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
    <td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. In versions 0.1.0 throu=
    gh 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_= block.py accepts a user-supplied smtp_server (string) and smtp_port (intege=
    r) as per-execution block inputs, then passes them directly to Python's smt= plib.SMTP() to open a raw TCP connection with no IP address validation. Thi=
    s completely bypasses the platform's hardened SSRF protections in backend/u= til/request.py - the validate_url_host() function and BLOCKED_IP_NETWORKS b= locklist that every other block uses to block connections to private, loopb= ack, link-local, and cloud metadata addresses. An authenticated user on a s= hared AutoGPT deployment can use this to perform non-blind internal network=
    port scanning and service fingerprinting: smtplib reads the target's TCP b= anner on connect and embeds it in the exception message, which is persisted=
    as user-visible block output via the execution framework. This issue has b= een fixed in version 0.6.52.</td>
    <td>2026-05-19</td>
    <td>5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33234" target=3D= "_blank" rel=3D"noopener">CVE-2026-33234</a></td>

    <a href=3D"https://github.com/Significant-Gravitas/AutoGPT/security/advisor= ies/GHSA-4jwj-6mg5-wrwf" target=3D"_blank" rel=3D"noopener">https://github.= com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-4jwj-6mg5-wrwf</a= ><br><a href=3D"https://github.com/Significant-Gravitas/AutoGPT/releases/ta= g/autogpt-platform-beta-v0.6.52" target=3D"_blank" rel=3D"noopener">https:/= /github.com/Significant-Gravitas/AutoGPT/releases/tag/autogpt-platform-beta= -v0.6.52</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">simonholliday--Anomify AI Anomaly Detection an=
    d Alerting</td>
    <td>The Anomify AI - Anomaly Detection and Alerting plugin for WordPress is=
    vulnerable to Stored Cross-Site Scripting via the 'anomify_api_key' parame= ter in versions up to and including 0.3.6. This is due to insufficient inpu=
    t sanitization and missing output escaping: the plugin applies sanitize_tex= t_field() to the Metric Data Key input before saving it via update_option()=
    , but sanitize_text_field() strips HTML tags without encoding double-quote = characters, and the value is then echoed directly into an HTML attribute co= ntext (value=3D"...") without esc_attr(). This makes it possible for authen= ticated attackers with administrator-level access to inject arbitrary web s= cripts that execute whenever a user visits the plugin's settings page.</td> <td>2026-05-20</td>
    <td>4.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6404" target=3D"= _blank" rel=3D"noopener">CVE-2026-6404</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/403605= 7c-0c43-4d9c-97db-4861d91a4daa?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/4036057c-0c4= 3-4d9c-97db-4861d91a4daa?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/anomify/trunk/Anomify/Wp/includes/admin_options.php= #L43" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org= /browser/anomify/trunk/Anomify/Wp/includes/admin_options.php#L43</a><br><a = href=3D"https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomi= fy/Wp/includes/admin_options.php#L43" target=3D"_blank" rel=3D"noopener">ht= tps://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/incl= udes/admin_options.php#L43</a><br><a href=3D"https://plugins.trac.wordpress= .org/browser/anomify/trunk/Anomify/Wp/Admin.php#L32" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/anomify/trunk/Anom= ify/Wp/Admin.php#L32</a><br><a href=3D"https://plugins.trac.wordpress.org/b= rowser/anomify/tags/0.3.6/Anomify/Wp/Admin.php#L32" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6= /Anomify/Wp/Admin.php#L32</a><br><a href=3D"https://plugins.trac.wordpress.= org/browser/anomify/trunk/Anomify/Config.php#L152" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify= /Config.php#L152</a><br><a href=3D"https://plugins.trac.wordpress.org/brows= er/anomify/tags/0.3.6/Anomify/Config.php#L152" target=3D"_blank" rel=3D"noo= pener">https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomif= y/Config.php#L152</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">simonholliday--Anomify AI Anomaly Detection an=
    d Alerting</td>
    <td>The Anomify AI - Anomaly Detection and Alerting plugin for WordPress is=
    vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Si=
    te Scripting (XSS) in versions up to and including 0.3.6. This is due to mi= ssing nonce verification on the settings page handler and insufficient outp=
    ut escaping in the admin_options.php template. The settings form includes n=
    o wp_nonce_field() and the handler performs no check_admin_referer() check,=
    meaning any cross-origin POST can modify plugin settings. The API key fiel=
    d is sanitized only with sanitize_text_field(), which strips HTML tags but = does not encode double-quote characters; the value is then rendered into an=
    HTML attribute via bare echo without esc_attr(), allowing a double-quote a= ttribute-escape payload to survive both sanitization and storage. This make=
    s it possible for unauthenticated attackers to inject arbitrary web scripts=
    by tricking a logged-in administrator into visiting a malicious page that = submits a forged request, storing the payload in the database and causing i=
    t to execute in the administrator's browser whenever the plugin settings pa=
    ge is visited.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6405" target=3D"= _blank" rel=3D"noopener">CVE-2026-6405</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e02c= 2d-a38a-495c-9c37-098049297be2?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e02c2d-a38= a-495c-9c37-098049297be2?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/anomify/trunk/Anomify/Wp/includes/admin_options.php= #L43" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org= /browser/anomify/trunk/Anomify/Wp/includes/admin_options.php#L43</a><br><a = href=3D"https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomi= fy/Wp/includes/admin_options.php#L43" target=3D"_blank" rel=3D"noopener">ht= tps://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/incl= udes/admin_options.php#L43</a><br><a href=3D"https://plugins.trac.wordpress= .org/browser/anomify/trunk/Anomify/Wp/Admin.php#L31" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/anomify/trunk/Anom= ify/Wp/Admin.php#L31</a><br><a href=3D"https://plugins.trac.wordpress.org/b= rowser/anomify/tags/0.3.6/Anomify/Wp/Admin.php#L31" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6= /Anomify/Wp/Admin.php#L31</a><br><a href=3D"https://plugins.trac.wordpress.= org/browser/anomify/trunk/Anomify/Config.php#L152" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify= /Config.php#L152</a><br><a href=3D"https://plugins.trac.wordpress.org/brows= er/anomify/tags/0.3.6/Anomify/Config.php#L152" target=3D"_blank" rel=3D"noo= pener">https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomif= y/Config.php#L152</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">smub--All in One SEO Powerful SEO Plugin to Bo= ost SEO Rankings &amp; Increase Traffic</td>
    <td>The All in One SEO plugin for WordPress is vulnerable to Sensitive Info= rmation Exposure via 'internalOptions' localized script data in versions up=
    to, and including, 4.9.7 due to sensitive internal option data being passe=
    d to wp_localize_script() in post editor contexts without effective masking=
    for low-privilege users. This makes it possible for authenticated attacker=
    s, with contributor-level access and above, to view configured API/OAuth to= kens and license-related values from page source.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5075" target=3D"= _blank" rel=3D"noopener">CVE-2026-5075</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8bc2= 03-c17a-4b31-8f9e-695f9e638cda?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8bc203-c17= a-4b31-8f9e-695f9e638cda?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/changeset/3532318/all-in-one-seo-pack" target=3D"_blank" re= l=3D"noopener">https://plugins.trac.wordpress.org/changeset/3532318/all-in-= one-seo-pack</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">smub--Photo Gallery, Sliders, Proofing and The= mes NextGEN Gallery</td>
    <td>The Photo Gallery, Sliders, Proofing and Themes - NextGEN Gallery plugi=
    n for WordPress is vulnerable to Insecure Direct Object Reference in versio=
    ns up to and including 4.2.0. This is due to insufficient object-level auth= orization in the image deletion REST flow where the permission callback for=
    DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permis= sions and does not enforce gallery ownership or 'NextGEN Manage others gall= ery' permissions. This makes it possible for authenticated attackers, with = Subscriber-level privileges and 'NextGEN Manage gallery' capability, to del= ete gallery images belonging to other users as well as their associated ima=
    ge files from disk when deleteImg is enabled (default).</td> <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6566" target=3D"= _blank" rel=3D"noopener">CVE-2026-6566</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/439809= ad-21ea-4a0b-b1fd-5de9f8f5ee7a?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/439809ad-21e= a-4a0b-b1fd-5de9f8f5ee7a?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/changeset/3533432/nextgen-gallery" target=3D"_blank" rel=3D= "noopener">https://plugins.trac.wordpress.org/changeset/3533432/nextgen-gal= lery</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">smub--Slider by Soliloquy Responsive Image Sli= der for WordPress</td>
    <td>The Slider by Soliloquy - Responsive Image Slider for WordPress plugin = for WordPress is vulnerable to Sensitive Information Exposure in all versio=
    ns up to, and including, 2.8.1 via the map_meta_cap. This makes it possible=
    for authenticated attackers, with subscriber-level access and above, to ex= tract draft slider metadata including unpublished media URLs, captions, and=
    slider configuration authored by administrators or editors.</td> <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7636" target=3D"= _blank" rel=3D"noopener">CVE-2026-7636</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/54115a= 9a-dadd-4f18-a139-02ec89f0a571?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/54115a9a-dad= d-4f18-a139-02ec89f0a571?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/soliloquy-lite/trunk/includes/global/posttype.php#L= 90" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/b= rowser/soliloquy-lite/trunk/includes/global/posttype.php#L90</a><br><a href= =3D"https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/include= s/global/posttype.php#L177" target=3D"_blank" rel=3D"noopener">https://plug= ins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/global/posttyp= e.php#L177</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/sol= iloquy-lite/tags/2.8.1/includes/global/posttype.php#L177" target=3D"_blank"=
    rel=3D"noopener">https://plugins.trac.wordpress.org/browser/soliloquy-lite= /tags/2.8.1/includes/global/posttype.php#L177</a><br><a href=3D"https://plu= gins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/global/postty= pe.php#L125" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpr= ess.org/browser/soliloquy-lite/trunk/includes/global/posttype.php#L125</a><= br><a href=3D"https://plugins.trac.wordpress.org/browser/soliloquy-lite/tag= s/2.8.1/includes/global/posttype.php#L125" target=3D"_blank" rel=3D"noopene= r">https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/inc= ludes/global/posttype.php#L125</a><br><a href=3D"https://plugins.trac.wordp= ress.org/browser/soliloquy-lite/tags/2.8.1/includes/global/posttype.php#L90=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/bro= wser/soliloquy-lite/tags/2.8.1/includes/global/posttype.php#L90</a><br><a h= ref=3D"https://plugins.trac.wordpress.org/changeset/3538404/soliloquy-lite/= trunk/includes/global/posttype.php?old=3D3395148&old_path=3Dsoliloquy-lite%= 2Ftrunk%2Fincludes%2Fglobal%2Fposttype.php" target=3D"_blank" rel=3D"noopen= er">https://plugins.trac.wordpress.org/changeset/3538404/soliloquy-lite/tru= nk/includes/global/posttype.php?old=3D3395148&old_path=3Dsoliloquy-lite%2Ft= runk%2Fincludes%2Fglobal%2Fposttype.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">SourceCodester--Hospitals Patient Records Mana= gement System</td>
    <td>A security flaw has been discovered in SourceCodester Hospitals Patient=
    Records Management System 1.0. Impacted is an unknown function of the file=
    /admin/patients/view_history.php. The manipulation of the argument ID resu= lts in sql injection. The attack may be launched remotely. The exploit has = been released to the public and may be used for attacks.</td> <td>2026-05-23</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9342" target=3D"= _blank" rel=3D"noopener">CVE-2026-9342</a></td>

    <a href=3D"https://vuldb.com/vuln/365305" target=3D"_blank" rel=3D"noopener= ">VDB-365305 | SourceCodester Hospitals Patient Records Management System v= iew_history.php sql injection</a><br><a href=3D"https://vuldb.com/vuln/3653= 05/cti" target=3D"_blank" rel=3D"noopener">VDB-365305 | CTI Indicators (IOB=
    , IOC, TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/812834" target= =3D"_blank" rel=3D"noopener">Submit #812834 | sourcecodester Hospital's Pat= ient Records Management System V1.0 SQL injection</a><br><a href=3D"https:/= /github.com/july-skyload/exp/issues/1" target=3D"_blank" rel=3D"noopener">h= ttps://github.com/july-skyload/exp/issues/1</a><br><a href=3D"https://www.s= ourcecodester.com/" target=3D"_blank" rel=3D"noopener">https://www.sourceco= dester.com/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Splunk--Splunk AI Toolkit</td>
    <td>In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that d= oes not hold the 'admin' or 'power' roles could access confidential data th=
    at was restricted through `srchFilter` configurations on custom roles.&lt;b= r&gt;&lt;br&gt;The app contains an `authorize.conf` configuration file with=
    a `srchFilter` entry that modifies the built-in 'user' role. Because the S= plunk platform combines inherited search filters with the `OR` SPL operator=
    , the injected filter overrides more restrictive filters on child roles.</t=

    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20238" target=3D= "_blank" rel=3D"noopener">CVE-2026-20238</a></td>

    <a href=3D"https://advisory.splunk.com/advisories/SVD-2026-0502" target=3D"= _blank" rel=3D"noopener">https://advisory.splunk.com/advisories/SVD-2026-05= 02</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">steipete--summarize</td>
    <td>Summarize prior to 0.15.1 contains a missing authorization vulnerabilit=
    y in the content script window.postMessage bridge that allows malicious pag=
    es to perform unauthorized operations on automation artifacts. Attackers ca=
    n simulate runtime messages with spoofed sender identifiers to list, read, = create, overwrite, or delete automation artifacts scoped to the affected ta=
    b without proper authorization checks.</td>
    <td>2026-05-18</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45243" target=3D= "_blank" rel=3D"noopener">CVE-2026-45243</a></td>

    <a href=3D"https://github.com/steipete/summarize/releases/tag/v0.15.2" targ= et=3D"_blank" rel=3D"noopener">https://github.com/steipete/summarize/releas= es/tag/v0.15.2</a><br><a href=3D"https://github.com/steipete/summarize/pull= /222" target=3D"_blank" rel=3D"noopener">https://github.com/steipete/summar= ize/pull/222</a><br><a href=3D"https://github.com/steipete/summarize/commit= /357544063af535bd574752622f9eb94be33ee5fd" target=3D"_blank" rel=3D"noopene= r">https://github.com/steipete/summarize/commit/357544063af535bd574752622f9= eb94be33ee5fd</a><br><a href=3D"https://www.vulncheck.com/advisories/summar= ize-browser-extension-missing-authorization-via-content-script" target=3D"_= blank" rel=3D"noopener">https://www.vulncheck.com/advisories/summarize-brow= ser-extension-missing-authorization-via-content-script</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">steipete--summarize</td>
    <td>Summarize prior to 0.15.1 contains a missing authorization vulnerabilit=
    y that allows attackers to execute browser automation actions without per-c= all user approval when the extension automation feature is enabled. Attacke=
    rs can influence the agent through malicious page or summary content to inv= oke enabled extension automation tools such as navigation or debugger-backe=
    d actions, bypassing the final user approval step when a user interacts wit=
    h attacker-controlled content.</td>
    <td>2026-05-18</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45244" target=3D= "_blank" rel=3D"noopener">CVE-2026-45244</a></td>

    <a href=3D"https://github.com/steipete/summarize/releases/tag/v0.15.2" targ= et=3D"_blank" rel=3D"noopener">https://github.com/steipete/summarize/releas= es/tag/v0.15.2</a><br><a href=3D"https://github.com/steipete/summarize/pull= /219" target=3D"_blank" rel=3D"noopener">https://github.com/steipete/summar= ize/pull/219</a><br><a href=3D"https://github.com/steipete/summarize/commit= /e64fe3ecd1bb4fdc181dcfa88c96b9e1914ced0e" target=3D"_blank" rel=3D"noopene= r">https://github.com/steipete/summarize/commit/e64fe3ecd1bb4fdc181dcfa88c9= 6b9e1914ced0e</a><br><a href=3D"https://www.vulncheck.com/advisories/summar= ize-unapproved-browser-automation-execution" target=3D"_blank" rel=3D"noope= ner">https://www.vulncheck.com/advisories/summarize-unapproved-browser-auto= mation-execution</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">steipete--summarize</td>
    <td>Summarize prior to 0.15.1 contains an insecure file permission vulnerab= ility in the refresh-free configuration rewrite path that allows local user=
    s to read sensitive credentials by exploiting default filesystem permission=
    s. When the refresh-free path rewrites the configuration file, it creates t=
    he replacement with default process umask permissions instead of preserving=
    the original file permissions, exposing the config file containing API key=
    s and provider credentials to other local users on shared Unix-like systems= .</td>
    <td>2026-05-18</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45246" target=3D= "_blank" rel=3D"noopener">CVE-2026-45246</a></td>

    <a href=3D"https://github.com/steipete/summarize/releases/tag/v0.15.2" targ= et=3D"_blank" rel=3D"noopener">https://github.com/steipete/summarize/releas= es/tag/v0.15.2</a><br><a href=3D"https://github.com/steipete/summarize/pull= /217" target=3D"_blank" rel=3D"noopener">https://github.com/steipete/summar= ize/pull/217</a><br><a href=3D"https://github.com/steipete/summarize/commit= /9e990193650a23dab73f37d5e1964d574a44098b" target=3D"_blank" rel=3D"noopene= r">https://github.com/steipete/summarize/commit/9e990193650a23dab73f37d5e19= 64d574a44098b</a><br><a href=3D"https://www.vulncheck.com/advisories/summar= ize-insecure-file-permissions-information-disclosure" target=3D"_blank" rel= =3D"noopener">https://www.vulncheck.com/advisories/summarize-insecure-file-= permissions-information-disclosure</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">storybookjs--telejson</td>
    <td>TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulne= rability in the parse() function that allows attackers to execute arbitrary=
    JavaScript by delivering a crafted JSON payload containing a malicious _co= nstructor-name_ property value. The custom reviver passes the constructor n= ame directly to new Function() without sanitization when recreating object = prototypes, enabling attackers to inject arbitrary JavaScript through vecto=
    rs such as postMessage in cross-frame communication contexts to achieve scr= ipt execution within the application.</td>
    <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47099" target=3D= "_blank" rel=3D"noopener">CVE-2026-47099</a></td>

    <a href=3D"https://github.com/storybookjs/telejson/security/advisories/GHSA= -ccgf-5rwj-j3hv" target=3D"_blank" rel=3D"noopener">https://github.com/stor= ybookjs/telejson/security/advisories/GHSA-ccgf-5rwj-j3hv</a><br><a href=3D"= https://github.com/Niccolo10/Security-Advisories/blob/main/CVE-2026-47099/c= ve-2026-47099.md" target=3D"_blank" rel=3D"noopener">https://github.com/Nic= colo10/Security-Advisories/blob/main/CVE-2026-47099/cve-2026-47099.md</a><b= r><a href=3D"https://www.vulncheck.com/advisories/telejson-dom-based-xss-vi= a-parse-function" target=3D"_blank" rel=3D"noopener">https://www.vulncheck.= com/advisories/telejson-dom-based-xss-via-parse-function</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. In versions=
    1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_c= hunk=3D0 in the stsc box causes an unsigned integer underflow in the Chunk = constructor (m_last_sample =3D 0 + 0 - 1 =3D UINT32_MAX), mapping all sampl=
    es to an empty chunk and resulting in a denial of service. When any sample =
    is accessed, the library reads from index 0 of an empty std::vector, causin=
    g a guaranteed SEGV (null-page read). The file parses successfully without = producing an error; the crash occurs on the first frame access. This issue = has been fixed in version 1.22.0.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32738" target=3D= "_blank" rel=3D"noopener">CVE-2026-32738</a></td>

    <a href=3D"https://github.com/strukturag/libheif/security/advisories/GHSA-7= f2h-cmpf-v9ww" target=3D"_blank" rel=3D"noopener">https://github.com/strukt= urag/libheif/security/advisories/GHSA-7f2h-cmpf-v9ww</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. In versions=
    1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite=
    loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely w= ith zero progress, leading to DoS. The loop has no iteration limit or timeo=
    ut and is triggered during file open (parsing) - before any user interactio=
    n or image decoding. The process stays alive (no crash, no error logged), m= aking it invisible to crash-based monitoring. This issue has been fixed in = version 1.22.0.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32739" target=3D= "_blank" rel=3D"noopener">CVE-2026-32739</a></td>

    <a href=3D"https://github.com/strukturag/libheif/security/advisories/GHSA-j= 9g7-q9hv-gq8c" target=3D"_blank" rel=3D"noopener">https://github.com/strukt= urag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c</a><br><a href=3D"http= s://github.com/strukturag/libheif/releases/tag/v1.22.0" target=3D"_blank" r= el=3D"noopener">https://github.com/strukturag/libheif/releases/tag/v1.22.0<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. In versions=
    1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=3Df= alse (the default), a corrupted tile silently fails to decode and the libra=
    ry returns heif_error_Ok with no indication of failure, leading to an unini= tialized heap memory information leak. The canvas is allocated via create_c= lone_image_at_new_size() =C3=A2=E2=80=A0=E2=80=99 plane.alloc() =C3=A2=E2= =80=A0=E2=80=99 new (std::nothrow) uint8_t[allocation_size] which does not = zero the memory; only the alpha plane is explicitly initialized via fill_pl= ane(), so the Y, Cb, and Cr planes contain whatever was previously at that = heap address. The failed tile's region of the canvas is never written. It r= etains uninitialized heap data that is delivered to the caller as decoded p= ixel values (4,096 bytes per Y/Cb/Cr plane =3D 12,288+ bytes total). Any ap= plication using libheif to decode grid-based HEIF/AVIF files with default s= ettings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of=
    heap memory to appear as pixel values in the decoded image, and the callin=
    g application receives heif_error_Ok, so it has no indication the output co= ntains heap garbage. In server-side image processing, an uploaded crafted H= EIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social m= edia) can leak cross-user data such as auth tokens, database results, and o= ther users' image data. This issue has been fixed in version 1.22.0.</td> <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32814" target=3D= "_blank" rel=3D"noopener">CVE-2026-32814</a></td>

    <a href=3D"https://github.com/strukturag/libheif/security/advisories/GHSA-4= m8r-34pg-rvwc" target=3D"_blank" rel=3D"noopener">https://github.com/strukt= urag/libheif/security/advisories/GHSA-4m8r-34pg-rvwc</a><br><a href=3D"http= s://github.com/strukturag/libheif/releases/tag/v1.22.0" target=3D"_blank" r= el=3D"noopener">https://github.com/strukturag/libheif/releases/tag/v1.22.0<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. In versions=
    1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bou= nds read in core sequence parsing logic, causing DoS. A malformed file can = have stco.entry_count =3D=3D 0 (creating no chunks) while still passing val= idation because saio.entry_count =3D=3D 0 matches, but with saiz.sample_cou=
    nt &gt; 0 the SampleAuxInfoReader constructor still enters its loop. This l= eads to an out-of-bounds dereference on the empty chunks[0] in chunked mode= .</td>
    <td>2026-05-22</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41069" target=3D= "_blank" rel=3D"noopener">CVE-2026-41069</a></td>

    <a href=3D"https://github.com/strukturag/libheif/security/advisories/GHSA-p= 82x-fpmv-576r" target=3D"_blank" rel=3D"noopener">https://github.com/strukt= urag/libheif/security/advisories/GHSA-p82x-fpmv-576r</a><br><a href=3D"http= s://github.com/strukturag/libheif/releases/tag/v1.22.0" target=3D"_blank" r= el=3D"noopener">https://github.com/strukturag/libheif/releases/tag/v1.22.0<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">submone--Amazon Scraper</td>
    <td>The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Req= uest Forgery in all versions up to, and including, 1.1. This is due to miss= ing or incorrect nonce validation on a function. This makes it possible for=
    unauthenticated attackers to update settings and inject malicious web scri= pts via a forged request granted they can trick a site administrator into p= erforming an action such as clicking on a link.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8419" target=3D"= _blank" rel=3D"noopener">CVE-2026-8419</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/c956e4= c5-bf7e-4ec4-b795-74d477a61694?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/c956e4c5-bf7= e-4ec4-b795-74d477a61694?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/amazon-scraper/trunk/amazon-admin.php#L49" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/ama= zon-scraper/trunk/amazon-admin.php#L49</a><br><a href=3D"https://plugins.tr= ac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-admin.php#L49" targ= et=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/a= mazon-scraper/tags/1.1/amazon-admin.php#L49</a><br><a href=3D"https://plugi= ns.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admin.php#L13" ta= rget=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser= /amazon-scraper/trunk/amazon-admin.php#L13</a><br><a href=3D"https://plugin= s.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-admin.php#L13" = target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brows= er/amazon-scraper/tags/1.1/amazon-admin.php#L13</a><br><a href=3D"https://p= lugins.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admin.php#L26=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/bro= wser/amazon-scraper/trunk/amazon-admin.php#L26</a><br><a href=3D"https://pl= ugins.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-admin.php#L= 26" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/b= rowser/amazon-scraper/tags/1.1/amazon-admin.php#L26</a><br><a href=3D"https= ://plugins.trac.wordpress.org/browser/amazon-scraper/trunk/amazon-admin.php= #L45" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org= /browser/amazon-scraper/trunk/amazon-admin.php#L45</a><br><a href=3D"https:= //plugins.trac.wordpress.org/browser/amazon-scraper/tags/1.1/amazon-admin.p= hp#L45" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.o= rg/browser/amazon-scraper/tags/1.1/amazon-admin.php#L45</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">svil4ok--Bottom Bar</td>
    <td>The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request=
    Forgery in all versions up to and including 0.1.7. This is due to missing = nonce verification on the plugin's settings update forms handled in bottom-= bar-admin.php. None of the three settings forms (main settings, sharing ser= vices, restore defaults) include a wp_nonce_field(), and the server-side pr= ocessing code never calls check_admin_referer() or any equivalent nonce val= idation before processing POST data and calling update_option(). This makes=
    it possible for unauthenticated attackers to trick a logged-in administrat=
    or into submitting a crafted request that updates plugin configuration opti= ons, such as changing the language, maximum post counts, or enabled sharing=
    services.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6401" target=3D"= _blank" rel=3D"noopener">CVE-2026-6401</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/db0715= ed-a06e-4a68-b9c3-408887cae113?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/db0715ed-a06= e-4a68-b9c3-408887cae113?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/bottom-bar/trunk/bottom-bar-admin.php#L16" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/bot= tom-bar/trunk/bottom-bar-admin.php#L16</a><br><a href=3D"https://plugins.tr= ac.wordpress.org/browser/bottom-bar/tags/0.1.7/bottom-bar-admin.php#L16" ta= rget=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser= /bottom-bar/tags/0.1.7/bottom-bar-admin.php#L16</a><br><a href=3D"https://p= lugins.trac.wordpress.org/browser/bottom-bar/trunk/bottom-bar-admin.php#L59=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/bro= wser/bottom-bar/trunk/bottom-bar-admin.php#L59</a><br><a href=3D"https://pl= ugins.trac.wordpress.org/browser/bottom-bar/tags/0.1.7/bottom-bar-admin.php= #L59" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org= /browser/bottom-bar/tags/0.1.7/bottom-bar-admin.php#L59</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">syslink software AG--Avantra</td>
    <td>Use of default password vulnerability in syslink software AG Avantra on=
    Linux, Windows allows Try Common or Default Usernames and Passwords. This = issue affects Avantra: before 25.3.0.</td>
    <td>2026-05-22</td>
    <td>5.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8672" target=3D"= _blank" rel=3D"noopener">CVE-2026-8672</a></td>

    <a href=3D"https://support.avantra.com/hc/en-us/articles/5535551609759" tar= get=3D"_blank" rel=3D"noopener">https://support.avantra.com/hc/en-us/articl= es/5535551609759</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">syslink software AG--Avantra</td>
    <td>Unprotected transport of credentials vulnerability in syslink software =
    AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Av= antra: before 25.3.0.</td>
    <td>2026-05-22</td>
    <td>5.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8673" target=3D"= _blank" rel=3D"noopener">CVE-2026-8673</a></td>

    <a href=3D"https://support.avantra.com/hc/en-us/articles/5535621927071" tar= get=3D"_blank" rel=3D"noopener">https://support.avantra.com/hc/en-us/articl= es/5535621927071</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Talend--Talend Administration Center</td>
    <td>A stored cross-site scripting vulnerability has been found in the Talen=
    d Administration Center. An attacker with permission to manage servers can = store a XSS payload that can be triggered by a different user.</td> <td>2026-05-20</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9056" target=3D"= _blank" rel=3D"noopener">CVE-2026-9056</a></td>

    <a href=3D"https://community.qlik.com/t5/Official-Support-Articles/Security= -fix-for-Qlik-Talend-Administration-Center-cross-site/ta-p/2548522" target= =3D"_blank" rel=3D"noopener">https://community.qlik.com/t5/Official-Support= -Articles/Security-fix-for-Qlik-Talend-Administration-Center-cross-site/ta-= p/2548522</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TeamViewer--DEX (On-premises)</td>
    <td>A broken access control vulnerability exists in the TeamViewer DEX Plat= form (On=C3=A2=E2=82=AC=E2=80=98Premises) prior version 9.2. Certain backen=
    d API endpoints do not correctly enforce authorization checks, allowing an = authenticated user with low privileges to perform actions and access resour= ces intended only for higher=C3=A2=E2=82=AC=E2=80=98privileged roles.=C2=A0=
    An attacker with low=C3=A2=E2=82=AC=E2=80=98privileged credentials may expl= oit this to gain unauthorized access to administrative or sensitive functio= nality.</td>
    <td>2026-05-22</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8381" target=3D"= _blank" rel=3D"noopener">CVE-2026-8381</a></td>

    <a href=3D"https://www.teamviewer.com/en/resources/trust-center/security-bu= lletins/tv-2026-1005/" target=3D"_blank" rel=3D"noopener">https://www.teamv= iewer.com/en/resources/trust-center/security-bulletins/tv-2026-1005/</a><br= >=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">techjewel--FluentCRM Email Newsletter, Automat= ion, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution</td> <td>The FluentCRM - Email Newsletter, Automation, Email Marketing, Email Ca= mpaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable=
    to Blind Server-Side Request Forgery in all versions up to, and including,=
    2.9.87 via the 'SubscribeURL' parameter. This makes it possible for unauth= enticated attackers to make web requests to arbitrary locations originating=
    from the web application and can be used to query and modify information f= rom internal services. Exploitation requires that the SES bounce handling k=
    ey ('_fc_bounce_key') has never been stored (i.e., the site is in its defau= lt/unconfigured state with respect to SES bounce handling) as visiting the = bounce configuration page auto-generates and stores a random key that cause=
    s the authentication check to evaluate correctly and reject unauthenticated=
    requests.</td>
    <td>2026-05-22</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7798" target=3D"= _blank" rel=3D"noopener">CVE-2026-7798</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c3ca2= d7-7af9-401f-bc5a-1796c6253cb0?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/5c3ca2d7-7af= 9-401f-bc5a-1796c6253cb0?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/fluent-crm/trunk/app/Hooks/Handlers/ExternalPages.p= hp#L113" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.= org/browser/fluent-crm/trunk/app/Hooks/Handlers/ExternalPages.php#L113</a><= br><a href=3D"https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.= 9.87/app/Hooks/Handlers/ExternalPages.php#L113" target=3D"_blank" rel=3D"no= opener">https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.9.87/a= pp/Hooks/Handlers/ExternalPages.php#L113</a><br><a href=3D"https://plugins.= trac.wordpress.org/browser/fluent-crm/trunk/app/Hooks/Handlers/ExternalPage= s.php#L85" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpres= s.org/browser/fluent-crm/trunk/app/Hooks/Handlers/ExternalPages.php#L85</a>= <br><a href=3D"https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2= .9.87/app/Hooks/Handlers/ExternalPages.php#L85" target=3D"_blank" rel=3D"no= opener">https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.9.87/a= pp/Hooks/Handlers/ExternalPages.php#L85</a><br><a href=3D"https://plugins.t= rac.wordpress.org/browser/fluent-crm/trunk/app/Hooks/Handlers/ExternalPages= .php#L87" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress= .org/browser/fluent-crm/trunk/app/Hooks/Handlers/ExternalPages.php#L87</a><= br><a href=3D"https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.= 9.87/app/Hooks/Handlers/ExternalPages.php#L87" target=3D"_blank" rel=3D"noo= pener">https://plugins.trac.wordpress.org/browser/fluent-crm/tags/2.9.87/ap= p/Hooks/Handlers/ExternalPages.php#L87</a><br><a href=3D"https://plugins.tr= ac.wordpress.org/changeset?sfp_email=3D&sfph_mail=3D&reponame=3D&old=3D3532= 271%40fluent-crm&new=3D3532271%40fluent-crm&sfp_email=3D&sfph_mail=3D" targ= et=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/changeset= ?sfp_email=3D&sfph_mail=3D&reponame=3D&old=3D3532271%40fluent-crm&new=3D353= 2271%40fluent-crm&sfp_email=3D&sfph_mail</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Technitium--DNS Server</td>
    <td>Technitium DNS Server aggressively tries to fetch missing RRSIG records=
    or mismatched DNSKEY records. An attacker in control of a domain can cause=
    a vulnerable system to generate excessive network traffic. Fixed in 15.0.<=

    <td>2026-05-19</td>
    <td>5.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45557" target=3D= "_blank" rel=3D"noopener">CVE-2026-45557</a></td>

    <a href=3D"https://github.com/TechnitiumSoftware/DnsServer/blo/master/CHANG= ELOG.md#version-150" target=3D"_blank" rel=3D"noopener">url</a><br><a href= =3D"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/wh= ite/2025/va-26-138-02.json" target=3D"_blank" rel=3D"noopener">url</a><br><=
    a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45557" target=3D"_bla= nk" rel=3D"noopener">url</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Tencent--WeKnora</td>
    <td>A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected=
    by this issue is the function getKnowledgeBaseForInitialization of the fil=
    e internal/handler/initialization.go of the component Config API Endpoint. = The manipulation of the argument kbId leads to authorization bypass. It is = possible to initiate the attack remotely. The exploit has been disclosed to=
    the public and may be used. The vendor was contacted early about this disc= losure but did not respond in any way.</td>
    <td>2026-05-18</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8786" target=3D"= _blank" rel=3D"noopener">CVE-2026-8786</a></td>

    <a href=3D"https://vuldb.com/vuln/364410" target=3D"_blank" rel=3D"noopener= ">VDB-364410 | Tencent WeKnora Config API Endpoint initialization.go getKno= wledgeBaseForInitialization authorization</a><br><a href=3D"https://vuldb.c= om/vuln/364410/cti" target=3D"_blank" rel=3D"noopener">VDB-364410 | CTI Ind= icators (IOB, IOC, IOA)</a><br><a href=3D"https://vuldb.com/submit/812172" = target=3D"_blank" rel=3D"noopener">Submit #812172 | Tencent WeKnora &lt;=3D=
    v0.3.6 Insecure Direct Object Reference (CWE-639)</a><br><a href=3D"https:= //gist.github.com/YLChen-007/1cdc50418f29af7ae671466425e52c7b" target=3D"_b= lank" rel=3D"noopener">https://gist.github.com/YLChen-007/1cdc50418f29af7ae= 671466425e52c7b</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">themefusion--Avada (Fusion) Builder</td>
    <td>The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored=
    Cross-Site Scripting via multiple shortcodes in all versions up to, and in= cluding, 3.15.2 due to insufficient input sanitization and output escaping.=
    This makes it possible for authenticated attackers, with Subscriber-level = access and above, to inject arbitrary web scripts in pages that will execut=
    e whenever a user (typically an administrator) accesses a page displaying d= ynamic user data (such as via the Dynamic Data feature pulling user biograp= hical information).</td>
    <td>2026-05-21</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-1543" target=3D"= _blank" rel=3D"noopener">CVE-2026-1543</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/72a6b0= 40-ed02-4561-82f2-4adb820bdf7d?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/72a6b040-ed0= 2-4561-82f2-4adb820bdf7d?source=3Dcve</a><br><a href=3D"https://themeforest= .net/item/avada-responsive-multipurpose-theme/2833226" target=3D"_blank" re= l=3D"noopener">https://themeforest.net/item/avada-responsive-multipurpose-t= heme/2833226</a><br><a href=3D"https://avada.com/documentation/avada-change= log/" target=3D"_blank" rel=3D"noopener">https://avada.com/documentation/av= ada-changelog/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Themeisle--Visualizer</td>
    <td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
    e Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This=
    issue affects Visualizer: from n/a before 4.0.0.</td>
    <td>2026-05-20</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-24573" target=3D= "_blank" rel=3D"noopener">CVE-2026-24573</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/visualizer/vuln= erability/wordpress-visualizer-plugin-4-0-0-cross-site-scripting-xss-vulner= ability?_s_id=3Dcve" target=3D"_blank" rel=3D"noopener">https://patchstack.= com/database/wordpress/plugin/visualizer/vulnerability/wordpress-visualizer= -plugin-4-0-0-cross-site-scripting-xss-vulnerability?_s_id=3Dcve</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">themeum--Kirki Freeform Page Builder, Website = Builder &amp; Customizer</td>
    <td>The Kirki - Freeform Page Builder, Website Builder &amp; Customizer plu= gin for WordPress is vulnerable to authorization bypass in all versions up = to, and including, 6.0.6. This is due to the plugin not properly verifying = that a user is authorized to perform an action. This makes it possible for = authenticated attackers, with subscriber-level access and above, to view al=
    l Kirki frontend forms and read stored visitor form submission data, includ= ing contact details, messages, and any other visitor-provided information s= ubmitted through site forms.</td>
    <td>2026-05-19</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8096" target=3D"= _blank" rel=3D"noopener">CVE-2026-8096</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a4414= b1-6a49-42f8-9927-93763d1502ce?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/1a4414b1-6a4= 9-42f8-9927-93763d1502ce?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/kirki/tags/6.0.4/includes/Ajax.php#L675" target=3D"= _blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/kirki/t= ags/6.0.4/includes/Ajax.php#L675</a><br><a href=3D"https://plugins.trac.wor= dpress.org/changeset/3535640/kirki" target=3D"_blank" rel=3D"noopener">http= s://plugins.trac.wordpress.org/changeset/3535640/kirki</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Tobias--CF7 WOW Styler</td>
    <td>Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exp= loiting Incorrectly Configured Access Control Security Levels. This issue a= ffects CF7 WOW Styler: from n/a through 1.7.6.</td>
    <td>2026-05-21</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27393" target=3D= "_blank" rel=3D"noopener">CVE-2026-27393</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/cf7-styler/vuln= erability/wordpress-cf7-wow-styler-plugin-1-7-6-broken-access-control-vulne= rability?_s_id=3Dcve" target=3D"_blank" rel=3D"noopener">https://patchstack= .com/database/wordpress/plugin/cf7-styler/vulnerability/wordpress-cf7-wow-s= tyler-plugin-1-7-6-broken-access-control-vulnerability?_s_id=3Dcve</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One</td>
    <td>A directory traversal vulnerability in the Apex One (on-premise) server=
    could allow a pre-authenticated local attacker to modify a key table on th=
    e server to inject malicious code to deploy to agents on affected installat= ions. This vulnerability is only exploitable on the on-premise version of A= pex One and a potential attacker must have access to the Apex One Server an=
    d already obtained administrative credentials to the server via some other = method to exploit this vulnerability.</td>
    <td>2026-05-21</td>
    <td>6.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34926" target=3D= "_blank" rel=3D"noopener">CVE-2026-34926</a></td>

    <a href=3D"https://success.trendmicro.com/en-US/solution/KA-0023430" target= =3D"_blank" rel=3D"noopener">https://success.trendmicro.com/en-US/solution/= KA-0023430</a><br><a href=3D"https://success.trendmicro.com/ja-JP/solution/= KA-0022974" target=3D"_blank" rel=3D"noopener">https://success.trendmicro.c= om/ja-JP/solution/KA-0022974</a><br><a href=3D"https://jvn.jp/en/vu/JVNVU90= 583059/" target=3D"_blank" rel=3D"noopener">https://jvn.jp/en/vu/JVNVU90583= 059/</a><br><a href=3D"https://www.jpcert.or.jp/english/at/2026/at260014.ht= ml" target=3D"_blank" rel=3D"noopener">https://www.jpcert.or.jp/english/at/= 2026/at260014.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TriliumNext--Trilium</td>
    <td>Trilium Notes is an open-source, cross-platform hierarchical note takin=
    g application for building large personal knowledge bases. Versions 0.102.1=
    and prior are vulnerable to Local File Inclusion, allowing an authenticate=
    d attacker to read sensitive arbitrary files from the server's filesystem. = The uploadModifiedFileToAttachment function, which is called when a POST re= quest is received to /api/attachments/{attachmentId}/upload-modified-file, = replaces the content of the attachment with the content from another file (= whose path is provided in filePath of Request body). After which the conten=
    t of the attachment can be viewed at /api/attachments/{attachmentId}/downlo= ad. This exposes sensitive system files such as SSH keys, credentials, conf= igs, and OS files, potentially leading to remote code execution and comprom= ise of co-hosted applications. This issue has been fixed in version 0.102.2= .</td>
    <td>2026-05-19</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35593" target=3D= "_blank" rel=3D"noopener">CVE-2026-35593</a></td>

    <a href=3D"https://github.com/TriliumNext/Trilium/security/advisories/GHSA-= hf4x-22rg-pjjp" target=3D"_blank" rel=3D"noopener">https://github.com/Trili= umNext/Trilium/security/advisories/GHSA-hf4x-22rg-pjjp</a><br><a href=3D"ht= tps://github.com/TriliumNext/Trilium/releases/tag/v0.102.2" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/TriliumNext/Trilium/releases/tag/v0.= 102.2</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TriliumNext--Trilium</td>
    <td>Trilium Notes is a cross-platform, hierarchical note taking application=
    focused on building large personal knowledge bases. Versions 0.102.1 and p= rior contain a critical security flaw where lack of SVG sanitization combin=
    ed with a disabled Content Security Policy (CSP) and a publicly reachable b= ackend execution API results in an unauthenticated Remote Code Execution (R= CE). The vulnerability arises from an insecure-by-design architecture: Tril= ium serves SVG attachments with the image/svg+xml MIME type without any san= itization, and it explicitly disables Helmet's Content Security Policy midd= leware, removing the primary defense against script execution in served ass= ets. Because the malicious SVG runs under the Same-Origin Policy, it can is= sue a fetch('/') to extract the csrfToken from the document body. With that=
    token, it can send a signed request to /api/script/exec to execute arbitra=
    ry Node.js code on the server. An attacker can compromise the entire server=
    instance simply by tricking an authenticated user into viewing a shared SV=
    G attachment. The issue has been fixed in version 0.102.2.</td> <td>2026-05-20</td>
    <td>6.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39311" target=3D= "_blank" rel=3D"noopener">CVE-2026-39311</a></td>

    <a href=3D"https://github.com/TriliumNext/Trilium/security/advisories/GHSA-= p837-cxw3-m964" target=3D"_blank" rel=3D"noopener">https://github.com/Trili= umNext/Trilium/security/advisories/GHSA-p837-cxw3-m964</a><br><a href=3D"ht= tps://github.com/TriliumNext/Trilium/releases/tag/v0.102.2" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/TriliumNext/Trilium/releases/tag/v0.= 102.2</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TriliumNext--Trilium</td>
    <td>Trilium Notes is a cross-platform, hierarchical note taking application=
    focused on building large personal knowledge bases. In versions 0.102.1 an=
    d prior, the Electron configuration is vulnerable to TCC Bypass via Prompt = Spoofing, allowing local attackers to trigger misleading macOS permission p= rompts by running malicious code under the identity of the trusted app. The=
    root cause is that the RunAsNode fuse allows launching the app in a specia=
    l Node.js mode using -e to execute arbitrary system commands with Trilium N= otes's permissions and identity. An attacker can leverage this through a su= bprocess to request any sensitive permissions, such as access to hardware (= camera, microphone) and TCC-protected files, causing the TCC system prompt =
    to appear as if the request came from Trilium rather than the attacker's co= de, because macOS treats the subprocess as part of the parent application. = Exploitation allows access to TCC-protected resources like the screen, came= ra, microphone, and folders such as ~/Documents and ~/Downloads, underminin=
    g macOS's security model and UI integrity through social engineering. This = issue has been fixed in version 0.102.2.</td>
    <td>2026-05-19</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39309" target=3D= "_blank" rel=3D"noopener">CVE-2026-39309</a></td>

    <a href=3D"https://github.com/TriliumNext/Trilium/security/advisories/GHSA-= 66pm-8hvq-2wwx" target=3D"_blank" rel=3D"noopener">https://github.com/Trili= umNext/Trilium/security/advisories/GHSA-66pm-8hvq-2wwx</a><br><a href=3D"ht= tps://github.com/TriliumNext/Trilium/releases/tag/v0.102.2" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/TriliumNext/Trilium/releases/tag/v0.= 102.2</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Turkiye Electricity Transmission Corporation (= TEA)--Mobile Application</td>
    <td>Improper restriction of excessive authentication attempts vulnerability=
    in Turkiye Electricity Transmission Corporation (TE=C3=84=C2=B0A=C3=85=C5= =BE) Mobile Application allows Brute Force. This issue affects Mobile Appli= cation: from 1.6.2 before 1.13.</td>
    <td>2026-05-21</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-1816" target=3D"= _blank" rel=3D"noopener">CVE-2026-1816</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 286" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0286</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Turkiye Electricity Transmission Corporation (= TEA)--Mobile Application</td>
    <td>Insufficient session expiration vulnerability in Turkiye Electricity Tr= ansmission Corporation (TE=C3=84=C2=B0A=C3=85=C5=BE) Mobile Application all= ows Session Hijacking. This issue affects Mobile Application: from 1.6.2 be= fore 1.13.</td>
    <td>2026-05-21</td>
    <td>5.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-1815" target=3D"= _blank" rel=3D"noopener">CVE-2026-1815</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 286" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0286</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">UserSpice--userSpice</td>
    <td>userSpice 4.3.24 contains a cross-site scripting vulnerability that all= ows attackers to inject malicious scripts through the X-Forwarded-For HTTP = header. Attackers can send crafted requests to the backup.php endpoint with=
    XSS payloads in the X-Forwarded-For header that execute when administrator=
    s visit the audit log page.</td>
    <td>2026-05-23</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25349" target=3D= "_blank" rel=3D"noopener">CVE-2018-25349</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44871" target=3D"_blank" rel= =3D"noopener">ExploitDB-44871</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/userspice-cross-site-scripting-via-x-forwarded-for-header" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: userSpice 4.3.24 Cross-Sit=
    e Scripting via X-Forwarded-For Header</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">vatanyazilim--VatanSMS WP SMS</td>
    <td>The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cro= ss-Site Scripting via the `page` parameter in all versions up to, and inclu= ding, 1.01. This is due to insufficient input sanitization and output escap= ing. This makes it possible for unauthenticated attackers to inject arbitra=
    ry web scripts in pages that execute if they can successfully trick an admi= nistrator into performing an action such as clicking on a link.</td> <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7462" target=3D"= _blank" rel=3D"noopener">CVE-2026-7462</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/96ef84= 59-1600-4ca0-93c6-0ee42f8adabd?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/96ef8459-160= 0-4ca0-93c6-0ee42f8adabd?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/wp-sms-vatansms-com/trunk/includes/admin/groups/gro= ups.php#L34" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpr= ess.org/browser/wp-sms-vatansms-com/trunk/includes/admin/groups/groups.php#= L34</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/wp-sms-vat= ansms-com/trunk/includes/admin/outbox/outbox.php#L5" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-co= m/trunk/includes/admin/outbox/outbox.php#L5</a><br><a href=3D"https://plugi= ns.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includes/admin/subs= cribers/subscribers.php#L128" target=3D"_blank" rel=3D"noopener">https://pl= ugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includes/admin/s= ubscribers/subscribers.php#L128</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">VillaTheme--HAPPY</td>
    <td>Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiti=
    ng Incorrectly Configured Access Control Security Levels. This issue affect=
    s HAPPY: from n/a through 1.0.10.</td>
    <td>2026-05-21</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39593" target=3D= "_blank" rel=3D"noopener">CVE-2026-39593</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/happy-helpdesk-= support-ticket-system/vulnerability/wordpress-happy-plugin-1-0-10-broken-ac= cess-control-vulnerability?_s_id=3Dcve" target=3D"_blank" rel=3D"noopener">= https://patchstack.com/database/wordpress/plugin/happy-helpdesk-support-tic= ket-system/vulnerability/wordpress-happy-plugin-1-0-10-broken-access-contro= l-vulnerability?_s_id=3Dcve</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Webmin--Webmin</td>
    <td>Webmin before 2.641 contains a stored cross-site scripting vulnerabilit=
    y in the email template description field of the System and Server Status m= odule that allows low-privileged authenticated attackers to execute arbitra=
    ry JavaScript in the browser context of administrators by injecting unsanit= ized input stored in save_tmpl.cgi and rendered unescaped in list_tmpls.cgi= .</td>
    <td>2026-05-21</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-22678" target=3D= "_blank" rel=3D"noopener">CVE-2026-22678</a></td>

    <a href=3D"https://webmin.com/changelog/webmin-2.641-released/" target=3D"_= blank" rel=3D"noopener">https://webmin.com/changelog/webmin-2.641-released/= </a><br><a href=3D"https://www.vulncheck.com/advisories/webmin-stored-xss-v= ia-system-and-server-status" target=3D"_blank" rel=3D"noopener">https://www= .vulncheck.com/advisories/webmin-stored-xss-via-system-and-server-status</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">winking--Word 2 Cash</td>
    <td>The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Reques=
    t Forgery leading to Stored Cross-Site Scripting in versions up to and incl= uding 0.9.2. This is due to the complete absence of nonce verification on t=
    he settings save handler in the w2c_admin() function, combined with missing=
    input sanitization before storage and missing output escaping when renderi=
    ng the stored value. The w2c-definitions POST parameter is saved raw via up= date_option() and later echoed without escaping inside a &lt;textarea&gt; e= lement. This makes it possible for unauthenticated attackers to forge a req= uest on behalf of a logged-in administrator, storing arbitrary JavaScript p= ayloads that execute in the WordPress admin panel whenever the settings pag=
    e is visited.</td>
    <td>2026-05-20</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6395" target=3D"= _blank" rel=3D"noopener">CVE-2026-6395</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4c7ca= 5c-38aa-4413-83eb-29185cca2a74?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/e4c7ca5c-38a= a-4413-83eb-29185cca2a74?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/word-2-cash/trunk/word2cash.php#L31" target=3D"_bla= nk" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/word-2-cash= /trunk/word2cash.php#L31</a><br><a href=3D"https://plugins.trac.wordpress.o= rg/browser/word-2-cash/tags/0.9.2/word2cash.php#L31" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/word-2-cash/tags/0= .9.2/word2cash.php#L31</a><br><a href=3D"https://plugins.trac.wordpress.org= /browser/word-2-cash/trunk/word2cash.php#L20" target=3D"_blank" rel=3D"noop= ener">https://plugins.trac.wordpress.org/browser/word-2-cash/trunk/word2cas= h.php#L20</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/word= -2-cash/tags/0.9.2/word2cash.php#L20" target=3D"_blank" rel=3D"noopener">ht= tps://plugins.trac.wordpress.org/browser/word-2-cash/tags/0.9.2/word2cash.p= hp#L20</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/word-2-= cash/trunk/word2cash.php#L18" target=3D"_blank" rel=3D"noopener">https://pl= ugins.trac.wordpress.org/browser/word-2-cash/trunk/word2cash.php#L18</a><br= ><a href=3D"https://plugins.trac.wordpress.org/browser/word-2-cash/tags/0.9= .2/word2cash.php#L18" target=3D"_blank" rel=3D"noopener">https://plugins.tr= ac.wordpress.org/browser/word-2-cash/tags/0.9.2/word2cash.php#L18</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">WP Chill--Image Photo Gallery Final Tiles Grid= </td>
    <td>Missing Authorization vulnerability in WP Chill Image Photo Gallery Fin=
    al Tiles Grid allows Exploiting Incorrectly Configured Access Control Secur= ity Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n=
    /a through 3.6.11.</td>
    <td>2026-05-20</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27424" target=3D= "_blank" rel=3D"noopener">CVE-2026-27424</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/final-tiles-gri= d-gallery-lite/vulnerability/wordpress-image-photo-gallery-final-tiles-grid= -plugin-3-6-11-broken-access-control-vulnerability?_s_id=3Dcve" target=3D"_= blank" rel=3D"noopener">https://patchstack.com/database/wordpress/plugin/fi= nal-tiles-grid-gallery-lite/vulnerability/wordpress-image-photo-gallery-fin= al-tiles-grid-plugin-3-6-11-broken-access-control-vulnerability?_s_id=3Dcve= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wpbean--WPB Floating Menu or Categories Sticky=
    Floating Side Menu &amp; Categories with Icons</td>
    <td>The WPB Floating Menu &amp; Categories for WordPress - Sticky Side Menu=
    with Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripti=
    ng via the 'Icon CSS Class' category field in all versions up to, and inclu= ding, 1.0.8 due to insufficient input sanitization and output escaping. Thi=
    s makes it possible for authenticated attackers, with Editor-level access a=
    nd above, to inject arbitrary web scripts in pages that will execute whenev=
    er a user accesses an injected page.</td>
    <td>2026-05-21</td>
    <td>4.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4811" target=3D"= _blank" rel=3D"noopener">CVE-2026-4811</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/961702= ff-60fb-41ff-99b0-a37ade051083?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/961702ff-60f= b-41ff-99b0-a37ade051083?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/wpb-floating-menu-or-categories/tags/1.0.8/admin/ca= tegory-icon.php#L41" target=3D"_blank" rel=3D"noopener">https://plugins.tra= c.wordpress.org/browser/wpb-floating-menu-or-categories/tags/1.0.8/admin/ca= tegory-icon.php#L41</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wpdive--Nexa Blocks Gutenberg Blocks, Page Bui= lder for Gutenberg Editor &amp; FSE</td>
    <td>The Nexa Blocks - Gutenberg Blocks, Page Builder for Gutenberg Editor &= amp; FSE plugin for WordPress is vulnerable to Server-Side Request Forgery = (SSRF) in versions up to and including 1.1.1. This is due to the import_dem= o() function accepting a user-supplied URL in the demo_json_file POST param= eter and passing it directly to wp_remote_get() without any URL validation =
    or restriction against internal or private network destinations. The nexa_b= locks_nonce required for the AJAX action is publicly exposed in the HTML so= urce of any frontend page where the plugin is active via wp_localize_script=
    on the enqueue_block_assets hook, effectively making the nonce available t=
    o all visitors and bypassing any intended authentication barrier. This make=
    s it possible for unauthenticated attackers to make server-side HTTP reques=
    ts to arbitrary internal or external destinations, potentially exposing int= ernal services, cloud metadata endpoints such as the AWS instance metadata = service, localhost services, and other resources not intended to be publicl=
    y accessible. A secondary SSRF vector also exists whereby image URLs extrac= ted from the attacker-controlled JSON response are subsequently fetched via=
    a second wp_remote_get() call, allowing chained exploitation through a cra= fted JSON payload.</td>
    <td>2026-05-20</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6394" target=3D"= _blank" rel=3D"noopener">CVE-2026-6394</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4bb30= 67-7953-466d-a469-8a101450f133?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/b4bb3067-795= 3-466d-a469-8a101450f133?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/nexa-blocks/trunk/inc/template/template.php#L242" t= arget=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browse= r/nexa-blocks/trunk/inc/template/template.php#L242</a><br><a href=3D"https:= //plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/template/te= mplate.php#L242" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wo= rdpress.org/browser/nexa-blocks/tags/1.1.1/inc/template/template.php#L242</= a><br><a href=3D"https://plugins.trac.wordpress.org/browser/nexa-blocks/tru= nk/inc/template/template.php#L236" target=3D"_blank" rel=3D"noopener">https= ://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/template/templa= te.php#L236</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/ne= xa-blocks/tags/1.1.1/inc/template/template.php#L236" target=3D"_blank" rel= =3D"noopener">https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1= .1.1/inc/template/template.php#L236</a><br><a href=3D"https://plugins.trac.= wordpress.org/browser/nexa-blocks/trunk/inc/classes/enqueue-assets.php#L84"=
    target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brow= ser/nexa-blocks/trunk/inc/classes/enqueue-assets.php#L84</a><br><a href=3D"= https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/class= es/enqueue-assets.php#L84" target=3D"_blank" rel=3D"noopener">https://plugi= ns.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/classes/enqueue-as= sets.php#L84</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">WPFunnels Team--Mail Mint</td>
    <td>Exposure of Sensitive System Information to an Unauthorized Control Sph= ere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sens= itive Data. This issue affects Mail Mint: from n/a through 1.19.5.</td> <td>2026-05-21</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27349" target=3D= "_blank" rel=3D"noopener">CVE-2026-27349</a></td>

    <a href=3D"https://patchstack.com/database/wordpress/plugin/mail-mint/vulne= rability/wordpress-mail-mint-plugin-1-19-5-sensitive-data-exposure-vulnerab= ility?_s_id=3Dcve" target=3D"_blank" rel=3D"noopener">https://patchstack.co= m/database/wordpress/plugin/mail-mint/vulnerability/wordpress-mail-mint-plu= gin-1-19-5-sensitive-data-exposure-vulnerability?_s_id=3Dcve</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">wpxpo--FastX</td>
    <td>The FastX theme for WordPress is vulnerable to unauthorized limited plu= gin installation and activation due to missing capability checks on the 'ul= tp_install_callback' and 'ultp_activate_callback' functions in all versions=
    up to, and including, 1.0.2. This makes it possible for authenticated atta= ckers, with Subscriber-level access and above, to install and activate the = PostX plugin.</td>
    <td>2026-05-22</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2518" target=3D"= _blank" rel=3D"noopener">CVE-2026-2518</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f5c41= 94-4f97-4f85-af90-e983ba9ce3a6?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/6f5c4194-4f9= 7-4f85-af90-e983ba9ce3a6?source=3Dcve</a><br><a href=3D"https://themes.trac= .wordpress.org/browser/fastx/1.0.2/classes/Initialization.php#L264" target= =3D"_blank" rel=3D"noopener">https://themes.trac.wordpress.org/browser/fast= x/1.0.2/classes/Initialization.php#L264</a><br><a href=3D"https://themes.tr= ac.wordpress.org/browser/fastx/1.0.2/classes/Initialization.php#L249" targe= t=3D"_blank" rel=3D"noopener">https://themes.trac.wordpress.org/browser/fas= tx/1.0.2/classes/Initialization.php#L249</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wupsales--AI Chatbot &amp; Workflow Automation=
    by AIWU</td>
    <td>The AI Chatbot &amp; Workflow Automation by AIWU plugin for WordPress i=
    s vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' heade=
    r in versions up to, and including, 1.4.14 due to insufficient input saniti= zation and output escaping. This makes it possible for unauthenticated atta= ckers to inject arbitrary web scripts in pages that will execute whenever a=
    user accesses an injected page. NOTE: Practical exploitation is constraine=
    d due to a 20-character storage limit.</td>
    <td>2026-05-20</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2955" target=3D"= _blank" rel=3D"noopener">CVE-2026-2955</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d4342= 50-aa16-4ba1-a1f8-289371176545?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/8d434250-aa1= 6-4ba1-a1f8-289371176545?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/changeset/3505998/ai-copilot-content-generator" target=3D"_= blank" rel=3D"noopener">https://plugins.trac.wordpress.org/changeset/350599= 8/ai-copilot-content-generator</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">xpro--Xpro Addons 140+ Widgets for Elementor</=

    <td>The Xpro Addons - 140+ Widgets for Elementor plugin for WordPress is vu= lnerable to unauthorized modification of data due to a missing capability c= heck on the get_content_editor function in all versions up to, and includin=
    g, 1.5.0. This makes it possible for unauthenticated attackers to create pu= blished Xpro templates.</td>
    <td>2026-05-20</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15369" target=3D= "_blank" rel=3D"noopener">CVE-2025-15369</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf49d3= fb-de14-42bc-bf51-f9adceba0d32?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/cf49d3fb-de1= 4-42bc-bf51-f9adceba0d32?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/xpro-elementor-addons/trunk?rev=3D3508547" target= =3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/xpr= o-elementor-addons/trunk?rev=3D3508547</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">yangzongzhuan--RuoYi-Vue</td>
    <td>A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impac= ted is the function FileUploadUtils.upload of the file /common/upload of th=
    e component Common Upload Endpoint. Performing a manipulation results in un= restricted upload. The attack is possible to be carried out remotely. The v= endor was contacted early about this disclosure but did not respond in any = way.</td>
    <td>2026-05-24</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9374" target=3D"= _blank" rel=3D"noopener">CVE-2026-9374</a></td>

    <a href=3D"https://vuldb.com/vuln/365338" target=3D"_blank" rel=3D"noopener= ">VDB-365338 | yangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUp= loadUtils.upload unrestricted upload</a><br><a href=3D"https://vuldb.com/vu= ln/365338/cti" target=3D"_blank" rel=3D"noopener">VDB-365338 | CTI Indicato=
    rs (IOB, IOC, TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/813252" = target=3D"_blank" rel=3D"noopener">Submit #813252 | RuoYi RuoYi-Vue 3.9.2 C= ross Site Scripting</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">yog2515--General Options</td>
    <td>The General Options plugin for WordPress is vulnerable to Stored Cross-= Site Scripting in versions up to and including 1.1.0. This is due to the us=
    e of sanitize_text_field() for output escaping in the Contact Number (ad_co= ntact_number) field - a function that strips HTML tags but does not encode = double-quote characters to their HTML entity equivalent (&amp;quot;). When = the stored value is echoed inside a double-quoted HTML attribute (value=3D"= ..."), an attacker-supplied double-quote character breaks out of the attrib= ute context. Even with WordPress's wp_magic_quotes mechanism (which prefixe=
    s quotes with a backslash), the resulting \" sequence is NOT treated as an = escaped quote by HTML parsers - the backslash is rendered as a literal char= acter and the bare double-quote still closes the attribute. This makes it p= ossible for authenticated attackers with Administrator-level access and abo=
    ve to inject arbitrary web scripts in the admin settings page that will exe= cute whenever any administrator visits the General Options settings page.</=

    <td>2026-05-20</td>
    <td>4.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6399" target=3D"= _blank" rel=3D"noopener">CVE-2026-6399</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/d29c69= bb-4feb-477e-b18f-934ece21aff6?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/d29c69bb-4fe= b-477e-b18f-934ece21aff6?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/general-options/trunk/direct-main.php" target=3D"_b= lank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/general-o= ptions/trunk/direct-main.php</a><br><a href=3D"https://plugins.trac.wordpre= ss.org/browser/general-options/tags/1.1.0/direct-main.php" target=3D"_blank=
    " rel=3D"noopener">https://plugins.trac.wordpress.org/browser/general-optio= ns/tags/1.1.0/direct-main.php</a><br><a href=3D"https://plugins.trac.wordpr= ess.org/browser/general-options/trunk/direct-action.php" target=3D"_blank" = rel=3D"noopener">https://plugins.trac.wordpress.org/browser/general-options= /trunk/direct-action.php</a><br><a href=3D"https://plugins.trac.wordpress.o= rg/browser/general-options/tags/1.1.0/direct-action.php" target=3D"_blank" = rel=3D"noopener">https://plugins.trac.wordpress.org/browser/general-options= /tags/1.1.0/direct-action.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ZTE--MU5250</td>
    <td>There is an unauthorized access vulnerability in ZTE MU5250. Due to imp= roper permission control of the Web interface, an unauthorized attacker can= =C2=A0 modify configuration through the interface.</td>
    <td>2026-05-19</td>
    <td>6.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44408" target=3D= "_blank" rel=3D"noopener">CVE-2026-44408</a></td>

    <a href=3D"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/deta= il/2657904255874650158" target=3D"_blank" rel=3D"noopener">https://support.= zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2657904255874650158</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ZTE--MU5250</td>
    <td>There is an an information disclosure vulnerability in ZTE MU5250. Due =
    to improper configuration of the access control mechanism, attackers can ob= tain information without authorization, causing the risk of information dis= closure.</td>
    <td>2026-05-22</td>
    <td>5.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44409" target=3D= "_blank" rel=3D"noopener">CVE-2026-44409</a></td>

    <a href=3D"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/deta= il/3711746568357343342" target=3D"_blank" rel=3D"noopener">https://support.= zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3711746568357343342</a><= br>=C2=A0</td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    <div id=3D"low_v">
    <h2 id=3D"low_v_title">Low Vulnerabilities</h2>
    <table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Low Vulnerabilities">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bo=
    t engine's the findResult query does not filter results by typebotId, allow= ing an authenticated user to load result data (user answers, variable value=
    s) from a different typebot by supplying a foreign resultId to the startCha=
    t endpoint. Exploitation is constrained by CUID2's cryptographically random=
    24-character IDs (making brute-force infeasible), the requirement that rem= emberUser be enabled, and the need for matching variable names in the curre=
    nt typebot. If successfully exploited, an attacker can access the original = user's previous answers, session variable values, and hasStarted flag, pote= ntially exposing PII like names, emails, and phone numbers. This issue has = been fixed in version 3.16.0.</td>
    <td>2026-05-22</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39967" target=3D= "_blank" rel=3D"noopener">CVE-2026-39967</a></td>

    <a href=3D"https://github.com/baptisteArno/typebot.io/security/advisories/G= HSA-f475-7m4x-m6mx" target=3D"_blank" rel=3D"noopener">https://github.com/b= aptisteArno/typebot.io/security/advisories/GHSA-f475-7m4x-m6mx</a><br><a hr= ef=3D"https://github.com/baptisteArno/typebot.io/commit/73162634e6bdebd37a1= a571db4062d30854e0400" target=3D"_blank" rel=3D"noopener">https://github.co= m/baptisteArno/typebot.io/commit/73162634e6bdebd37a1a571db4062d30854e0400</= a><br><a href=3D"https://github.com/baptisteArno/typebot.io/releases/tag/v3= .16.0" target=3D"_blank" rel=3D"noopener">https://github.com/baptisteArno/t= ypebot.io/releases/tag/v3.16.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Besen--BS20 EV Charging Station</td>
    <td>A vulnerability was determined in Besen BS20 EV Charging Station up to = 20260426. This impacts an unknown function of the component Bluetooth Low E= nergy Handler. Executing a manipulation can lead to weak password requireme= nts. The attack needs to be done within the local network. This attack is c= haracterized by high complexity. The exploitability is said to be difficult=
    . The original disclosure mentions, that "[t]hese vulnerabilities have been=
    reported to Besen and we have received their acknowlegement that they are = reviewing this as of April 2026."</td>
    <td>2026-05-24</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9394" target=3D"= _blank" rel=3D"noopener">CVE-2026-9394</a></td>

    <a href=3D"https://vuldb.com/vuln/365375" target=3D"_blank" rel=3D"noopener= ">VDB-365375 | Besen BS20 EV Charging Station Bluetooth Low Energy weak pas= sword</a><br><a href=3D"https://vuldb.com/vuln/365375/cti" target=3D"_blank=
    " rel=3D"noopener">VDB-365375 | CTI Indicators (IOB, IOC, TTP)</a><br><a hr= ef=3D"https://vuldb.com/submit/813569" target=3D"_blank" rel=3D"noopener">S= ubmit #813569 | Besen EV Charging Station BS20 EV Charger Weak Authenticati= on</a><br><a href=3D"https://github.com/carfeii/besen#finding-1-weak-authen= tication-mechanism-in-besen-home-ev-charging-station-via-ble" target=3D"_bl= ank" rel=3D"noopener">https://github.com/carfeii/besen#finding-1-weak-authe= ntication-mechanism-in-besen-home-ev-charging-station-via-ble</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">Besen--BS20 EV Charging Station</td>
    <td>A vulnerability was identified in Besen BS20 EV Charging Station up to = 20260426. Affected is an unknown function of the component BLE/UDP. The man= ipulation leads to insufficiently protected credentials. The attack needs t=
    o be initiated within the local network. The original disclosure mentions, = that "[t]hese vulnerabilities have been reported to Besen and we have recei= ved their acknowlegement that they are reviewing this as of April 2026."</t=

    <td>2026-05-24</td>
    <td>3.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9395" target=3D"= _blank" rel=3D"noopener">CVE-2026-9395</a></td>

    <a href=3D"https://vuldb.com/vuln/365376" target=3D"_blank" rel=3D"noopener= ">VDB-365376 | Besen BS20 EV Charging Station BLE/UDP insufficiently protec= ted credentials</a><br><a href=3D"https://vuldb.com/vuln/365376/cti" target= =3D"_blank" rel=3D"noopener">VDB-365376 | CTI Indicators (IOB, IOC, TTP)</a= ><br><a href=3D"https://vuldb.com/submit/813572" target=3D"_blank" rel=3D"n= oopener">Submit #813572 | Besen EV Charging Station BS20 EV Charger Insuffi= ciently Protected Credentials</a><br><a href=3D"https://github.com/carfeii/= besen#finding-2-cleartext-credential-exposure-via-ble-and-udp-in-besen-home= -ev-charging-station" target=3D"_blank" rel=3D"noopener">https://github.com= /carfeii/besen#finding-2-cleartext-credential-exposure-via-ble-and-udp-in-b= esen-home-ev-charging-station</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Besen--BS20 EV Charging Station</td>
    <td>A security flaw has been discovered in Besen BS20 EV Charging Station u=
    p to 20260426. Affected by this vulnerability is an unknown functionality o=
    f the component Firmware Version Check. The manipulation results in imprope=
    r restriction of rendered ui layers. The attack can be executed remotely. A=
    high complexity level is associated with this attack. The exploitation app= ears to be difficult. The original disclosure mentions, that "[t]hese vulne= rabilities have been reported to Besen and we have received their acknowleg= ement that they are reviewing this as of April 2026."</td>
    <td>2026-05-24</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9396" target=3D"= _blank" rel=3D"noopener">CVE-2026-9396</a></td>

    <a href=3D"https://vuldb.com/vuln/365377" target=3D"_blank" rel=3D"noopener= ">VDB-365377 | Besen BS20 EV Charging Station Firmware Version Check ui lay= er</a><br><a href=3D"https://vuldb.com/vuln/365377/cti" target=3D"_blank" r= el=3D"noopener">VDB-365377 | CTI Indicators (IOB, IOC)</a><br><a href=3D"ht= tps://vuldb.com/submit/813575" target=3D"_blank" rel=3D"noopener">Submit #8= 13575 | Besen EV Charging Station BS20 EV Charger Improper Verification of = Cryptographic Signature</a><br><a href=3D"https://github.com/carfeii/besen#= finding-3-firmware-version-check-manipulation-and-ui-spoofing" target=3D"_b= lank" rel=3D"noopener">https://github.com/carfeii/besen#finding-3-firmware-= version-check-manipulation-and-ui-spoofing</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Besen--BS20 EV Charging Station</td>
    <td>A security vulnerability has been detected in Besen BS20 EV Charging St= ation up to 20260426. This affects an unknown part of the component BLE/WiF=
    i. Such manipulation leads to authentication bypass by capture-replay. The = attack must be carried out from within the local network. Attacks of this n= ature are highly complex. It is indicated that the exploitability is diffic= ult. The original disclosure mentions, that "[t]hese vulnerabilities have b= een reported to Besen and we have received their acknowlegement that they a=
    re reviewing this as of April 2026."</td>
    <td>2026-05-24</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9398" target=3D"= _blank" rel=3D"noopener">CVE-2026-9398</a></td>

    <a href=3D"https://vuldb.com/vuln/365379" target=3D"_blank" rel=3D"noopener= ">VDB-365379 | Besen BS20 EV Charging Station BLE/WiFi authentication repla= y</a><br><a href=3D"https://vuldb.com/vuln/365379/cti" target=3D"_blank" re= l=3D"noopener">VDB-365379 | CTI Indicators (IOB, IOC, TTP)</a><br><a href= =3D"https://vuldb.com/submit/813577" target=3D"_blank" rel=3D"noopener">Sub= mit #813577 | Besen EV Charging Station BS20 EV Charger Improper Authorizat= ion</a><br><a href=3D"https://github.com/carfeii/besen#finding-5-unauthoriz= ed-tampering-of-charger-commands" target=3D"_blank" rel=3D"noopener">https:= //github.com/carfeii/besen#finding-5-unauthorized-tampering-of-charger-comm= ands</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--PowerFlex Manager (Appliance)</td>
    <td>Dell PowerFlex Manager, version(s) &lt;=3D4.6.2, contain(s) a Use of a = Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low pri= vileged attacker with local access could potentially exploit this vulnerabi= lity, leading to Protection mechanism bypass.</td>
    <td>2026-05-22</td>
    <td>3.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-46371" target=3D= "_blank" rel=3D"noopener">CVE-2025-46371</a></td>

    <a href=3D"https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-= security-update-for-dell-powerflex-rack-multiple-third-party-component-vuln= erabilities" target=3D"_blank" rel=3D"noopener">https://www.dell.com/suppor= t/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rac= k-multiple-third-party-component-vulnerabilities</a><br><a href=3D"https://= www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for= -dell-powerflex-appliance-multiple-third-party-component-vulnerabilities" t= arget=3D"_blank" rel=3D"noopener">https://www.dell.com/support/kbdoc/en-us/= 000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multipl= e-third-party-component-vulnerabilities</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HCL--BigFix Service Management (SM)</td>
    <td>HCL BigFix Service Management (SM) is affected by a security misconfigu= ration due to a missing or insecure "X-Content-Type-Options" header. This c= ould allow browsers to perform MIME-type sniffing, potentially causing mali= cious content to be interpreted and executed incorrectly.</td> <td>2026-05-20</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-31985" target=3D= "_blank" rel=3D"noopener">CVE-2025-31985</a></td>

    <a href=3D"https://support.hcl-software.com/csm?id=3Dkb_article&sysparm_art= icle=3DKB0128144" target=3D"_blank" rel=3D"noopener">https://support.hcl-so= ftware.com/csm?id=3Dkb_article&sysparm_article=3DKB0128144</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">jarrodwatts--claude-hud</td>
    <td>Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path t= raversal vulnerability that allows attackers to read arbitrary files by sup= plying an unvalidated transcript_path value via stdin JSON. Attackers can a= ccess any file readable by the process and the file metadata is written to =
    a persistent cache file with insufficient permissions, creating a forensic = record of accessed paths that survives process exit.</td>
    <td>2026-05-18</td>
    <td>3.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47091" target=3D= "_blank" rel=3D"noopener">CVE-2026-47091</a></td>

    <a href=3D"https://github.com/jarrodwatts/claude-hud/issues/485" target=3D"= _blank" rel=3D"noopener">https://github.com/jarrodwatts/claude-hud/issues/4= 85</a><br><a href=3D"https://github.com/jarrodwatts/claude-hud/pull/487" ta= rget=3D"_blank" rel=3D"noopener">https://github.com/jarrodwatts/claude-hud/= pull/487</a><br><a href=3D"https://github.com/jarrodwatts/claude-hud/commit= /234d9aad919b51326a43bcf90b45ae35c23afc30" target=3D"_blank" rel=3D"noopene= r">https://github.com/jarrodwatts/claude-hud/commit/234d9aad919b51326a43bcf= 90b45ae35c23afc30</a><br><a href=3D"https://www.vulncheck.com/advisories/cl= aude-hud-path-traversal-via-transcript-path" target=3D"_blank" rel=3D"noope= ner">https://www.vulncheck.com/advisories/claude-hud-path-traversal-via-tra= nscript-path</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13 fai=
    l to escape some variables that could contain malicious content during erro=
    r page composition which allows an attacker with access to edit some site c= onfiguration to execute some malicious code via injecting some JS as part o=
    f those values.. Mattermost Advisory ID: MMSA-2026-00622</td> <td>2026-05-18</td>
    <td>3.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3495" target=3D"= _blank" rel=3D"noopener">CVE-2026-3495</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00622</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13 fai=
    l to validate that the RefreshedToken differs from the original invite toke=
    n during remote cluster invite confirmation which allows an authenticated a= ttacker to bypass token rotation and reuse the original invite token via se= nding a crafted invite confirmation with a RefreshedToken matching the orig= inal token. Mattermost Advisory ID: MMSA-2026-00575</td>
    <td>2026-05-18</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4273" target=3D"= _blank" rel=3D"noopener">CVE-2026-4273</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00575</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13 fai=
    l to check if {{team_id}} was being changed when updating playbooks, allowi=
    ng users with only {{Manage Playbook Configurations}} permission to change =
    a playbook's team, bypassing manage members restriction via PUT api. Matter= most Advisory ID: MMSA-2025-00552</td>
    <td>2026-05-18</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4286" target=3D"= _blank" rel=3D"noopener">CVE-2026-4286</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2025-00552</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost Desktop App versions &lt;=3D6.1 6.0.1 5.4.13.0 fail to preve=
    nt server-rendered content from closing an underlying application view in t=
    he Mattermost Desktop App which allows a malicious server or plugin to cras=
    h the desktop client via invoking {{window.close()}} in the renderer contex=
    t, leading to a denial of service condition at the client level. Mattermost=
    Advisory ID: MMSA-2026-00633</td>
    <td>2026-05-18</td>
    <td>3.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4643" target=3D"= _blank" rel=3D"noopener">CVE-2026-4643</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00633</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13 fai=
    l to validate the Host header when constructing response URLs for custom sl= ash commands which allows an authenticated attacker to redirect slash comma=
    nd responses to an attacker-controlled server via a spoofed Host header.. M= attermost Advisory ID: MMSA-2026-00582</td>
    <td>2026-05-18</td>
    <td>3.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6333" target=3D"= _blank" rel=3D"noopener">CVE-2026-6333</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00582</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mattermost--Mattermost</td>
    <td>Mattermost versions 11.5.x &lt;=3D 11.5.1, 10.11.x &lt;=3D 10.11.13 fai=
    l to enforce client identity binding during the OAuth authorization code re= demption flow which allows an authenticated OAuth client to redeem authoriz= ation codes issued to a different client via a crafted token exchange reque= st.. Mattermost Advisory ID: MMSA-2026-00570</td>
    <td>2026-05-18</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6334" target=3D"= _blank" rel=3D"noopener">CVE-2026-6334</a></td>

    <a href=3D"https://mattermost.com/security-updates" target=3D"_blank" rel= =3D"noopener">MMSA-2026-00570</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--JeecgBoot</td>
    <td>A vulnerability has been found in JeecgBoot 3.9.1. This issue affects s= ome unknown processing of the file /openapi/call/ of the component OpenAPI = Endpoint. Such manipulation leads to improper authentication. The attack ca=
    n be executed remotely. A high complexity level is associated with this att= ack. The exploitability is assessed as difficult. The vendor was contacted = early about this disclosure but did not respond in any way.</td> <td>2026-05-24</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9373" target=3D"= _blank" rel=3D"noopener">CVE-2026-9373</a></td>

    <a href=3D"https://vuldb.com/vuln/365337" target=3D"_blank" rel=3D"noopener= ">VDB-365337 | JeecgBoot OpenAPI Endpoint call improper authentication</a><= br><a href=3D"https://vuldb.com/vuln/365337/cti" target=3D"_blank" rel=3D"n= oopener">VDB-365337 | CTI Indicators (IOB, IOC, IOA)</a><br><a href=3D"http= s://vuldb.com/submit/813251" target=3D"_blank" rel=3D"noopener">Submit #813= 251 | jeecgboot JeecgBoot 3.9.1 Improper Authentication</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">n/a--vBulletin</td>
    <td>A vulnerability was found in vBulletin 6.x. This impacts an unknown fun= ction of the component Login. Performing a manipulation results in cross si=
    te scripting. It is possible to initiate the attack remotely. The exploit h=
    as been made public and could be used. VulDB is withholding an extended red= istribution of exploit details to prevent simplified exploitation. The vend=
    or was contacted early about this disclosure but did not respond in any way= .</td>
    <td>2026-05-24</td>
    <td>3.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9357" target=3D"= _blank" rel=3D"noopener">CVE-2026-9357</a></td>

    <a href=3D"https://vuldb.com/vuln/365320" target=3D"_blank" rel=3D"noopener= ">VDB-365320 | vBulletin Login cross site scripting</a><br><a href=3D"https= ://vuldb.com/vuln/365320/cti" target=3D"_blank" rel=3D"noopener">VDB-365320=
    | CTI Indicators (IOB, IOC, TTP)</a><br><a href=3D"https://vuldb.com/submi= t/813052" target=3D"_blank" rel=3D"noopener">Submit #813052 | Cross Site Sc= ripting no f=C3=83=C2=B3rum vBulletin 6.xx Vbulletin 6.x.x Cross Site Scrip= ting</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NeoRazorX--facturascripts</td>
    <td>FacturaScripts is an open source accounting and invoicing software. Ver= sions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulne= rability through the fsNick cookie parameter. The application reflects the = cookie's value directly into the HTML without sanitization. The fsNick cook=
    ie is rendered into the DOM without encoding. While the server does reject = the modified session and forces a logout, the HTML containing the payload r= eaches the browser first. This lets the script execute immediately upon loa=
    d, effectively beating the redirect. This issue has been fixed in version 2= 025.8.</td>
    <td>2026-05-18</td>
    <td>3.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27964" target=3D= "_blank" rel=3D"noopener">CVE-2026-27964</a></td>

    <a href=3D"https://github.com/NeoRazorX/facturascripts/security/advisories/= GHSA-gq5c-rw37-g46c" target=3D"_blank" rel=3D"noopener">https://github.com/= NeoRazorX/facturascripts/security/advisories/GHSA-gq5c-rw37-g46c</a><br><a = href=3D"https://github.com/NeoRazorX/facturascripts/commit/9066e10326029adf= 012114e27eb5f3f33f78ecfd" target=3D"_blank" rel=3D"noopener">https://github= .com/NeoRazorX/facturascripts/commit/9066e10326029adf012114e27eb5f3f33f78ec= fd</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0=
    through 4.4.2 results in an unreachable code path that provides no effecti=
    ve bounds protection, which may allow a remote authenticated attacker to ob= tain limited information via crafted Spotlight RPC requests.</td> <td>2026-05-21</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44057" target=3D= "_blank" rel=3D"noopener">CVE-2026-44057</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44057" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44057</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A race condition in the privilege toggle mechanism in Netatalk 2.2.5 th= rough 4.4.2 allows a local attacker to obtain limited information, modify l= imited data, or cause a minor service disruption.</td>
    <td>2026-05-21</td>
    <td>3.9</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44059" target=3D= "_blank" rel=3D"noopener">CVE-2026-44059</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44059" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44059</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4=
    .2 allows an adjacent network attacker to modify limited data or cause a mi= nor service disruption via crafted print data.</td>
    <td>2026-05-21</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44065" target=3D= "_blank" rel=3D"noopener">CVE-2026-44065</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44065" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44065</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A heap over-read in extended attribute (EA) header parsing in Netatalk = 2.1.0 through 4.4.2 allows a remote authenticated attacker to obtain limite=
    d information or cause a minor service disruption via crafted EA data.</td> <td>2026-05-21</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44067" target=3D= "_blank" rel=3D"noopener">CVE-2026-44067</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44067" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44067</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An integer underflow in the volxlate function in Netatalk 3.0.0 through=
    4.4.2 allows a local privileged user to obtain limited information, modify=
    limited data, or cause a minor service disruption via crafted volume trans= lation input.</td>
    <td>2026-05-21</td>
    <td>3.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44069" target=3D= "_blank" rel=3D"noopener">CVE-2026-44069</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44069" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44069</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An unbounded memory reallocation in the charset conversion code in Neta= talk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a = minor denial of service via crafted character conversion requests.</td> <td>2026-05-21</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44070" target=3D= "_blank" rel=3D"noopener">CVE-2026-44070</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44070" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44070</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which = disables built-in buffer overflow detection at runtime, potentially allowin=
    g a remote attacker to cause a minor denial of service via memory errors th=
    at would otherwise be caught and safely terminated by runtime protection.</=

    <td>2026-05-21</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44071" target=3D= "_blank" rel=3D"noopener">CVE-2026-44071</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44071" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44071</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwi=
    se OR, resulting in incorrect error codes when multiple error conditions oc= cur simultaneously, which may allow a remote attacker to cause a minor serv= ice disruption via conditions that trigger incorrect error-handling paths.<=

    <td>2026-05-21</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44074" target=3D= "_blank" rel=3D"noopener">CVE-2026-44074</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44074" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44074</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A missing break statement in DSI OpenSession processing in Netatalk 1.5=
    .0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into=
    DSIOPT_SERVQUANT, resulting in unintended session option handling that may=
    allow a remote attacker to cause a minor service disruption via crafted DS=
    I session options.</td>
    <td>2026-05-21</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44075" target=3D= "_blank" rel=3D"noopener">CVE-2026-44075</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44075" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44075</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allow=
    s a remote authenticated attacker to cause a minor denial of service via cr= afted input that triggers incorrect format string processing.</td> <td>2026-05-21</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7835" target=3D"= _blank" rel=3D"noopener">CVE-2026-7835</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-7835" target=3D"_blank" re= l=3D"noopener">Netatalk Security Advisory CVE-2026-7835</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>An incorrect calculation in the hextoint macro in Netatalk 2.0.0 throug=
    h 4.4.2 due to improper uppercase character handling allows a remote authen= ticated attacker to cause limited data modification via crafted hexadecimal=
    input.</td>
    <td>2026-05-21</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7836" target=3D"= _blank" rel=3D"noopener">CVE-2026-7836</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-7836" target=3D"_blank" re= l=3D"noopener">Netatalk Security Advisory CVE-2026-7836</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>A time-of-check time-of-use (TOCTOU) condition in the ad_flush function=
    in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, = which may allow a remote attacker to cause limited data modification under = specific race conditions.</td>
    <td>2026-05-21</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7837" target=3D"= _blank" rel=3D"noopener">CVE-2026-7837</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-7837" target=3D"_blank" re= l=3D"noopener">Netatalk Security Advisory CVE-2026-7837</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">Netatalk--Netatalk</td>
    <td>Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() with= out properly handling the error condition, which allows a local privileged = user to execute unintended commands or cause a minor service disruption und=
    er specific conditions.</td>
    <td>2026-05-21</td>
    <td>2.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44072" target=3D= "_blank" rel=3D"noopener">CVE-2026-44072</a></td>

    <a href=3D"https://netatalk.io/security/CVE-2026-44072" target=3D"_blank" r= el=3D"noopener">Netatalk Security Advisory CVE-2026-44072</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS= .</td>
    <td>2026-05-19</td>
    <td>3.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25110" target=3D= "_blank" rel=3D"noopener">CVE-2026-25110</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-04.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 04.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS= .</td>
    <td>2026-05-19</td>
    <td>3.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27781" target=3D= "_blank" rel=3D"noopener">CVE-2026-27781</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-04.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 04.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS= .</td>
    <td>2026-05-19</td>
    <td>3.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-28751" target=3D= "_blank" rel=3D"noopener">CVE-2026-28751</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-04.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 04.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpenHarmony--OpenHarmony</td>
    <td>in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS= .</td>
    <td>2026-05-19</td>
    <td>3.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33565" target=3D= "_blank" rel=3D"noopener">CVE-2026-33565</a></td>

    <a href=3D"https://gitcode.com/openharmony/security/tree/master/zh/security= -disclosure/2026/2026-05.md" target=3D"_blank" rel=3D"noopener">https://git= code.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-= 05.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">opensourcepos--Open Source Point of Sale</td> <td>A flaw has been found in opensourcepos Open Source Point of Sale up to = 3.4.2. Impacted is the function Login of the file app/Models/Employee.php o=
    f the component Employee Login. This manipulation causes use of weak hash. = Remote exploitation of the attack is possible. The attack is considered to = have high complexity. The exploitability is considered difficult. The actua=
    l existence of this vulnerability is currently in question. The vendor expl= ains: "[T]he code is still there to allow the upgrade path to work. The def= ault password is initially seeded with the old hash function, but then migr= ated to a newer one after login. [T]he hash version check might be cleaned =
    up in the future. Currently it's not actively in use as any password change=
    will use a newer hash function."</td>
    <td>2026-05-18</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8803" target=3D"= _blank" rel=3D"noopener">CVE-2026-8803</a></td>

    <a href=3D"https://vuldb.com/vuln/364436" target=3D"_blank" rel=3D"noopener= ">VDB-364436 | opensourcepos Open Source Point of Sale Employee Login Emplo= yee.php login weak hash</a><br><a href=3D"https://vuldb.com/vuln/364436/cti=
    " target=3D"_blank" rel=3D"noopener">VDB-364436 | CTI Indicators (IOB, IOC,=
    TTP, IOA)</a><br><a href=3D"https://vuldb.com/submit/802561" target=3D"_bl= ank" rel=3D"noopener">Submit #802561 | opensourcepos Open Source Point of S= ale 3.4.1 Weak Encoding for Password</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">QuantumNous--new-api</td>
    <td>A security vulnerability has been detected in QuantumNous new-api up to=
    0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of th=
    e file router/relay-router.go of the component Midjourney Image Relay Endpo= int. Such manipulation leads to authorization bypass. The attack can be lau= nched remotely. The attack requires a high level of complexity. The exploit= ability is reported as difficult. The exploit has been disclosed publicly a=
    nd may be used. The vendor was contacted early about this disclosure but di=
    d not respond in any way.</td>
    <td>2026-05-23</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9306" target=3D"= _blank" rel=3D"noopener">CVE-2026-9306</a></td>

    <a href=3D"https://vuldb.com/vuln/365253" target=3D"_blank" rel=3D"noopener= ">VDB-365253 | QuantumNous new-api Midjourney Image Relay Endpoint relay-ro= uter.go GetByOnlyMJId authorization</a><br><a href=3D"https://vuldb.com/vul= n/365253/cti" target=3D"_blank" rel=3D"noopener">VDB-365253 | CTI Indicator=
    s (IOB, IOC, IOA)</a><br><a href=3D"https://vuldb.com/submit/812196" target= =3D"_blank" rel=3D"noopener">Submit #812196 | QuantumNous new-api 0.12.1 Au= thorization Bypass Through User-Controlled Key (CWE-639)</a><br><a href=3D"= https://gist.github.com/YLChen-007/13974ead25fc6dac42fd7bac62fbb2df" target= =3D"_blank" rel=3D"noopener">https://gist.github.com/YLChen-007/13974ead25f= c6dac42fd7bac62fbb2df</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">RsyncProject--rsync</td>
    <td>Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack w= rite vulnerability in the establish_proxy_connection() function in socket.c=
    that allows network attackers to corrupt stack memory by sending a malform=
    ed HTTP proxy response. Attackers can exploit this by positioning themselve=
    s between the client and proxy or controlling the proxy server to send a re= sponse line of 1023 or more bytes without a newline terminator, causing a n= ull byte to be written to an out-of-bounds stack address when the RSYNC_PRO=
    XY environment variable is set.</td>
    <td>2026-05-20</td>
    <td>3.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45232" target=3D= "_blank" rel=3D"noopener">CVE-2026-45232</a></td>

    <a href=3D"https://github.com/RsyncProject/rsync/security/advisories/GHSA-8= f85-j2cv-59m8" target=3D"_blank" rel=3D"noopener">https://github.com/RsyncP= roject/rsync/security/advisories/GHSA-8f85-j2cv-59m8</a><br><a href=3D"http= s://github.com/RsyncProject/rsync/releases/tag/v3.4.3" target=3D"_blank" re= l=3D"noopener">https://github.com/RsyncProject/rsync/releases/tag/v3.4.3</a= ><br><a href=3D"https://www.vulncheck.com/advisories/rsync-off-by-one-stack= -write-via-http-proxy" target=3D"_blank" rel=3D"noopener">https://www.vulnc= heck.com/advisories/rsync-off-by-one-stack-write-via-http-proxy</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">SourceCodester--SUP Online Shopping</td>
    <td>A vulnerability was identified in SourceCodester SUP Online Shopping 1.=
    0. The impacted element is an unknown function of the file /admin/producted= it.php. The manipulation of the argument productName leads to cross site sc= ripting. It is possible to initiate the attack remotely. The exploit is pub= licly available and might be used.</td>
    <td>2026-05-24</td>
    <td>2.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9377" target=3D"= _blank" rel=3D"noopener">CVE-2026-9377</a></td>

    <a href=3D"https://vuldb.com/vuln/365340" target=3D"_blank" rel=3D"noopener= ">VDB-365340 | SourceCodester SUP Online Shopping productedit.php cross sit=
    e scripting</a><br><a href=3D"https://vuldb.com/vuln/365340/cti" target=3D"= _blank" rel=3D"noopener">VDB-365340 | CTI Indicators (IOB, IOC, TTP, IOA)</= a><br><a href=3D"https://vuldb.com/submit/813270" target=3D"_blank" rel=3D"= noopener">Submit #813270 | sourcecodester SUP Online Shopping Project V1.0 = Cross Site Scripting</a><br><a href=3D"https://github.com/redshadowword-cel= l/CVE/issues/13" target=3D"_blank" rel=3D"noopener">https://github.com/reds= hadowword-cell/CVE/issues/13</a><br><a href=3D"https://www.sourcecodester.c= om/" target=3D"_blank" rel=3D"noopener">https://www.sourcecodester.com/</a>= <br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">SPIP--SPIP</td>
    <td>action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open r= edirect vulnerability.</td>
    <td>2026-05-24</td>
    <td>3.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48832" target=3D= "_blank" rel=3D"noopener">CVE-2026-48832</a></td>

    <a href=3D"https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4= -15.html?lang=3Dfr" target=3D"_blank" rel=3D"noopener">https://blog.spip.ne= t/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-15.html?lang=3Dfr</a><br><a hr= ef=3D"https://git.spip.net/spip/spip/-/commit/75629034697ab52a963a340afd109= 30407e1cd55" target=3D"_blank" rel=3D"noopener">https://git.spip.net/spip/s= pip/-/commit/75629034697ab52a963a340afd10930407e1cd55</a><br><a href=3D"htt= ps://git.spip.net/spip/ecrire/-/commit/a22cb8a56f1e37ff3854b73ff3f66aa3df47= 070a" target=3D"_blank" rel=3D"noopener">https://git.spip.net/spip/ecrire/-= /commit/a22cb8a56f1e37ff3854b73ff3f66aa3df47070a</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ulisesbocchio--jasypt-spring-boot</td>
    <td>A weakness has been identified in ulisesbocchio jasypt-spring-boot up t=
    o 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeyS= altGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio= /jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password = Hash Handler. Executing a manipulation can lead to use of a one-way hash wi=
    th a predictable salt. The attack can be launched remotely. The attack requ= ires a high level of complexity. The exploitation appears to be difficult. = The exploit has been made available to the public and could be used for att= acks. The project was informed of the problem early through an issue report=
    but has not responded yet.</td>
    <td>2026-05-24</td>
    <td>3.7</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9370" target=3D"= _blank" rel=3D"noopener">CVE-2026-9370</a></td>

    <a href=3D"https://vuldb.com/vuln/365333" target=3D"_blank" rel=3D"noopener= ">VDB-365333 | ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConf= ig.java getSecretKeySaltGenerator hash predictable salt</a><br><a href=3D"h= ttps://vuldb.com/vuln/365333/cti" target=3D"_blank" rel=3D"noopener">VDB-36= 5333 | CTI Indicators (IOB, IOC, TTP, IOA)</a><br><a href=3D"https://vuldb.= com/submit/813198" target=3D"_blank" rel=3D"noopener">Submit #813198 | Ulis=
    es Bocchio jasypt-spring-boot 3.0.0 to 4.0.4 Cryptographic Issues</a><br><a=
    href=3D"https://github.com/ulisesbocchio/jasypt-spring-boot/issues/431" ta= rget=3D"_blank" rel=3D"noopener">https://github.com/ulisesbocchio/jasypt-sp= ring-boot/issues/431</a><br><a href=3D"https://github.com/dntyfate/cve/issu= es/3" target=3D"_blank" rel=3D"noopener">https://github.com/dntyfate/cve/is= sues/3</a><br><a href=3D"https://github.com/ulisesbocchio/jasypt-spring-boo= t/" target=3D"_blank" rel=3D"noopener">https://github.com/ulisesbocchio/jas= ypt-spring-boot/</a><br>=C2=A0</td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    <div id=3D"snya_v">
    <h2 id=3D"snya_v_title">Severity Not Yet Assigned</h2>
    <table id=3D"table_severity_not_yet_assigned" class=3D"table no-tablesaw" s= tyle=3D"table-layout: fixed; width: 100%;" border=3D"1" summary=3D"Severity=
    Not Yet Assigned">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">9front--9front</td>
    <td>Mothra would respect a default value given by a website for HTML file u= pload forms. An attacker could craft a website with a malicious default fil=
    e path, and then conceal this form element.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9053" target=3D"= _blank" rel=3D"noopener">CVE-2026-9053</a></td>

    <a href=3D"https://git.9front.org/plan9front/9front/d145acc9ef0da47131af6ad= 94e87264e04870d47/commit.html" target=3D"_blank" rel=3D"noopener">https://g= it.9front.org/plan9front/9front/d145acc9ef0da47131af6ad94e87264e04870d47/co= mmit.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">9front--9front</td>
    <td>An attacker sending tcp, il, rudp, rudp, or gre packets with a length l= ess than the header size would trigger a kernel panic.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9054" target=3D"= _blank" rel=3D"noopener">CVE-2026-9054</a></td>

    <a href=3D"https://git.9front.org/plan9front/9front/7838d68969549f938cc8e80= c0c2b4218cb12805c/commit.html" target=3D"_blank" rel=3D"noopener">https://g= it.9front.org/plan9front/9front/7838d68969549f938cc8e80c0c2b4218cb12805c/co= mmit.html</a><br><a href=3D"https://git.9front.org/plan9front/9front/f86917= b75e9562f90545b7e484dbdcd748236952/commit.html" target=3D"_blank" rel=3D"no= opener">https://git.9front.org/plan9front/9front/f86917b75e9562f90545b7e484= dbdcd748236952/commit.html</a><br><a href=3D"https://git.9front.org/plan9fr= ont/9front/70c97c334171c715df82774d1a47638abaca2db4/commit.html" target=3D"= _blank" rel=3D"noopener">https://git.9front.org/plan9front/9front/70c97c334= 171c715df82774d1a47638abaca2db4/commit.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Advantech--WebAccess/SCADA 8.0-2015.08.16=C2= =A0</td>
    <td>Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-201= 5.08.16 allows a remote attacker to obtain sensitive information via the de= cryption field in the Create New Project User component</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36226" target=3D= "_blank" rel=3D"noopener">CVE-2026-36226</a></td>

    <a href=3D"https://github.com/NullByte8080/CVE-2026-36226" target=3D"_blank=
    " rel=3D"noopener">https://github.com/NullByte8080/CVE-2026-36226</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Altium--Altium 365</td>
    <td>A missing authentication vulnerability exists in the Altium 365 SearchS= ervice. A legacy SOAP endpoint exposes search index operations without requ= iring authentication, session tokens, or any form of identity verification.=
    An unauthenticated network attacker who can reference a target workspace's=
    identifier can interact with that workspace's search index, crossing tenan=
    t boundaries. Successful exploitation allows reading a workspace's indexed = contents (such as component data, project and folder names, and user metada= ta) and injecting, modifying, or deleting search index entries. These opera= tions affect the search index only, not the underlying vault data, but they=
    can disclose sensitive workspace information and compromise the integrity = and availability of search results. Altium 365 cloud deployments are affect= ed; on-premise Altium Enterprise Server is not affected.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9152" target=3D"= _blank" rel=3D"noopener">CVE-2026-9152</a></td>

    <a href=3D"https://www.altium.com/platform/security-compliance/security-adv= isories" target=3D"_blank" rel=3D"noopener">https://www.altium.com/platform= /security-compliance/security-advisories</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Altium--Altium Enterprise Server</td>
    <td>A path traversal vulnerability exists in the Altium Enterprise Server C= omparisonService due to missing filename sanitization in the Gerber file up= load APIs. A regular authenticated workspace user can supply a crafted file= name in the multipart Content-Disposition header to escape the intended tem= porary upload directory and write arbitrary files to any location on the se= rver filesystem. Because content-controlled files can be written to web-acc= essible directories, this can be escalated to remote code execution in the = context of the service account. It can also be used to overwrite applicatio=
    n binaries or configuration files, leading to service takeover or denial of=
    service.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9102" target=3D"= _blank" rel=3D"noopener">CVE-2026-9102</a></td>

    <a href=3D"https://www.altium.com/platform/security-compliance/security-adv= isories" target=3D"_blank" rel=3D"noopener">https://www.altium.com/platform= /security-compliance/security-advisories</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Altium--Altium Enterprise Server</td>
    <td>A path traversal vulnerability exists in the Altium Enterprise Server V= iewer StorageController due to improper handling of file path route paramet= ers. On on-premise deployments that use local filesystem storage, a regular=
    authenticated user can supply a URL-encoded absolute path (such as an enco= ded drive letter) in a Viewer storage API request, causing the configured s= torage root to be discarded and allowing arbitrary files to be read from th=
    e server filesystem. Because the readable files include the server's master=
    configuration, which stores database credentials, signing key locations, c= ertificate passwords, and OAuth secrets, exploitation can lead to disclosur=
    e of all server secrets and full compromise of the server and its data. Clo=
    ud deployments are not affected, as they use object storage and do not enab=
    le this component.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9129" target=3D"= _blank" rel=3D"noopener">CVE-2026-9129</a></td>

    <a href=3D"https://www.altium.com/platform/security-compliance/security-adv= isories" target=3D"_blank" rel=3D"noopener">https://www.altium.com/platform= /security-compliance/security-advisories</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD EPYC 4004</td>
    <td>Improper input validation in the System Management Mode (SMM) communica= tions buffer could allow a privileged attacker to perform an out of bounds = read or write to a limited section of the Top of Memory Segment (TSEG) memo=
    ry region, potentially resulting in loss of confidentiality or integrity.</=

    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36343" target=3D= "_blank" rel=3D"noopener">CVE-2024-36343</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-3030.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-3030.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-4017.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache Airflow Ama= zon provider</td>
    <td>In the AWS Secrets Manager and SSM Parameter Store secrets backends of = `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic c= ould resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the sa=
    me path as another team's team-scoped secret when the caller had no team co= ntext. A privileged caller without team context could therefore retrieve an= other team's secret by crafting a colliding `conn_id`. Fixed in 9.28.0 by s= witching the team-scope separator to `--` and rejecting team-shaped `conn_i= d`s when team context is absent. Affects the experimental multi-tenant team=
    s feature only. Users are recommended to upgrade to `apache-airflow-provide= rs-amazon` 9.28.0, which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42526" target=3D= "_blank" rel=3D"noopener">CVE-2026-42526</a></td>

    <a href=3D"https://github.com/apache/airflow/pull/65703" target=3D"_blank" = rel=3D"noopener">https://github.com/apache/airflow/pull/65703</a><br><a hre= f=3D"https://lists.apache.org/thread/0092sz5g520d3qqjb01wd61myqlgjtyn" targ= et=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/0092sz5g520d= 3qqjb01wd61myqlgjtyn</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache Airflow CNC=
    F Kubernetes provider</td>
    <td>JWT tokens that were used by workers in Kubernetes Executors have been = exposed to users who had read only access to Kuberentes Pods. This could al= low users with just read-only access to perform actions that were only avai= lable to running tasks via Task SDK and potentially allow to modify state o=
    f Airflow Database for tasks.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27173" target=3D= "_blank" rel=3D"noopener">CVE-2026-27173</a></td>

    <a href=3D"https://github.com/apache/airflow/pull/60108" target=3D"_blank" = rel=3D"noopener">https://github.com/apache/airflow/pull/60108</a><br><a hre= f=3D"https://lists.apache.org/thread/pk3m2z4s2rkmc0v6gh9hnch9spc6stqw" targ= et=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/pk3m2z4s2rkm= c0v6gh9hnch9spc6stqw</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Camel-CXF and Camel-Knative Message Header Injection via Missing Inboun=
    d Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRs= HeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cx= f-transport, and KnativeHttpHeaderFilterStrategy in camel-knative-http) onl=
    y filter outbound Camel-internal headers via setOutFilterStartsWith, while = not configuring inbound filtering via setInFilterStartsWith. As a result, a=
    n unauthenticated attacker can inject Camel-internal headers (e.g. CamelExe= cCommandExecutable, CamelFileName) via HTTP requests to CXF-RS or CXF-SOAP = endpoints. When a route forwards messages from these endpoints to header-dr= iven components such as camel-exec or camel-file, the injected headers over= ride configured values, enabling remote code execution or arbitrary file wr= ites. This is the same pattern that was previously addressed in camel-under= tow (CVE-2025-30177), the broader incoming-header filter (CVE-2025-27636 an=
    d CVE-2025-29891), and non-HTTP strategies (CVE-2026-40453). This issue aff= ects Apache Camel: from 3.18.0 before 4.14.6, from 4.15.0 before 4.18.2. Us= ers are recommended to upgrade to version 4.19.0, which fixes the issue. If=
    users are on the 4.18.x LTS releases stream, then they are suggested to up= grade to 4.18.2. If users are on the 4.14.x LTS releases stream, then they = are suggested to upgrade to 4.14.6.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47323" target=3D= "_blank" rel=3D"noopener">CVE-2026-47323</a></td>

    <a href=3D"https://camel.apache.org/security/CVE-2026-47323.html" target=3D= "_blank" rel=3D"noopener">https://camel.apache.org/security/CVE-2026-47323.= html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache Camel K</td=

    <td>(Externally Controlled Reference to a Resource in Another Sphere), (Aut= horization Bypass Through User-Controlled Key) vulnerability in Apache Came=
    l K. Authorized users in a Kubernetes namespace can create a Build resource=
    , controlling the Pod generation in a namespace of their choice, including = the operator namespace. This issue affects Apache Camel K: from 2.0.0 befor=
    e 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1. Users are reco= mmended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the i= ssue.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45760" target=3D= "_blank" rel=3D"noopener">CVE-2026-45760</a></td>

    <a href=3D"https://camel.apache.org/security/CVE-2026-45760.html" target=3D= "_blank" rel=3D"noopener">https://camel.apache.org/security/CVE-2026-45760.= html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache CXF</td> <td>The fix for=C2=A0CVE-2025-48913: Apache CXF: Untrusted JMS configuratio=
    n can lead to RCE was not complete, meaning that another path in the code m= ight lead to code execution capabilities, if untrusted users are allowed to=
    configure JMS for Apache CXF. Users are recommended to upgrade to versions=
    4.2.1, 4.1.6 or 3.6.11, which fix this issue.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44417" target=3D= "_blank" rel=3D"noopener">CVE-2026-44417</a></td>

    <a href=3D"https://lists.apache.org/thread/bqg6gjy2cx7rfyqjxcpv3jwjvmclvz4o=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/bqg6gj= y2cx7rfyqjxcpv3jwjvmclvz4o</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache CXF</td> <td>Insecure XML parser configuration in Apache CXF's WS-Transfer module ma=
    y allow attackers to perform XXE attacks. Users are recommended to upgrade =
    to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44618" target=3D= "_blank" rel=3D"noopener">CVE-2026-44618</a></td>

    <a href=3D"https://lists.apache.org/thread/c7vb015f8ljmjl44030mn0yfq71f7sd7=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/c7vb01= 5f8ljmjl44030mn0yfq71f7sd7</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache CXF</td>
    <td>An LDAP injection vulnerability in the LDAP Certificate repository of t=
    he XKMS server in Apache CXF may allow an attacker to retrieve arbitrary ce= rtificates from the repository.=C2=A0 Users are recommended to upgrade to v= ersions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44930" target=3D= "_blank" rel=3D"noopener">CVE-2026-44930</a></td>

    <a href=3D"https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/c1zqxp= po1m5z3kbdhjn5p991zk09ynkh</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache Fory</td> <td>Deserialization of untrusted data in Apache Fory PyFory. PyFory's Reduc= eSerializer could bypass documented DeserializationPolicy validation hooks = during reduce-state restoration and global-name resolution. An application =
    is vulnerable if it deserializes attacker-controlled data using PyFory Pyth= on-native mode with strict mode disabled and relies on DeserializationPolic=
    y to restrict unsafe classes, functions, or module attributes. This issue a= ffects Apache Fory: from before 1.0.0. Mitigation: Users of Apache Fory are=
    recommended to upgrade to version 1.0.0 or later, which enforces Deseriali= zationPolicy validation for the affected ReduceSerializer paths and thus fi= xes this issue.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48207" target=3D= "_blank" rel=3D"noopener">CVE-2026-48207</a></td>

    <a href=3D"https://fory.apache.org/security/#cve-2026-48207-pyfory-reducese= rializer-deserializationpolicy-bypass" target=3D"_blank" rel=3D"noopener">h= ttps://fory.apache.org/security/#cve-2026-48207-pyfory-reduceserializer-des= erializationpolicy-bypass</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Neutralization of Special Elements Used in a Template Engine v= ulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09= .06. Users are recommended to upgrade to version 24.09.06, which fixes the = issue. Please note that in the updated version, "Data Resource" records wit=
    h dataTemplateTypeId =3D "FTL" are no longer supported. Additionally, in th=
    e updated version, the "Ecommerce Customer" security group no longer includ=
    es content management grants. Users are advised to remove these permissions=
    from any production site as well.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29207" target=3D= "_blank" rel=3D"noopener">CVE-2026-29207</a></td>

    <a href=3D"https://lists.apache.org/thread/3rcrp8bh3x6ovrj5xnc0fm1f0nrn52r0=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/3rcrp8= bh3x6ovrj5xnc0fm1f0nrn52r0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: bef= ore 24.09.06. Users are recommended to upgrade to version 24.09.06, which f= ixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29220" target=3D= "_blank" rel=3D"noopener">CVE-2026-29220</a></td>

    <a href=3D"https://lists.apache.org/thread/5hjnmt9no6mmtg8sxq3mhonzff1vkd5m=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/5hjnmt= 9no6mmtg8sxq3mhonzff1vkd5m</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Co= ntent component operations. This issue affects Apache OFBiz: before 24.09.0=
    6. Users are recommended to upgrade to version 24.09.06, which fixes the is= sue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29226" target=3D= "_blank" rel=3D"noopener">CVE-2026-29226</a></td>

    <a href=3D"https://lists.apache.org/thread/6707wys8jxzmowxggn4cmtwwk9ygl2tr=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/6707wy= s8jxzmowxggn4cmtwwk9ygl2tr</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Input Validation vulnerability in Apache OFBiz. This issue aff= ects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to ver= sion 24.09.06, which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31378" target=3D= "_blank" rel=3D"noopener">CVE-2026-31378</a></td>

    <a href=3D"https://lists.apache.org/thread/cbl8qkqtxv90m6ssfwd58bnoh933v38t=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/cbl8qk= qtxv90m6ssfwd58bnoh933v38t</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
    e Scripting'), Improper Limitation of a Pathname to a Restricted Directory = ('Path Traversal'), Improper Control of Generation of Code ('Code Injection=
    ') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 2= 4.09.06. Users are recommended to upgrade to version 24.09.06, which fixes = the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31379" target=3D= "_blank" rel=3D"noopener">CVE-2026-31379</a></td>

    <a href=3D"https://lists.apache.org/thread/1tcnkxjm0s6n1ohfb21brl25dt0hv9by=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/1tcnkx= jm0s6n1ohfb21brl25dt0hv9by</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Neutralization of Special Elements used in an Expression Langu= age Statement ('Expression Language Injection') vulnerability in Apache OFB= iz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended=
    to upgrade to version 24.09.06, which fixes the issue.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31380" target=3D= "_blank" rel=3D"noopener">CVE-2026-31380</a></td>

    <a href=3D"https://lists.apache.org/thread/v2brvq1tf4q491obkxv8p7fc5qfshc08=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/v2brvq= 1tf4q491obkxv8p7fc5qfshc08</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Authentication vulnerability in Apache OFBiz. This issue affec=
    ts Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versi=
    on 24.09.06, which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31387" target=3D= "_blank" rel=3D"noopener">CVE-2026-31387</a></td>

    <a href=3D"https://lists.apache.org/thread/3wgybgdvmbfvly24zm4sb4y53fc1pqcf=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/3wgybg= dvmbfvly24zm4sb4y53fc1pqcf</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Access Control vulnerability in Apache OFBiz in multi-tenant d= eployments. This issue affects Apache OFBiz: before 24.09.06. Users are rec= ommended to upgrade to version 24.09.06, which fixes the issue.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31388" target=3D= "_blank" rel=3D"noopener">CVE-2026-31388</a></td>

    <a href=3D"https://lists.apache.org/thread/npjchvnpnosoqpto46s2om12jd9s7py7=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/npjchv= npnosoqpto46s2om12jd9s7py7</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
    e Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBi=
    z: before 24.09.06. Users are recommended to upgrade to version 24.09.06, w= hich fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31906" target=3D= "_blank" rel=3D"noopener">CVE-2026-31906</a></td>

    <a href=3D"https://lists.apache.org/thread/1fblqdo89d3ps8kgtcnkcq8sh7gwkcpn=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/1fblqd= o89d3ps8kgtcnkcq8sh7gwkcpn</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Exposure of Sensitive Information to an Unauthorized Actor vulnerabilit=
    y in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users = are recommended to upgrade to version 24.09.06, which fixes the issue.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31909" target=3D= "_blank" rel=3D"noopener">CVE-2026-31909</a></td>

    <a href=3D"https://lists.apache.org/thread/0hpopzz1qrhkzsbt3ncofs6qo0545r2h=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/0hpopz= z1qrhkzsbt3ncofs6qo0545r2h</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This = issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra=
    de to version 24.09.06, which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31910" target=3D= "_blank" rel=3D"noopener">CVE-2026-31910</a></td>

    <a href=3D"https://lists.apache.org/thread/2smc4c4o056ovd2hoq1l29593y5y29vh=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/2smc4c= 4o056ovd2hoq1l29593y5y29vh</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This=
    issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgr= ade to version 24.09.06, which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31986" target=3D= "_blank" rel=3D"noopener">CVE-2026-31986</a></td>

    <a href=3D"https://lists.apache.org/thread/2hl9xoqm8tq8b22x6vnmtp7tg3opcqgc=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/2hl9xo= qm8tq8b22x6vnmtp7tg3opcqgc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Control of Generation of Code ('Code Injection') vulnerability=
    in email services of Apache OFBiz. This issue affects Apache OFBiz: before=
    24.09.06. Users are recommended to upgrade to version 24.09.06, which fixe=
    s the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-35086" target=3D= "_blank" rel=3D"noopener">CVE-2026-35086</a></td>

    <a href=3D"https://lists.apache.org/thread/g0s37yhnh2xwfts400crb2w8s337hgjx=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/g0s37y= hnh2xwfts400crb2w8s337hgjx</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Neutralization of Special Elements used in an LDAP Query ('LDA=
    P Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBi=
    z: before 24.09.06. Users are recommended to upgrade to version 24.09.06, w= hich fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41919" target=3D= "_blank" rel=3D"noopener">CVE-2026-41919</a></td>

    <a href=3D"https://lists.apache.org/thread/592czh9o69n74c036vy30fnqknocw74p=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/592czh= 9o69n74c036vy30fnqknocw74p</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Authorization vulnerability in Apache OFBiz Webtools. This iss=
    ue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade =
    to version 24.09.06, which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45187" target=3D= "_blank" rel=3D"noopener">CVE-2026-45187</a></td>

    <a href=3D"https://lists.apache.org/thread/pcmfyxjyk7dg0btxqg9h7cr30yg8mr7k=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/pcmfyx= jyk7dg0btxqg9h7cr30yg8mr7k</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Authentication vulnerability in Apache OFBiz via Password-Chan=
    ge Logic Flaw Leading to Remote Code Execution This issue affects Apache OF= Biz: before 24.09.06. Users are recommended to upgrade to version 24.09.06,=
    which fixes the issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45434" target=3D= "_blank" rel=3D"noopener">CVE-2026-45434</a></td>

    <a href=3D"https://lists.apache.org/thread/yw4owrzl0yho1yx7oqxvr6xjkmln9tq8=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/yw4owr= zl0yho1yx7oqxvr6xjkmln9tq8</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apache Software Foundation--Apache OFBiz</td> <td>Improper Control of Generation of Code ('Code Injection'), Improper Neu= tralization of Directives in Dynamically Evaluated Code ('Eval Injection') = vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.0= 9.06. Users are recommended to upgrade to version 24.09.06, which fixes the=
    issue.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46586" target=3D= "_blank" rel=3D"noopener">CVE-2026-46586</a></td>

    <a href=3D"https://lists.apache.org/thread/7mgjl81nrpxqtfcg6h5qtrx7wztbl4js=
    " target=3D"_blank" rel=3D"noopener">https://lists.apache.org/thread/7mgjl8= 1nrpxqtfcg6h5qtrx7wztbl4js</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Apple--Private Cloud Compute Server Software</=

    <td>An attacker in a privileged network position may be able to leak sensit= ive information. A path handling issue was addressed with improved validati= on. This issue is fixed in PCC Release 5E290.3.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-20685" target=3D= "_blank" rel=3D"noopener">CVE-2026-20685</a></td>

    <a href=3D"https://security.apple.com/documentation/private-cloud-compute/r= eleasenotes#darwin-init" target=3D"_blank" rel=3D"noopener">https://securit= y.apple.com/documentation/private-cloud-compute/releasenotes#darwin-init</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">APScheduler--JSONSerializer and CBORSerializer= =C2=A0</td>
    <td>The JSONSerializer and CBORSerializer in APScheduler (all versions incl= uding 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via=
    Insecure Deserialization. The unmarshal_object function allows for arbitra=
    ry class instantiation and state injection by dynamically importing modules=
    and calling __setstate__ on any class available in the Python environment.=
    An attacker can exploit this by submitting a specially crafted JSON or CBO=
    R payload to an application using these serializers</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31072" target=3D= "_blank" rel=3D"noopener">CVE-2026-31072</a></td>

    <a href=3D"https://github.com/agronholm/apscheduler" target=3D"_blank" rel= =3D"noopener">https://github.com/agronholm/apscheduler</a><br><a href=3D"ht= tps://gist.github.com/nedlir/11fb77f35a59cbba73392a086b02a9c6" target=3D"_b= lank" rel=3D"noopener">https://gist.github.com/nedlir/11fb77f35a59cbba73392= a086b02a9c6</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Arm--ArmNN</td>
    <td>In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::Ge= tNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to by= pass buffer size validation and trigger a heap-based buffer over-read durin=
    g model optimization. The overflow occurs when multiplying tensor dimension=
    s using 32-bit unsigned arithmetic without overflow detection, causing GetN= umBytes() to return an understated allocation size. During Optimize()-&gt;I= nferOutputShapes(), the BatchToSpaceNdLayer reads beyond the allocated buff= er.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42627" target=3D= "_blank" rel=3D"noopener">CVE-2026-42627</a></td>

    <a href=3D"https://github.com/ARM-software/armnn/blob/main/src/armnn/Tensor= .cpp" target=3D"_blank" rel=3D"noopener">https://github.com/ARM-software/ar= mnn/blob/main/src/armnn/Tensor.cpp</a><br><a href=3D"https://github.com/ARM= -software/armnn/blob/main/src/armnnTfLiteParser/TfLiteParser.cpp" target=3D= "_blank" rel=3D"noopener">https://github.com/ARM-software/armnn/blob/main/s= rc/armnnTfLiteParser/TfLiteParser.cpp</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">awesomemotive--NextGEN Gallery</td>
    <td>NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated = SQL injection via the 'orderby' parameter on the REST API endpoints '/image= ly/v1/galleries' and '/imagely/v1/albums'. The root cause is an insufficien=
    t sanitization function ('_clean_column()') in the data mapper layer that u= ses a character blacklist instead of a whitelist approach. This allows an a= uthenticated attacker with the 'NextGEN Gallery overview' capability (assig= ned to the Administrator role by default) to inject arbitrary SQL into the = 'ORDER BY' clause.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9059" target=3D"= _blank" rel=3D"noopener">CVE-2026-9059</a></td>

    <a href=3D"https://www.tenable.com/security/research/tra-2026-42" target=3D= "_blank" rel=3D"noopener">https://www.tenable.com/security/research/tra-202= 6-42</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">baptisteArno--typebot.io</td>
    <td>TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a = critical stored XSS vulnerability in the app.typebot.io profile picture upl= oad form. The application fails to sanitize or restrict SVG/XML-based uploa=
    ds and directly renders them when accessed through the domain. By uploading=
    a crafted malicious SVG file containing embedded JavaScript, an attacker w= ill execute arbitrary JavaScript code. This vulnerability directly enables = stored XSS exploitation because the payload is persistently stored on your = infrastructure (app.typebot.io) and accessible from a public-facing, perman= ent link. Stored XSS via malicious SVG uploads to app.typebot.io allows att= ackers to execute arbitrary JavaScript in victims' browsers, enabling sessi= on/token theft, account takeover, and exfiltration of sensitive user data. = This issue has been fixed in version 3.16.0.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39970" target=3D= "_blank" rel=3D"noopener">CVE-2026-39970</a></td>

    <a href=3D"https://github.com/baptisteArno/typebot.io/security/advisories/G= HSA-jj87-c343-26vp" target=3D"_blank" rel=3D"noopener">https://github.com/b= aptisteArno/typebot.io/security/advisories/GHSA-jj87-c343-26vp</a><br><a hr= ef=3D"https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0" targ= et=3D"_blank" rel=3D"noopener">https://github.com/baptisteArno/typebot.io/r= eleases/tag/v3.16.0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Best Practical--Request Tracker</td>
    <td>Request Tracker is vulnerable to a reflected cross-site scripting (XSS)=
    vulnerability via the "Page" parameter in GET requests. An attacker can cr= aft a URL that, when opened, results in arbitrary JavaScript execution in t=
    he victim's browser. This vulnerability affects versions from 5.0.4 up to 5= .0.9 and from 6.0.0 up to=C2=A06.0.2.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6841" target=3D"= _blank" rel=3D"noopener">CVE-2026-6841</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-6841" target=3D"_blank=
    " rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-6841</a><br><a=
    href=3D"https://requesttracker.com/request-tracker/" target=3D"_blank" rel= =3D"noopener">https://requesttracker.com/request-tracker/</a><br><a href=3D= "https://docs.bestpractical.com/release-notes/rt/5.0.10" target=3D"_blank" = rel=3D"noopener">https://docs.bestpractical.com/release-notes/rt/5.0.10</a>= <br><a href=3D"https://docs.bestpractical.com/release-notes/rt/6.0.3" targe= t=3D"_blank" rel=3D"noopener">https://docs.bestpractical.com/release-notes/= rt/6.0.3</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">BillaBear--BillaBear</td>
    <td>BillaBear (all versions prior to Jan 2026) contains a SQL Injection vul= nerability in the EventRepository. User-controlled input from metric filter=
    names and aggregation properties is directly interpolated into SQL queries=
    using sprintf() without proper sanitization or identifier quoting. Althoug=
    h filter values are parameterized, the filter identifiers (keys) are not. A=
    n authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit = this to execute arbitrary SQL commands.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31069" target=3D= "_blank" rel=3D"noopener">CVE-2026-31069</a></td>

    <a href=3D"https://gist.github.com/nedlir/a50725b94650467f0593b8f4009ae19e"=
    target=3D"_blank" rel=3D"noopener">https://gist.github.com/nedlir/a50725b9= 4650467f0593b8f4009ae19e</a><br><a href=3D"https://github.com/BillaBear/bil= labear" target=3D"_blank" rel=3D"noopener">https://github.com/BillaBear/bil= labear</a><br><a href=3D"https://gist.github.com/nedlir/2377ba6e7fa2ad95721= 0b52aa8e400d9" target=3D"_blank" rel=3D"noopener">https://gist.github.com/n= edlir/2377ba6e7fa2ad957210b52aa8e400d9</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">brainstormforce--Surecart</td>
    <td>SureCart version prior to 4.2.1 are vulnerable to authenticated SQL inj= ection via multiple parameters ('model_name', 'model_id', 'integration_id',=
    'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'. The=
    root cause is a flawed escaping bypass in the query builder ('wp-query-bui= lder'). Values passed to the 'where()' method are only sanitized via '$wpdb= -&gt;prepare()' when they do **not** contain a dot ('.') or the WordPress t= able prefix ('wp_'). By including a dot anywhere in the payload, an attacke=
    r completely bypasses the escaping logic and injects arbitrary SQL into the=
    'WHERE' clause, allowing full UNION-based extraction of the database.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9065" target=3D"= _blank" rel=3D"noopener">CVE-2026-9065</a></td>

    <a href=3D"https://www.tenable.com/security/research/tra-2026-43" target=3D= "_blank" rel=3D"noopener">https://www.tenable.com/security/research/tra-202= 6-43</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Broadcom--Automic Automation</td>
    <td>Execution with unnecessary privileges vulnerability in Broadcom Automic=
    Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, = zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 allows Privilege Escal= ation, Target Programs with Elevated Privileges. This issue affects Automic=
    Automation: &lt; 24.4.4 HF1.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8370" target=3D"= _blank" rel=3D"noopener">CVE-2026-8370</a></td>

    <a href=3D"https://support.broadcom.com/web/ecx/support-content-notificatio= n/-/external/content/SecurityAdvisories/0/37512" target=3D"_blank" rel=3D"n= oopener">https://support.broadcom.com/web/ecx/support-content-notification/= -/external/content/SecurityAdvisories/0/37512</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">BYD--Atto3</td>
    <td>In BYD Atto3, an attacker can obtain an authentication key through Brut=
    e Force attack, which is permanently available. The authentication key enab= les flash to the Electronic Parking Break (EPB) and Supplemental Restoratio=
    n System (SRS) related ECUs.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-61081" target=3D= "_blank" rel=3D"noopener">CVE-2025-61081</a></td>

    <a href=3D"https://www.notion.so/BYD-Atto3-26215fb6156c8000b338db3c2011f637= ?source=3Dcopy_link" target=3D"_blank" rel=3D"noopener">https://www.notion.= so/BYD-Atto3-26215fb6156c8000b338db3c2011f637?source=3Dcopy_link</a><br><a = href=3D"https://www.notion.so/CVE-2025-61081-26215fb6156c8000b338db3c2011f6= 37" target=3D"_blank" rel=3D"noopener">https://www.notion.so/CVE-2025-61081= -26215fb6156c8000b338db3c2011f637</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Centralny Instytut Ochrony Pracy - Pastwowy In= stytut Badawczy--STER</td>
    <td>A SQL injection vulnerability has been identified in STER. Improper neu= tralization of input provided by user into multiple Search Filters allows f=
    or SQL Injection attacks. It allows an authenticated attacker to view sensi= tive data such as=C2=A0data belonging to other users, or any other data tha=
    t the application itself is able to access This issue was fixed in version = 9.5.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25606" target=3D= "_blank" rel=3D"noopener">CVE-2026-25606</a></td>

    <a href=3D"https://cert.pl/posts/2026/05/CVE-2026-25606" target=3D"_blank" = rel=3D"noopener">https://cert.pl/posts/2026/05/CVE-2026-25606</a><br><a hre= f=3D"https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pag= eLabel=3DP52000165211572544981480" target=3D"_blank" rel=3D"noopener">https= ://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pageLabel=3DP= 52000165211572544981480</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Centralny Instytut Ochrony Pracy - Pastwowy In= stytut Badawczy--STER</td>
    <td>Use of a weak password encoding algorithm in STER software allows the v= alue of the password to be guessed after analyzing how passwords with known=
    values are encoded. This issue was fixed in version 9.5.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25607" target=3D= "_blank" rel=3D"noopener">CVE-2026-25607</a></td>

    <a href=3D"https://cert.pl/posts/2026/05/CVE-2026-25606" target=3D"_blank" = rel=3D"noopener">https://cert.pl/posts/2026/05/CVE-2026-25606</a><br><a hre= f=3D"https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pag= eLabel=3DP52000165211572544981480" target=3D"_blank" rel=3D"noopener">https= ://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pageLabel=3DP= 52000165211572544981480</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Centralny Instytut Ochrony Pracy - Pastwowy In= stytut Badawczy--STER</td>
    <td>STER uses unencrypted TCP traffic to transmit data over the network. It=
    allows an attacker to=C2=A0conduct a Man-In-The-Middle attack and obtain s= ensitive data such as passwords, personal data, or authentication tokens. T= his issue was fixed in version 9.5.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25608" target=3D= "_blank" rel=3D"noopener">CVE-2026-25608</a></td>

    <a href=3D"https://cert.pl/posts/2026/05/CVE-2026-25606" target=3D"_blank" = rel=3D"noopener">https://cert.pl/posts/2026/05/CVE-2026-25606</a><br><a hre= f=3D"https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pag= eLabel=3DP52000165211572544981480" target=3D"_blank" rel=3D"noopener">https= ://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=3Dtrue&_pageLabel=3DP= 52000165211572544981480</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Chroma--ChromaDB</td>
    <td>A pre-authentication, code injection vulnerability in version 1.0.0 or = later of the ChromaDB Python project allows an unauthenticated attacker to = run arbitrary code on the server by sending a malicious model repository an=
    d trust_remote_code set to true in the=C2=A0/api/v2/tenants/{tenant}/databa= ses/{db}/collections endpoint.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45829" target=3D= "_blank" rel=3D"noopener">CVE-2026-45829</a></td>

    <a href=3D"https://www.hiddenlayer.com/research/chromatoast-served-pre-auth=
    " target=3D"_blank" rel=3D"noopener">https://www.hiddenlayer.com/research/c= hromatoast-served-pre-auth</a><br><a href=3D"https://github.com/chroma-core= /chroma/issues/6717" target=3D"_blank" rel=3D"noopener">https://github.com/= chroma-core/chroma/issues/6717</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ClipBucket--ClipBucket v5 v.5.5.2</td>
    <td>An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitra=
    ry code via the Authentication interface, login page endpoint and HTTP resp= onse security headers components</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-37470" target=3D= "_blank" rel=3D"noopener">CVE-2026-37470</a></td>

    <a href=3D"http://clipbucket.com" target=3D"_blank" rel=3D"noopener">http:/= /clipbucket.com</a><br><a href=3D"https://medium.com/@arpit03sharma2003/cve= -2026-37470-clickjacking-vulnerability-in-clipbucket-v5-leads-to-credential= -theft-and-8415def7804a" target=3D"_blank" rel=3D"noopener">https://medium.= com/@arpit03sharma2003/cve-2026-37470-clickjacking-vulnerability-in-clipbuc= ket-v5-leads-to-credential-theft-and-8415def7804a</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">CODESYS--Visualization</td>
    <td>The affected product may expose credentials remotely between low privil= eged visualization users during concurrent login operations due to insuffic= ient isolation of authentication data. The vulnerability affects only login=
    operations within an active visualization session.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-0393" target=3D"= _blank" rel=3D"noopener">CVE-2026-0393</a></td>

    <a href=3D"https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/= advisory2026-07_vde-2026-052.json" target=3D"_blank" rel=3D"noopener">https= ://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-07_= vde-2026-052.json</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below=C2=A0 is vulnerable to=C2=A0unauthenticate=
    d file usage disclosure via missing permission check in the usage controlle= r.=C2=A0=C2=A0Any unauthenticated visitor can request /ccm/system/dialogs/f= ile/usage/{fID} with any file ID and receive a list of every page that refe= rences that file, including page IDs, handles, and full URLs. This includes=
    pages that are otherwise restricted by permissions.The Concrete CMS securi=
    ty team gave this vulnerability a CVSS v.4.0 score of 6.9 with vector=C2=A0= CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eld= udareeno=C2=A0for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6826" target=3D"= _blank" rel=3D"noopener">CVE-2026-6826</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>In Concrete CMS 9.5.0 and below,=C2=A0 the submit_password() method in = concrete/controllers/single_page/download_file.php allows unauthorized file=
    access since downloading permission-restricted files bypasses the view_fil=
    e permission check.=C2=A0Files without passwords can be downloaded and any = user who knows a file's password can download a password protected file reg= ardless of whether they have permission to access the file.=C2=A0The Concre=
    te CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with=
    vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:= N.=C2=A0 Thanks=C2=A0Youssef Eid for reporting</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7879" target=3D"= _blank" rel=3D"noopener">CVE-2026-7879</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is subject to=C2=A0Insecure Direct Object = Reference=C2=A0(IDOR) in the Express Entry Detail block via the exEntryID p= arameter. This IDOR leads to unauthorized access to all Express form submis= sions.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS v= .4.0 score of 6.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/V= I:N/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Tristan Madani for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7881" target=3D"= _blank" rel=3D"noopener">CVE-2026-7881</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletio=
    n due to an Inverted CSRF token check in the DeleteFile controller.=C2=A0Th=
    e code throws an error when the token IS valid and proceeds with file delet= ion when the token is invalid or missing. This effectively disables CSRF pr= otection for the file deletion endpoint, allowing cross-site request forger=
    y attacks against users who have permission to edit conversation messages.= =C2=A0The Concrete CMS security team gave this vulnerability a CVSS v.4.0 s= core of=C2=A02.3 with a vector of=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC= :N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Mandani for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7882" target=3D"= _blank" rel=3D"noopener">CVE-2026-7882</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to=C2=A0IDOR in AddMessage/U= pdateMessage via attachments[] parameter which can lead to file permission = bypass.=C2=A0The `AddMessage` and `UpdateMessage` conversation controllers = accept user-supplied file attachment IDs and load files directly via `$em-&= gt;find(File::class, $attachmentID)` without checking per-file permissions = (`canViewFile()`). A user who can post in any conversation can reference an=
    y file in the CMS file manager by its sequential ID, effectively bypassing = the file permission system.=C2=A0 The Concrete CMS security team gave this = vulnerability a CVSS v.4.0 score of=C2=A02.3 with a vector=C2=A0CVSS:4.0/AV= :N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N.=C2=A0Thanks Tristan M= andani for reporting.=C2=A0if a site truly has private files, the owner sho= uld set up a private storage location https://documentation.concretecms.org= /user-guide/editors-reference/dashboard/system-and-maintenance/files/file-s= torage-locations outside of the webroot so that permissions can be checked =
    on view as well. That way, even if a authorized user attaches a file, or ot= herwise links to it, unauthorized users won't be able to view the file.</td=

    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7886" target=3D"= _blank" rel=3D"noopener">CVE-2026-7886</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler = Bypasses Account Status. A=C2=A0user with uIsActive=3D0 (suspended, banned,=
    terminated employee) can still authenticate via OAuth and receive valid AP=
    I tokens.=C2=A0The Concrete CMS security team gave this vulnerability a CVS=
    S v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:= L/VI:L/VA:N/SC:L/SI:L/SA:N. Thanks=C2=A00x4c616e for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7887" target=3D"= _blank" rel=3D"noopener">CVE-2026-7887</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed=
    URL from any page editor and fetches it server-side without validation=C2= =A0enabling redirect-to-internal bypasses.=C2=A0=C2=A0The Concrete CMS secu= rity team gave this vulnerability a CVSS v.4.0 score of=C2=A02.1 with a vec= tor=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N.</=

    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7890" target=3D"= _blank" rel=3D"noopener">CVE-2026-7890</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences=
    in the ptComposerFormLayoutSetControlCustomTemplate field when saving page=
    type composer form layouts. An authenticated rogue administrator with comp= oser form editing rights can exploit this to include arbitrary readable fil=
    es on the server. Combined with the file uploader's extension-only validati=
    on (which permits PHP code in files saved with image extensions like .png),=
    this can result in=C2=A0authenticated remote code execution.=C2=A0The Conc= rete CMS security team gave this vulnerability a CVSS v.4.0 score of 9.4 wi=
    th vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/S= A:H=C2=A0 =C2=A0Thanks=C2=A0Yonatan Drori=C2=A0(Tenzai)=C2=A0for reporting.= </td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8134" target=3D"= _blank" rel=3D"noopener">CVE-2026-8134</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due=
    to insecure deserialization occurring in the=C2=A0ExpressEntryList=C2=A0bl= ock controller. An rogue administrator with privileges to add blocks to an = area can bypass the intended protection mechanism (_fromCIF =3D=3D=3D true)=
    , which normally restricts malicious inputs over form POST requests, by lev= eraging the REST API functionality. Because the REST API parses requests us= ing json_decode(), the string "true" is evaluated as a strict PHP Boolean(t= rue).=C2=A0 This bypass allows the attacker to inject a malicious serialize=
    d payload =C2=A0into the block's filterFields database column. The payload = will subsequently be executed when the block's data is viewed or edited by =
    an administrator leading to complete server takeover (RCE).The Concrete CMS=
    security team gave this vulnerability a CVSS v.4.0 score of 8.9 with a vec= tor of=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H= .=C2=A0 Thanks Nguy=C3=A1=C2=BB=E2=80=A6n V=C3=84=C6=92n Thi=C3=A1=C2=BB=E2= =80=A1n https://github.com/Thien225409 =C2=A0for reporting</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8135" target=3D"= _blank" rel=3D"noopener">CVE-2026-8135</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-l= ink page cvName because updateCollectionAliasExternal bypasses being saniti= zed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sc= ore of 2.0 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:= N/SC:N/SI:N/SA:N.=C2=A0 Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</=

    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8139" target=3D"= _blank" rel=3D"noopener">CVE-2026-8139</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below does not validate a CSRF token before proc= essing requests to /dashboard/extend/install/download/&lt;remoteId&gt;. The=
    download() method in concrete/controllers/single_page/dashboard/extend/ins= tall.php checks only the canInstallPackages() permission before fetching a = remote marketplace package and writing it to the server's DIR_PACKAGES dire= ctory. Because the endpoint is a state-changing GET route with no token enf= orcement, an attacker who can cause an authenticated administrator to visit=
    a crafted page can force an arbitrary marketplace package to be downloaded=
    . In order to be vulnerable, the victim must be passing canInstallPackages(=
    ) and the site must be connected to the Concrete marketplace.=C2=A0The Conc= rete CMS security team gave this vulnerability a CVSS v.4.0 score of=C2=A07=
    .5 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/S= I:N/SA:N. Thanks=C2=A0 https://github.com/maru1009 =C2=A0for reporting.</td=

    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8140" target=3D"= _blank" rel=3D"noopener">CVE-2026-8140</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth inte= gration name. The OAuth authorize template renders the integration name (ad= min-controlled) through Concrete's t() translation helper as a sprintf-styl=
    e format. The &lt;strong&gt;...&lt;/strong&gt; wrap is built by PHP string = interpolation before t() runs, so the integration name lands in the transla= ted output as raw HTML. A rogue admin could potentially snoop on login subm= issions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0=
    score of=C2=A07.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/= VI:H/VA:H/SC:N/SI:N/SA:N=C2=A0 Thanks Yonatan Drori (Tenzai) for reporting.= </td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8197" target=3D"= _blank" rel=3D"noopener">CVE-2026-8197</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below has Stored XSS on the height parameter.=C2= =A0The controller does not validate or sanitize $height.=C2=A0Any user with=
    editor privileges can inject malicious JavaScript that executes in the con= text of any visitor's browser, potentially leading to session hijacking, cr= edential theft, or other malicious actions.=C2=A0The Concrete CMS security = team gave this vulnerability a CVSS v.4.0 score of=C2=A07.3 with vector=C2= =A0CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks= =C2=A0Alfin Joseph for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8203" target=3D"= _blank" rel=3D"noopener">CVE-2026-8203</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in t=
    he Calendar Event Frontend Dialog which can allow cross-calendar data discl= osure. A public calendar block can be used as a pivot point to access priva=
    te calendar data. The Concrete CMS security team gave this vulnerability a = CVSS v.4.0 score of=C2=A06.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/= UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Winston Crooker for reporti= ng.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8204" target=3D"= _blank" rel=3D"noopener">CVE-2026-8204</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in t=
    he Calendar Block since action_get_events does not check canView on the cal= endar=C2=A0which results in restricted event details being disclosed.=C2=A0= The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score o= f=C2=A06.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:= N/SC:N/SI:N/SA:N. Thanks lalalala5678 for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8205" target=3D"= _blank" rel=3D"noopener">CVE-2026-8205</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a miss= ing authentication gate. The endpoint=C2=A0/ccm/system/dialogs/file/usage/{= fID}=C2=A0accepts an integer file ID in the URL and returns internal site s= tructure data (page IDs, versions, URL paths) to anyone who sends a GET req= uest. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 s= core of=C2=A06.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI= :N/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Winston Crooker for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8236" target=3D"= _blank" rel=3D"noopener">CVE-2026-8236</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to IDOR.=C2=A0The `/ccm/fron= tend/conversations/message_detail` endpoint returns the full content of any=
    conversation message. An unauthenticated attacker can enumerate all conver= sation messages, including messages from restricted pages, member-only area=
    s, and the moderation queue. File attachments with download URLs are also e= xposed.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS = v.4.0 score of=C2=A06.3 with Vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/= VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8237" target=3D"= _blank" rel=3D"noopener">CVE-2026-8237</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to IDOR.=C2=A0The=C2=A0'/ccm= /frontend/conversations/message_page'=C2=A0endpoint returns the full conten=
    t of any conversation message. An unauthenticated attacker can enumerate al=
    l conversation messages, including messages from restricted pages, member-o= nly areas, and the moderation queue. File attachments with download URLs ar=
    e also exposed.=C2=A0The Concrete CMS security team gave this vulnerability=
    a CVSS v.4.0 score of=C2=A06.3 with Vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR= :N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.= </td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8238" target=3D"= _blank" rel=3D"noopener">CVE-2026-8238</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to IDOR.=C2=A0The=C2=A0'/ccm= /frontend/conversations/get_rating'=C2=A0endpoint confirms existence and re= turns rating score for any message by ID.=C2=A0The Concrete CMS security te=
    am gave this vulnerability a CVSS v.4.0 score of=C2=A06.3 with Vector=C2=A0= CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tri= stan Madani for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8239" target=3D"= _blank" rel=3D"noopener">CVE-2026-8239</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is=C2=A0vulnerable to unauthenticated page=
    metadata disclosure across every page with a configured summary template, = revealing the existence of private, draft, and restricted pages while leaki=
    ng title, path, description, and author information.=C2=A0The Concrete CMS = security team gave this vulnerability a CVSS v.4.0 score of=C2=A06.3 with v= ector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N.=
    Thanks=C2=A0Winston Crooker for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8240" target=3D"= _blank" rel=3D"noopener">CVE-2026-8240</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy P= agination via HTML attribute injection.=C2=A0Concrete\Core\Legacy\Paginatio=
    n builds pagination links by raw-interpolating its $URL field into href=3D"=
    " (&lt;a href=3D"{$linkURL}" =C3=A2=E2=82=AC=C2=A6&gt;).=C2=A0Any authentic= ated admin or report viewer with access to `/dashboard/reports/forms/legacy=
    ` who clicks the crafted URL fires the payload in their session.=C2=A0The C= oncrete CMS security team gave this vulnerability a CVSS v.4.0 score of=C2= =A06.0 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC= :N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8245" target=3D"= _blank" rel=3D"noopener">CVE-2026-8245</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS below 9.5.0 and below is vulnerable to password change wit= hout reauthorization and session-hardening bypass.=C2=A0The user-profile ed=
    it controller passes the entire raw POST array to UserInfo::update() withou=
    t field whitelisting resulting in password change without requiring the cur= rent password=C2=A0 and also resulting in registered users able to disable = the per-user-IP-pinning in the session validator which is meant to detect h= ijacking.=C2=A0=C2=A0The Concrete CMS security team gave this vulnerability=
    a CVSS v.4.0 score of 5.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI= :N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A00x4c616e for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8327" target=3D"= _blank" rel=3D"noopener">CVE-2026-8327</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys.=C2=A0To =
    be vulnerable, a=C2=A0site would have to be configured in such a way that b= oth public and private surveys are present on the site. An=C2=A0unauthentic= ated attacker can vote in the restricted survey by submitting the restricte=
    d optionID through the public survey's endpoint.=C2=A0The Concrete CMS secu= rity team gave this vulnerability a CVSS v.4.0 score of=C2=A06.3 with vecto= r=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Tha= nks=C2=A0 Zer0daySec https://github.com/Zee99y =C2=A0for reporting</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8337" target=3D"= _blank" rel=3D"noopener">CVE-2026-8337</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::ap= proveVersion.=C2=A0Victim with=C2=A0edit_file_contents=C2=A0permission is C= SRF'd into publishing an attacker-chosen previously-uploaded version (downg= rade to an older version of a file, or activation of a co-editor's unpublis= hed version).=C2=A0The Concrete CMS security team gave this vulnerability a=
    CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P= /VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8340" target=3D"= _blank" rel=3D"noopener">CVE-2026-8340</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorizatio= n-level in the Express association Reorder dialog.=C2=A0 This can cause=C2= =A0Cross-entity state tampering=C2=A0with view-only permission on one entry= .=C2=A0To be affected, a website has to be using express and relying on exp= ress entity ordering.=C2=A0The Concrete CMS security team gave this vulnera= bility a CVSS v.4.0 score of 2.3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/P= R:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reportin= g.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8347" target=3D"= _blank" rel=3D"noopener">CVE-2026-8347</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below is vulnerable to missing authorization in = the bulk_user_assignment.php which can lead to privilege escalation=C2=A0to=
    Administrative Group.=C2=A0Any authenticated user with access to the bulk = user assignment dashboard page can add any user email to any group and can = remove legitimate admins.=C2=A0The Concrete CMS security team gave this vul= nerability a CVSS v.4.0 score of 7.5 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT= :P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0Vincent55 for repor= ting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8350" target=3D"= _blank" rel=3D"noopener">CVE-2026-8350</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page = name in the Atomik theme. A rogue editor=C2=A0can inject arbitrary JavaScri=
    pt that executes in the context of any authenticated user visiting the affe= cted account pages. This can lead to session hijacking, credential theft, m= alicious actions performed on behalf of users, and potential privilege esca= lation.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS = v.4.0 score of=C2=A02.1 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/= VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for repor= ting.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8353" target=3D"= _blank" rel=3D"noopener">CVE-2026-8353</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/logs/delete.=C2=A0 The The Concrete = CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with ve= ctor=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. = Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8409" target=3D"= _blank" rel=3D"noopener">CVE-2026-8409</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/logs/bulk/delete.=C2=A0 The The Conc= rete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 wi=
    th vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/S= A:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8410" target=3D"= _blank" rel=3D"noopener">CVE-2026-8410</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS s= ecurity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector= =C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Than= ks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8411" target=3D"= _blank" rel=3D"noopener">CVE-2026-8411</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS se= curity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector= =C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Than= ks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8412" target=3D"= _blank" rel=3D"noopener">CVE-2026-8412</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS s= ecurity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector= =C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Than= ks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8413" target=3D"= _blank" rel=3D"noopener">CVE-2026-8413</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS se= curity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector= =C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Than= ks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8414" target=3D"= _blank" rel=3D"noopener">CVE-2026-8414</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/dialog/express/association/reorder. The Con= crete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 w= ith vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/= SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8415" target=3D"= _blank" rel=3D"noopener">CVE-2026-8415</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Co= ncrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 = with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N= /SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8416" target=3D"= _blank" rel=3D"noopener">CVE-2026-8416</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below does not validate a CSRF token before proc= essing requests to /dashboard/extend/update/do_update/&lt;pkgHandle&gt;. Th=
    e do_update() method in concrete/controllers/single_page/dashboard/extend/u= pdate.php checks only canInstallPackages() before executing upgradeCoreData=
    () and upgrade() on the named package's controller. Because the endpoint is=
    a state-changing GET route with no token enforcement, an attacker can forc=
    e an authenticated administrator to trigger a package upgrade via a single = cross-site navigation.In order to be vulnerable, the victim must be passing=
    canInstallPackages() and and a target package must already be already inst= alled.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS v= .4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/V= C:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0 https://github.com/maru1009 =C2= =A0for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8417" target=3D"= _blank" rel=3D"noopener">CVE-2026-8417</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the insta= ll_package() method of concrete/controllers/single_page/dashboard/extend/in= stall.php. =C2=A0An attacker who can cause an authenticated administrator t=
    o visit a crafted page,=C2=A0 and who has placed or caused a package to be = present under DIR_PACKAGES/&lt;handle&gt;/, can force the installation of t= hat package without any CSRF protection. Package installation executes the = package controller's install() method as the web server user, enabling remo=
    te code execution.=C2=A0=C2=A0In order to be vulnerable, the victim must be=
    passing canInstallPackages.=C2=A0The Concrete CMS security team gave this = vulnerability a CVSS v.4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV:N= /AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0 https://gi= thub.com/maru1009 =C2=A0for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8421" target=3D"= _blank" rel=3D"noopener">CVE-2026-8421</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below does not validate a CSRF token before proc= essing requests to /dashboard/extend/update/prepare_remote_upgrade/&lt;remo= teMPID&gt;. An attacker who controls the remote package returned for a know=
    n marketplace item ID can overwrite the package PHP on disk and force its u= pgrade() method to execute in a single browser navigation. This results in = remote code execution as the web server user.=C2=A0=C2=A0=C2=A0In order to =
    be vulnerable, the victim must be passing canInstallPackages,=C2=A0victim s= ite must be connected to the Concrete marketplace; and the attacker control=
    s the package returned for a marketplace item ID already installed on the v= ictim site.=C2=A0The Concrete CMS security team gave this vulnerability a C= VSS v.4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/U= I:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0https://github.com/maru1009= =C2=A0for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8426" target=3D"= _blank" rel=3D"noopener">CVE-2026-8426</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The=
    Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2=
    .3 with vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/S= I:N/SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8427" target=3D"= _blank" rel=3D"noopener">CVE-2026-8427</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_= update.php view ($token-&gt;output('do_update')) but the corresponding do_u= pdate() method in concrete/controllers/single_page/dashboard/system/update/= update.php never calls $this-&gt;token-&gt;validate('do_update'). The form =
    is rendered as a POST form, meaning the token reaches the browser, but beca= use the controller discards it without verification, an attacker can craft =
    a cross-site POST that triggers a core CMS update to an attacker-specified = version string.=C2=A0=C2=A0In order to be vulnerable, theictim must be pass= ing canUpgrade()anda valid update version must be present under DIR_CORE_UP= DATES.=C2=A0The Concrete CMS security team gave this vulnerability a CVSS v= .4.0 score of=C2=A07.5 with vector=C2=A0CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/V= C:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks=C2=A0https://github.com/maru1009=C2=A0= for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8428" target=3D"= _blank" rel=3D"noopener">CVE-2026-8428</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS secur= ity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector=C2= =A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks= =C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8432" target=3D"= _blank" rel=3D"noopener">CVE-2026-8432</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS sec= urity team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector=C2= =A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks= =C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8433" target=3D"= _blank" rel=3D"noopener">CVE-2026-8433</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete=
    CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with v= ector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.=
    Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8434" target=3D"= _blank" rel=3D"noopener">CVE-2026-8434</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Concrete CMS--Concrete CMS</td>
    <td>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery=
    (CSRF) at concrete/controllers/backend/file approveVersion().=C2=A0The Con= crete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 w= ith vector=C2=A0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/= SA:N. Thanks=C2=A0Yonatan Drori (Tenzai) for reporting.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8435" target=3D"= _blank" rel=3D"noopener">CVE-2026-8435</a></td>

    <a href=3D"https://documentation.concretecms.org/9-x/developers/introductio= n/version-history/951-release-notes" target=3D"_blank" rel=3D"noopener">htt= ps://documentation.concretecms.org/9-x/developers/introduction/version-hist= ory/951-release-notes</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Creartia Internet Consulting--ICMS Content Man= agement</td>
    <td>Authorization Bypass vulnerability in Creartia's ICMS software could al= low an attacker to gain unauthorized access to protected features by manipu= lating the HTTP redirect headers of the login process, causing the script t=
    o continue running and enabling privilege escalation without the need for c= redentials.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4320" target=3D"= _blank" rel=3D"noopener">CVE-2026-4320</a></td>

    <a href=3D"https://www.incibe.es/en/incibe-cert/notices/aviso/authorization= -bypass-icms-content-management-creartia-internet-consulting" target=3D"_bl= ank" rel=3D"noopener">https://www.incibe.es/en/incibe-cert/notices/aviso/au= thorization-bypass-icms-content-management-creartia-internet-consulting</a>= <br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">cyntler--react-doc-viewer v1.17.1</td> <td>Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v= 1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafte=
    d .txt file. The TXTRenderer component fails to sanitize file content and e= xplicitly casts raw data as a ReactNode</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-30691" target=3D= "_blank" rel=3D"noopener">CVE-2026-30691</a></td>

    <a href=3D"https://github.com/cyntler/react-doc-viewer/issues/317" target= =3D"_blank" rel=3D"noopener">https://github.com/cyntler/react-doc-viewer/is= sues/317</a><br><a href=3D"https://github.com/walidriouah/CVE-2026-30691" t= arget=3D"_blank" rel=3D"noopener">https://github.com/walidriouah/CVE-2026-3= 0691</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Dell--Portrait Dell Color Management Applicati= on</td>
    <td>An issue was discovered in the Portrait Dell Color Management applicati=
    on before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerabilit=
    y allows a local low-privileged user to escalate privileges to Administrato=
    r. During installation, the software writes the file CCFLFamily_07Feb11.edr=
    to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with eleva= ted privileges. Because the installer does not properly validate symbolic l= inks or reparse points at the destination path, an attacker can create a ma= licious link that redirects the write operation to an arbitrary system loca= tion, enabling arbitrary file creation or overwrite with elevated privilege= s.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34883" target=3D= "_blank" rel=3D"noopener">CVE-2026-34883</a></td>

    <a href=3D"https://www.portrait.com/dell-security-cve-updates/" target=3D"_= blank" rel=3D"noopener">https://www.portrait.com/dell-security-cve-updates/= </a><br><a href=3D"https://www.portrait.com/dell" target=3D"_blank" rel=3D"= noopener">https://www.portrait.com/dell</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Improper access control in the entry activity log feature in Devolution=
    s Server allows an authenticated user with access to an entry but without t=
    he required permission to retrieve that entry's activity logs via a crafted=
    API request. This issue affects : * Devolutions Server 2026.1.6.0 through = 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5171" target=3D"= _blank" rel=3D"noopener">CVE-2026-5171</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Improper authorization in the Active Directory browsing feature in Devo= lutions Server allows a low-privileged authenticated user to obtain authent= ication material associated with a stored PAM provider service account via = authentication relay to an attacker-controlled server. This issue affects :=
    * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2= 025.3.20.0 and earlier</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7325" target=3D"= _blank" rel=3D"noopener">CVE-2026-7325</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Improper enforcement of the sealed-entry workflow in the entry sensitiv= e-data retrieval feature in Devolutions Server allows an authenticated user=
    with access to a sealed entry to retrieve its sensitive data without trigg= ering the unseal audit notification via a crafted API request. This issue a= ffects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions = Server 2025.3.20.0 and earlier</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8477" target=3D"= _blank" rel=3D"noopener">CVE-2026-8477</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Improper handling of factor key state in the multi-factor authenticatio=
    n management feature in Devolutions Server allows an attacker with knowledg=
    e of a user's password to bypass the user's multi-factor authentication aft=
    er the user reconfigures their factors. This issue affects : * Devolutions = Server 2026.1.6.0 through 2026.1.16.0</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9047" target=3D"= _blank" rel=3D"noopener">CVE-2026-9047</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Missing authorization in the vault import feature in Devolutions Server= =C2=A0=C2=A02026.1.16.0 and earlier allows a low-privileged authenticated u= ser to create new vaults via a crafted import request.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9223" target=3D"= _blank" rel=3D"noopener">CVE-2026-9223</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Missing authorization in the user profile update feature in Devolutions=
    Server allows an authenticated Active Directory user to modify their own p= rofile attributes via a crafted API request. This issue affects : * Devolut= ions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0=
    and earlier</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9224" target=3D"= _blank" rel=3D"noopener">CVE-2026-9224</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Improper input validation in the external authentication provider flow =
    in Devolutions Server allows an unauthenticated remote attacker to redirect=
    victims to an attacker-controlled domain via a crafted login link. This is= sue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolut= ions Server 2025.3.20.0 and earlier</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9245" target=3D"= _blank" rel=3D"noopener">CVE-2026-9245</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Improper access control in the entry documentation and attachment featu= res in Devolutions Server allows an authenticated user with vault read acce=
    ss to retrieve the documentation and attachments of sealed entries via a cr= afted API request. This issue affects : * Devolutions Server 2026.1.6.0 thr= ough 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9246" target=3D"= _blank" rel=3D"noopener">CVE-2026-9246</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Insufficient logging in the entry export feature in Devolutions Server = allows an authenticated user with export permissions to export a sealed ent=
    ry without triggering the unseal notification to administrators via a craft=
    ed export request. This issue affects : * Devolutions Server 2026.1.6.0 thr= ough 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9247" target=3D"= _blank" rel=3D"noopener">CVE-2026-9247</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Authorization bypass in the entry duplication feature in Devolutions Se= rver allows an authenticated user with write access to any vault to copy do= cumentation and attachments from an entry in a vault they cannot access via=
    a crafted save request. This issue affects : * Devolutions Server 2026.1.6=
    .0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9248" target=3D"= _blank" rel=3D"noopener">CVE-2026-9248</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Unverified password change in Devolutions Server allows an attacker to = change a user's password without providing the previous one via a crafted p= assword change request. This issue affects : * Devolutions Server 2026.1.6.=
    0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9249" target=3D"= _blank" rel=3D"noopener">CVE-2026-9249</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Devolutions--Server</td>
    <td>Missing authorization in the entry status management feature in Devolut= ions Server allows a non-administrator authenticated user to bypass the adm= inistrator-enforced Pending Approval flow and gain access to an entry's dat=
    a via a crafted status change request. This issue affects : * Devolutions S= erver 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and e= arlier</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9251" target=3D"= _blank" rel=3D"noopener">CVE-2026-9251</a></td>

    <a href=3D"https://devolutions.net/security/advisories/DEVO-2026-0013/" tar= get=3D"_blank" rel=3D"noopener">https://devolutions.net/security/advisories= /DEVO-2026-0013/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">discourse--discourse</td>
    <td>Discourse is an open-source discussion platform. In versions prior to 2= 026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on=
    a Discourse instance with the form templates feature enabled can read the = name and structured content of form templates that are intended exclusively=
    for categories they are not authorized to access. Impact is limited to dis= closure of site configuration metadata. This issue has been fixed in versio=
    ns 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33514" target=3D= "_blank" rel=3D"noopener">CVE-2026-33514</a></td>

    <a href=3D"https://github.com/discourse/discourse/security/advisories/GHSA-= w6g7-p2p9-2m5h" target=3D"_blank" rel=3D"noopener">https://github.com/disco= urse/discourse/security/advisories/GHSA-w6g7-p2p9-2m5h</a><br><a href=3D"ht= tps://github.com/discourse/discourse/commit/ae5c9570fb918442c4d96abc83c1e7e= 169909b02" target=3D"_blank" rel=3D"noopener">https://github.com/discourse/= discourse/commit/ae5c9570fb918442c4d96abc83c1e7e169909b02</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">discourse--discourse</td>
    <td>Discourse is an open-source discussion platform. In versions prior to 2= 026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the d= iscourse-subscriptions plugin allows users to gain access to subscription-g= ated groups without completing payment. This issue has been fixed in versio=
    ns 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34154" target=3D= "_blank" rel=3D"noopener">CVE-2026-34154</a></td>

    <a href=3D"https://github.com/discourse/discourse/security/advisories/GHSA-= pjgj-7mjq-6j7g" target=3D"_blank" rel=3D"noopener">https://github.com/disco= urse/discourse/security/advisories/GHSA-pjgj-7mjq-6j7g</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drupal--Colorbox Inline</td>
    <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
    e Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scr= ipting (XSS). This issue affects Colorbox Inline: from 0.0.0 before 2.1.1.<=

    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8493" target=3D"= _blank" rel=3D"noopener">CVE-2026-8493</a></td>

    <a href=3D"https://www.drupal.org/sa-contrib-2026-036" target=3D"_blank" re= l=3D"noopener">https://www.drupal.org/sa-contrib-2026-036</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Drupal--Date iCal</td>
    <td>Missing Authorization vulnerability in Drupal Date iCal allows Forceful=
    Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8495" target=3D"= _blank" rel=3D"noopener">CVE-2026-8495</a></td>

    <a href=3D"https://www.drupal.org/sa-contrib-2026-037" target=3D"_blank" re= l=3D"noopener">https://www.drupal.org/sa-contrib-2026-037</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Drupal--Drupal core</td>
    <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
    e Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripti=
    ng (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10= .6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.<=

    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6365" target=3D"= _blank" rel=3D"noopener">CVE-2026-6365</a></td>

    <a href=3D"https://www.drupal.org/sa-core-2026-001" target=3D"_blank" rel= =3D"noopener">https://www.drupal.org/sa-core-2026-001</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drupal--Drupal core</td>
    <td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Drupal core allows Object Injection. This i= ssue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6= .7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6366" target=3D"= _blank" rel=3D"noopener">CVE-2026-6366</a></td>

    <a href=3D"https://www.drupal.org/sa-core-2026-002" target=3D"_blank" rel= =3D"noopener">https://www.drupal.org/sa-core-2026-002</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drupal--Drupal core</td>
    <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
    e Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripti=
    ng (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6367" target=3D"= _blank" rel=3D"noopener">CVE-2026-6367</a></td>

    <a href=3D"https://www.drupal.org/sa-core-2026-003" target=3D"_blank" rel= =3D"noopener">https://www.drupal.org/sa-core-2026-003</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drupal--Node View Permissions</td>
    <td>Improper Check for Unusual or Exceptional Conditions vulnerability in D= rupal Node View Permissions allows Forceful Browsing. This issue affects No=
    de View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8491" target=3D"= _blank" rel=3D"noopener">CVE-2026-8491</a></td>

    <a href=3D"https://www.drupal.org/sa-contrib-2026-034" target=3D"_blank" re= l=3D"noopener">https://www.drupal.org/sa-contrib-2026-034</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Drupal--Obfuscate</td>
    <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
    e Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting=
    (XSS). This issue affects Obfuscate: from 0.0.0 before 2.0.2.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6871" target=3D"= _blank" rel=3D"noopener">CVE-2026-6871</a></td>

    <a href=3D"https://www.drupal.org/sa-contrib-2026-033" target=3D"_blank" re= l=3D"noopener">https://www.drupal.org/sa-contrib-2026-033</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Drupal--Orejime</td>
    <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
    e Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (= XSS). This issue affects Orejime: from 0.0.0 before 2.0.16.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6095" target=3D"= _blank" rel=3D"noopener">CVE-2026-6095</a></td>

    <a href=3D"https://www.drupal.org/sa-contrib-2026-032" target=3D"_blank" re= l=3D"noopener">https://www.drupal.org/sa-contrib-2026-032</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Drupal--Simple Hierarchical Select (shs)</td> <td>Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scrip= ting risk due to improper output escaping of term-derived text. Confirmed a= ffected paths include field formatter output (shs_field_formatter_view) and=
    term-tree child-term data generation (shs_term_get_children). Malicious ta= xonomy term names can be rendered unsafely depending on output context. Thi=
    s affects versions from 7.x-1.0 through (and including) 7.x-1.10.</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4929" target=3D"= _blank" rel=3D"noopener">CVE-2026-4929</a></td>

    <a href=3D"https://www.herodevs.com/vulnerability-directory/cve-2026-4929" = target=3D"_blank" rel=3D"noopener">NES patch branch comparison</a><br><a hr= ef=3D"https://d7es.tag1.com/security-advisories/simple-hierarchical-select-= moderately-critical-cross-site-scripting" target=3D"_blank" rel=3D"noopener= ">https://d7es.tag1.com/security-advisories/simple-hierarchical-select-mode= rately-critical-cross-site-scripting</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drupal--Term Reference Tree</td>
    <td>In the Drupal 7 Term Reference Tree module, two stored XSS vectors exis=
    t in the widget/formatter rendering pipeline. Vector A (token display templ= ates): When the Token module is enabled and token display templates are con= figured, attacker-controlled token output (e.g., term description) is rende= red without proper sanitization. Any user who can edit the referenced taxon= omy terms can inject HTML/JS that executes when the field is rendered. Vect=
    or B (term label rendering): Taxonomy term labels are not properly sanitize=
    d before being rendered in the widget, allowing a user with permission to c= reate or edit taxonomy terms to inject scripts into the term name that exec= ute when a form containing the widget is viewed. Exploit affects versions 7= .x-1.x up to and including 7.x-1.11.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4093" target=3D"= _blank" rel=3D"noopener">CVE-2026-4093</a></td>

    <a href=3D"https://www.herodevs.com/vulnerability-directory/cve-2026-4093" = target=3D"_blank" rel=3D"noopener">https://www.herodevs.com/vulnerability-d= irectory/cve-2026-4093</a><br><a href=3D"https://d7es.tag1.com/security-adv= isories/taxonomy-term-reference-tree-widget-moderately-critical-cross-site-= scripting" target=3D"_blank" rel=3D"noopener">https://d7es.tag1.com/securit= y-advisories/taxonomy-term-reference-tree-widget-moderately-critical-cross-= site-scripting</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drupal--Translate Drupal with GTranslate</td> <td>Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal T= ranslate Drupal with GTranslate allows Resource Location Spoofing. This iss=
    ue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8492" target=3D"= _blank" rel=3D"noopener">CVE-2026-8492</a></td>

    <a href=3D"https://www.drupal.org/sa-contrib-2026-035" target=3D"_blank" re= l=3D"noopener">https://www.drupal.org/sa-contrib-2026-035</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Easy Chat--Easy Chat Server 3.1</td>
    <td>Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remo=
    te attacker to obtain sensitive information and execute arbitrary code via = the UserName parameter</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36227" target=3D= "_blank" rel=3D"noopener">CVE-2026-36227</a></td>

    <a href=3D"http://easy.com" target=3D"_blank" rel=3D"noopener">http://easy.= com</a><br><a href=3D"https://github.com/NullByte8080/CVE-2026-36227" targe= t=3D"_blank" rel=3D"noopener">https://github.com/NullByte8080/CVE-2026-3622= 7</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Easy Chat--Easy Chat Server 3.1</td>
    <td>Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote a= ttacker to obtain sensitive information and execute arbitrary code via the = chat message functionality</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36228" target=3D= "_blank" rel=3D"noopener">CVE-2026-36228</a></td>

    <a href=3D"http://easy.com" target=3D"_blank" rel=3D"noopener">http://easy.= com</a><br><a href=3D"https://github.com/NullByte8080/CVE-2026-36228" targe= t=3D"_blank" rel=3D"noopener">https://github.com/NullByte8080/CVE-2026-3622= 8</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Espon--Epson L14150 FL27PB</td>
    <td>Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote at= tacker to execute arbitrary code via the RAW Printing Service (JetDirect) o=
    n TCP port 9100</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39047" target=3D= "_blank" rel=3D"noopener">CVE-2026-39047</a></td>

    <a href=3D"https://github.com/AzhariRamadhan/CVE-PORT-9100" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/AzhariRamadhan/CVE-PORT-9100</a><br>=
    <a href=3D"https://gist.github.com/AzhariRamadhan/1defc815542fb72e6025da2ce= 53a1046" target=3D"_blank" rel=3D"noopener">https://gist.github.com/AzhariR= amadhan/1defc815542fb72e6025da2ce53a1046</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Follett--Software's Destiny Library Manager</t=

    <td>Directory traversal in Follett Software's Destiny Library Manager 22_0_= 2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary sys= tem and application files via the image parameter</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-45145" target=3D= "_blank" rel=3D"noopener">CVE-2025-45145</a></td>

    <a href=3D"http://follett.com" target=3D"_blank" rel=3D"noopener">http://fo= llett.com</a><br><a href=3D"https://medium.com/@jaredutahusa/cve-2025-45145= -unauthenticated-local-file-inclusion-in-fsc-destiny-40a3f11b3a4d" target= =3D"_blank" rel=3D"noopener">https://medium.com/@jaredutahusa/cve-2025-4514= 5-unauthenticated-local-file-inclusion-in-fsc-destiny-40a3f11b3a4d</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">frappe--frappe</td>
    <td>Frappe is a full-stack web application framework. Versions prior to 15.= 105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via = Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and abo= ve.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39352" target=3D= "_blank" rel=3D"noopener">CVE-2026-39352</a></td>

    <a href=3D"https://github.com/frappe/frappe/security/advisories/GHSA-67rf-p= xgh-vfqv" target=3D"_blank" rel=3D"noopener">https://github.com/frappe/frap= pe/security/advisories/GHSA-67rf-pxgh-vfqv</a><br><a href=3D"https://github= .com/frappe/frappe/releases/tag/v16.15.0" target=3D"_blank" rel=3D"noopener= ">https://github.com/frappe/frappe/releases/tag/v16.15.0</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">frappe--lms</td>
    <td>Frappe Learning Management System (LMS) is a learning system that helps=
    users structure their content. In versions 2.50.0 and below, a user with c= ourse editing role could upload a SCORM ZIP package to write files outside = the intended directory. This issue has been resolved in version 2.50.1.</td=

    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39405" target=3D= "_blank" rel=3D"noopener">CVE-2026-39405</a></td>

    <a href=3D"https://github.com/frappe/lms/security/advisories/GHSA-mxh7-g3r7= -g96h" target=3D"_blank" rel=3D"noopener">https://github.com/frappe/lms/sec= urity/advisories/GHSA-mxh7-g3r7-g96h</a><br><a href=3D"https://github.com/f= rappe/lms/releases/tag/v2.50.1" target=3D"_blank" rel=3D"noopener">https://= github.com/frappe/lms/releases/tag/v2.50.1</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>libcasper(3) communicates with helper processes via UNIX domain sockets=
    , and uses the select(2) system call to wait for data to become available. = However, it does not verify that its socket descriptor fits within select(2= )'s descriptor set size limit of FD_SETSIZE (1024). An attacker able to cau=
    se an application using libcasper(3) to allocate large file descriptors, e.= g., by opening many descriptors and executing a program which is not carefu=
    l to close them upon startup, may trigger stack corruption. If the target a= pplication runs with setuid root privileges, this could be used to escalate=
    local privileges.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39461" target=3D= "_blank" rel=3D"noopener">CVE-2026-39461</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:22.libcasp= er.asc" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/adv= isories/FreeBSD-SA-26:22.libcasper.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>The setcred(2) system call is only available to privileged users. Howev= er, before the privilege level of the caller is checked, the user-supplied = list of supplementary groups is copied into a fixed-size kernel stack buffe=
    r without first validating its length. If the supplied list exceeds the cap= acity of that buffer, a stack buffer overflow occurs. Because the bounds ch= eck on the supplementary groups list occurs after the kernel stack buffer h=
    as already been written, an unprivileged local user may trigger the overflo=
    w without holding any special privilege. Successful exploitation may allow =
    an attacker to execute arbitrary code in the context of the kernel, allowin=
    g an unprivileged local user to gain elevated privileges on the affected sy= stem.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45250" target=3D= "_blank" rel=3D"noopener">CVE-2026-45250</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:18.setcred= .asc" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/advis= ories/FreeBSD-SA-26:18.setcred.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>A file descriptor can be closed while a thread is blocked in a poll(2) =
    or select(2) call waiting for that descriptor. Because the blocked thread d= oes not hold a reference to the underlying object, this closure may result =
    in the object being freed while the thread remains blocked. In this situati= on, the kernel must remove the blocked thread from the per-object wait queu=
    e prior to freeing the object. In the case of some file descriptor types, t=
    he kernel failed to unlink blocked threads from the object before freeing i=
    t. When the blocked thread is subsequently woken, it accesses memory that h=
    as already been freed resulting in a use-after-free vulnerability. The use-= after-free vulnerability may be triggered by an unprivileged local user and=
    can be exploited to obtain superuser privileges.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45251" target=3D= "_blank" rel=3D"noopener">CVE-2026-45251</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:19.file.as=
    c" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/advisori= es/FreeBSD-SA-26:19.file.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>When a fusefs file system implements extended attributes, the kernel ma=
    y send a FUSE_LISTXATTR message to the userspace daemon to retrieve the lis=
    t of extended attributes for a given file. The FUSE protocol requires the d= aemon to return a packed list of NUL-terminated strings. The fusefs kernel = module calls strlen() on this daemon-supplied buffer without first verifyin=
    g that the entire list is NUL-terminated. If a malicious daemon sends a non= -NUL-terminated list, the fusefs kernel module may read beyond the end of o=
    ne heap-allocated buffer and potentially write beyond the end of a second b= uffer. A malicious daemon could disclose up to 253 bytes of kernel heap mem= ory, or it could inject up to 250 attacker-controlled bytes into unallocate=
    d kernel heap space.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45252" target=3D= "_blank" rel=3D"noopener">CVE-2026-45252</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:20.fusefs.= asc" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/adviso= ries/FreeBSD-SA-26:20.fusefs.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>ptrace(PT_SC_REMOTE) failed to properly validate parameters for the sys= call(2) and __syscall(2) meta-system calls. As a result, a user with the ab= ility to debug a process may trigger arbitrary code execution in the kernel=
    , even if the target process has no special privileges. The missing validat= ion allows an unprivileged local user to escalate privileges, potentially g= aining full control of the affected system.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45253" target=3D= "_blank" rel=3D"noopener">CVE-2026-45253</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:21.ptrace.= asc" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/adviso= ries/FreeBSD-SA-26:21.ptrace.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>In the case of the cap_net service, when a key present in the old limit=
    was omitted from the new limit, the missing key was treated as "allow any"=
    instead of being rejected. In certain scenarios, an application that had p= reviously restricted a subset of network operations could ask for a new lim=
    it that extended the permissions of the process.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45254" target=3D= "_blank" rel=3D"noopener">CVE-2026-45254</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:24.cap_net= .asc" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/advis= ories/FreeBSD-SA-26:24.cap_net.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreeBSD--FreeBSD</td>
    <td>When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi netw= orks, they build up a list of network names and use bsddialog(1) to prompt = the user to select a network. This is implemented using a shell script, and=
    the code which handled network names was not careful to prevent expansion =
    by the shell. As a result, a suitably crafted network name can be used to e= xecute commands via a subshell. The problem can be exploited to execute cod=
    e as root on the system running bsdinstall or bsdconfig. The attacker would=
    need to create an access point with a specially crafted name and be within=
    range of a Wi-Fi scan. Note that bsdinstall and bsdconfig are vulnerable a=
    s soon as the user prompts them to scan for nearby networks; they do not ne=
    ed to actually select the malicious network.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-45255" target=3D= "_blank" rel=3D"noopener">CVE-2026-45255</a></td>

    <a href=3D"https://security.freebsd.org/advisories/FreeBSD-SA-26:23.bsdinst= all.asc" target=3D"_blank" rel=3D"noopener">https://security.freebsd.org/ad= visories/FreeBSD-SA-26:23.bsdinstall.asc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">FreePBX--security-reporting</td>
    <td>FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6,=
    the backup module does not properly sanitize data during restore operation=
    s, potentially leading to compromise if the backup contains carefully craft=
    ed hostile data. During backup restore operations, FreePBX extracts selecte=
    d files from a user-supplied tar archive. If a malicious file exists in the=
    archive, it is read and passed directly to unserialize() without validatio=
    n, class restrictions, or integrity checks. This issue allows Remote Code E= xecution during restoration of the backup as the web server user (typically=
    asterisk or www-data). The attack does not require shell access, CLI acces=
    s, or filesystem write permissions beyond the normal restore workflow. Auth= entication with a known username that has sufficient access permissions and= /or write access to backup files is required. This issue has been fixed in = versions 16.0.71 and 17.0.6.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-26978" target=3D= "_blank" rel=3D"noopener">CVE-2026-26978</a></td>

    <a href=3D"https://github.com/FreePBX/security-reporting/security/advisorie= s/GHSA-5v7h-49gr-jcwr" target=3D"_blank" rel=3D"noopener">https://github.co= m/FreePBX/security-reporting/security/advisories/GHSA-5v7h-49gr-jcwr</a><br= ><a href=3D"https://github.com/FreePBX/backup/commit/45c57e1207cbf9fd1c5f76= f8a3e72d204a69a472" target=3D"_blank" rel=3D"noopener">https://github.com/F= reePBX/backup/commit/45c57e1207cbf9fd1c5f76f8a3e72d204a69a472</a><br><a hre= f=3D"https://github.com/FreePBX/backup/commit/64781af5c80cce0cff21a981be4d8= e6a7a71f2c4" target=3D"_blank" rel=3D"noopener">https://github.com/FreePBX/= backup/commit/64781af5c80cce0cff21a981be4d8e6a7a71f2c4</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">glpi-project--glpi</td>
    <td>GLPI is a free asset and IT management software package. In versions 11= .0.0 through 11.0.6, an authenticated user with forms READ permission can e= xport the structure of unauthorized forms. This issue has been fixed in ver= sion 11.0.7.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32312" target=3D= "_blank" rel=3D"noopener">CVE-2026-32312</a></td>

    <a href=3D"https://github.com/glpi-project/glpi/security/advisories/GHSA-cg= 63-qchq-q626" target=3D"_blank" rel=3D"noopener">https://github.com/glpi-pr= oject/glpi/security/advisories/GHSA-cg63-qchq-q626</a><br><a href=3D"https:= //github.com/glpi-project/glpi/releases/tag/11.0.7" target=3D"_blank" rel= =3D"noopener">https://github.com/glpi-project/glpi/releases/tag/11.0.7</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">goauthentik--authentik</td>
    <td>authentik is an open-source identity provider. In versions prior to 202= 5.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users wit=
    h at least one OAuth2 access token can retrieve the client_secret of confid= ential OAuth2 providers they have previously authenticated against, exposin=
    g sensitive information to users without the correct permissions. This logi=
    c is GET /api/v3/oauth2/access_tokens/. The API response includes a nested = provider object containing client_id and client_secret for providers config= ured with client_type: confidential, which should not be accessible to low-= privilege users. This issue has been fixed in versions 2025.12.5 and 2026.2= .3.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40166" target=3D= "_blank" rel=3D"noopener">CVE-2026-40166</a></td>

    <a href=3D"https://github.com/goauthentik/authentik/security/advisories/GHS= A-hhpc-rqgm-pxj4" target=3D"_blank" rel=3D"noopener">https://github.com/goa= uthentik/authentik/security/advisories/GHSA-hhpc-rqgm-pxj4</a><br><a href= =3D"https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12= .5" target=3D"_blank" rel=3D"noopener">https://github.com/goauthentik/authe= ntik/releases/tag/version%2F2025.12.5</a><br><a href=3D"https://github.com/= goauthentik/authentik/releases/tag/version%2F2026.2.3" target=3D"_blank" re= l=3D"noopener">https://github.com/goauthentik/authentik/releases/tag/versio= n%2F2026.2.3</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">gohttp--gohttp</td>
    <td>An issue in gohttp commit 34ea51 allows attackers to execute a director=
    y traversal via supplying a crafted request.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-70950" target=3D= "_blank" rel=3D"noopener">CVE-2025-70950</a></td>

    <a href=3D"https://github.com/itang/gohttp/issues/13" target=3D"_blank" rel= =3D"noopener">https://github.com/itang/gohttp/issues/13</a><br><a href=3D"h= ttps://gist.github.com/Lime-Cocoa/202127ae5f4dcc4b39909ce7ac1c8466" target= =3D"_blank" rel=3D"noopener">https://gist.github.com/Lime-Cocoa/202127ae5f4= dcc4b39909ce7ac1c8466</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>An authenticated SSH client that repeatedly opened channels which were = rejected by the server caused unbounded memory growth, eventually crashing = the server process and affecting all connected users. Rejected channels are=
    now properly removed from the connection's internal state and released for=
    garbage collection.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39827" target=3D= "_blank" rel=3D"noopener">CVE-2026-39827</a></td>

    <a href=3D"https://go.dev/issue/35127" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/35127</a><br><a href=3D"https://go.dev/cl/781320" targe= t=3D"_blank" rel=3D"noopener">https://go.dev/cl/781320</a><br><a href=3D"ht= tps://groups.google.com/g/golang-announce/c/a082jnz-LvI" target=3D"_blank" = rel=3D"noopener">https://groups.google.com/g/golang-announce/c/a082jnz-LvI<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5016" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5016</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>When an SSH server authentication callback returned PartialSuccessError=
    with non-nil Permissions, those permissions were silently discarded, poten= tially dropping certificate restrictions such as force-command after a seco=
    nd factor succeeded. Returning non-nil Permissions with PartialSuccessError=
    now results in a connection error.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39828" target=3D= "_blank" rel=3D"noopener">CVE-2026-39828</a></td>

    <a href=3D"https://go.dev/issue/79562" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79562</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781621" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781621<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5014" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5014</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>The RSA and DSA public key parsers did not enforce size limits on key p= arameters. A crafted public key with an excessively large modulus or DSA pa= rameter could cause several minutes of CPU consumption during signature ver= ification. This could be triggered by unauthenticated clients during public=
    key authentication. RSA moduli are now limited to 8192 bits, and DSA param= eters are validated per FIPS 186-2.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39829" target=3D= "_blank" rel=3D"noopener">CVE-2026-39829</a></td>

    <a href=3D"https://go.dev/issue/79565" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79565</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781641" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781641<= /a><br><a href=3D"https://go.dev/cl/781661" target=3D"_blank" rel=3D"noopen= er">https://go.dev/cl/781661</a><br><a href=3D"https://pkg.go.dev/vuln/GO-2= 026-5018" target=3D"_blank" rel=3D"noopener">https://pkg.go.dev/vuln/GO-202= 6-5018</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>A malicious SSH peer could send unsolicited global request responses to=
    fill an internal buffer, blocking the connection's read loop. The blocked = goroutine could not be released by calling Close(), resulting in a resource=
    leak per connection. Unsolicited global responses are now discarded.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39830" target=3D= "_blank" rel=3D"noopener">CVE-2026-39830</a></td>

    <a href=3D"https://go.dev/issue/79564" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79564</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781640" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781640<= /a><br><a href=3D"https://go.dev/cl/781664" target=3D"_blank" rel=3D"noopen= er">https://go.dev/cl/781664</a><br><a href=3D"https://pkg.go.dev/vuln/GO-2= 026-5017" target=3D"_blank" rel=3D"noopener">https://pkg.go.dev/vuln/GO-202= 6-5017</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nist= p256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presen=
    ce flag. Signatures generated without physical touch were accepted, allowin=
    g unattended use of a hardware security key. To restore the previous behavi= or, return a "no-touch-required" extension in Permissions.Extensions from P= ublicKeyCallback.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39831" target=3D= "_blank" rel=3D"noopener">CVE-2026-39831</a></td>

    <a href=3D"https://go.dev/issue/79566" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79566</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781662" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781662<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5019" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5019</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>When writing data larger than 4GB in a single Write call on an SSH chan= nel, an integer overflow in the internal payload size calculation caused th=
    e write loop to spin indefinitely, sending empty packets without making pro= gress. The size comparison now uses int64 to prevent truncation.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39834" target=3D= "_blank" rel=3D"noopener">CVE-2026-39834</a></td>

    <a href=3D"https://go.dev/issue/79567" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79567</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781663" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781663<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5020" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5020</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>SSH servers which use CertChecker as a public key callback without sett= ing IsUserAuthority or IsHostAuthority could be caused to panic by a client=
    presenting a certificate. CertChecker now returns an error instead of pani= cking when these callbacks are nil.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39835" target=3D= "_blank" rel=3D"noopener">CVE-2026-39835</a></td>

    <a href=3D"https://go.dev/issue/79563" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79563</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781660" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781660<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5015" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5015</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>Previously, CVE-2024-45337 fixed an authorization bypass for misused ss=
    h server configurations; if any other type of callback is passed other than=
    public key, then the source-address validation would be skipped.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46595" target=3D= "_blank" rel=3D"noopener">CVE-2026-46595</a></td>

    <a href=3D"https://go.dev/issue/79570" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79570</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781642" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781642<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5023" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5023</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh</=

    <td>An incorrectly placed cast from bytes to int allowed for server-side pa= nic in the AES-GCM packet decoder for well-crafted inputs.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46597" target=3D= "_blank" rel=3D"noopener">CVE-2026-46597</a></td>

    <a href=3D"https://go.dev/issue/79561" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79561</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/a082jnz-LvI" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/a082jnz-LvI</a><br><a href=3D"https://go.= dev/cl/781620" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781620<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5013" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5013</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh/a= gent</td>
    <td>When adding a key to a remote agent constraint extensions such as restr= ict-destination-v00@openssh.com were not serialized in the request. Destina= tion restrictions were silently stripped when forwarding keys, allowing unr= estricted use of the key on the remote host. The client now serializes all = constraint extensions. Additionally, the in-memory keyring returned by NewK= eyring() now rejects keys with unsupported constraint extensions instead of=
    silently ignoring them.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39832" target=3D= "_blank" rel=3D"noopener">CVE-2026-39832</a></td>

    <a href=3D"https://go.dev/issue/79435" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79435</a><br><a href=3D"https://go.dev/cl/778642" targe= t=3D"_blank" rel=3D"noopener">https://go.dev/cl/778642</a><br><a href=3D"ht= tps://groups.google.com/g/golang-announce/c/a082jnz-LvI" target=3D"_blank" = rel=3D"noopener">https://groups.google.com/g/golang-announce/c/a082jnz-LvI<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5006" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5006</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh/a= gent</td>
    <td>The in-memory keyring returned by NewKeyring() silently accepted keys w= ith the ConfirmBeforeUse constraint but never enforced it. The key would si=
    gn without any confirmation prompt, with no indication to the caller that t=
    he constraint was not in effect. NewKeyring() now returns an error when uns= upported constraints are requested.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39833" target=3D= "_blank" rel=3D"noopener">CVE-2026-39833</a></td>

    <a href=3D"https://go.dev/issue/79436" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79436</a><br><a href=3D"https://go.dev/cl/778640" targe= t=3D"_blank" rel=3D"noopener">https://go.dev/cl/778640</a><br><a href=3D"ht= tps://go.dev/cl/778641" target=3D"_blank" rel=3D"noopener">https://go.dev/c= l/778641</a><br><a href=3D"https://groups.google.com/g/golang-announce/c/a0= 82jnz-LvI" target=3D"_blank" rel=3D"noopener">https://groups.google.com/g/g= olang-announce/c/a082jnz-LvI</a><br><a href=3D"https://pkg.go.dev/vuln/GO-2= 026-5005" target=3D"_blank" rel=3D"noopener">https://pkg.go.dev/vuln/GO-202= 6-5005</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh/a= gent</td>
    <td>For certain crafted inputs, a 'ed25519.PrivateKey' was created by casti=
    ng malformed wire bytes, leading to a panic when used.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46598" target=3D= "_blank" rel=3D"noopener">CVE-2026-46598</a></td>

    <a href=3D"https://go.dev/issue/79596" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79596</a><br><a href=3D"https://go.dev/cl/781360" targe= t=3D"_blank" rel=3D"noopener">https://go.dev/cl/781360</a><br><a href=3D"ht= tps://groups.google.com/g/golang-announce/c/a082jnz-LvI" target=3D"_blank" = rel=3D"noopener">https://groups.google.com/g/golang-announce/c/a082jnz-LvI<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5033" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5033</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/crypto--golang.org/x/crypto/ssh/k= nownhosts</td>
    <td>Previously, a revoked 'SignatureKey' belonging to a CA was not correctl=
    y checked for revocation. Now, both the 'key' and 'key.SignatureKey' are ch= ecked for @revoked.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42508" target=3D= "_blank" rel=3D"noopener">CVE-2026-42508</a></td>

    <a href=3D"https://go.dev/issue/79568" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79568</a><br><a href=3D"https://go.dev/cl/781220" targe= t=3D"_blank" rel=3D"noopener">https://go.dev/cl/781220</a><br><a href=3D"ht= tps://groups.google.com/g/golang-announce/c/a082jnz-LvI" target=3D"_blank" = rel=3D"noopener">https://groups.google.com/g/golang-announce/c/a082jnz-LvI<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5021" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5021</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/net--golang.org/x/net/html</td> <td>Parsing arbitrary HTML can consume excessive CPU time, possibly leading=
    to denial of service.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25680" target=3D= "_blank" rel=3D"noopener">CVE-2026-25680</a></td>

    <a href=3D"https://go.dev/cl/781702" target=3D"_blank" rel=3D"noopener">htt= ps://go.dev/cl/781702</a><br><a href=3D"https://go.dev/issue/79573" target= =3D"_blank" rel=3D"noopener">https://go.dev/issue/79573</a><br><a href=3D"h= ttps://groups.google.com/g/golang-announce/c/iI-mYSI0lu8" target=3D"_blank"=
    rel=3D"noopener">https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8= </a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5028" target=3D"_blank" = rel=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5028</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/net--golang.org/x/net/html</td> <td>Parsing arbitrary HTML which is then rendered using Render can result i=
    n an unexpected HTML tree. This can be leveraged to execute XSS attacks in = applications that attempt to sanitize input HTML before rendering.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-25681" target=3D= "_blank" rel=3D"noopener">CVE-2026-25681</a></td>

    <a href=3D"https://go.dev/issue/79574" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79574</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/iI-mYSI0lu8" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/iI-mYSI0lu8</a><br><a href=3D"https://go.= dev/cl/781703" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781703<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5029" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5029</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/net--golang.org/x/net/html</td> <td>Parsing arbitrary HTML which is then rendered using Render can result i=
    n an unexpected HTML tree. This can be leveraged to execute XSS attacks in = applications that attempt to sanitize input HTML before rendering.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-27136" target=3D= "_blank" rel=3D"noopener">CVE-2026-27136</a></td>

    <a href=3D"https://go.dev/issue/79575" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79575</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/iI-mYSI0lu8" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/iI-mYSI0lu8</a><br><a href=3D"https://go.= dev/cl/781685" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781685<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5030" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5030</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/net--golang.org/x/net/html</td> <td>Parsing arbitrary HTML which is then rendered using Render can result i=
    n an unexpected HTML tree. This can be leveraged to execute XSS attacks in = applications that attempt to sanitize input HTML before rendering.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42502" target=3D= "_blank" rel=3D"noopener">CVE-2026-42502</a></td>

    <a href=3D"https://go.dev/issue/79572" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79572</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/iI-mYSI0lu8" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/iI-mYSI0lu8</a><br><a href=3D"https://go.= dev/cl/781701" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781701<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5027" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5027</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/net--golang.org/x/net/html</td> <td>Parsing arbitrary HTML which is then rendered using Render can result i=
    n an unexpected HTML tree. This can be leveraged to execute XSS attacks in = applications that attempt to sanitize input HTML before rendering.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42506" target=3D= "_blank" rel=3D"noopener">CVE-2026-42506</a></td>

    <a href=3D"https://go.dev/issue/79571" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/79571</a><br><a href=3D"https://groups.google.com/g/gol= ang-announce/c/iI-mYSI0lu8" target=3D"_blank" rel=3D"noopener">https://grou= ps.google.com/g/golang-announce/c/iI-mYSI0lu8</a><br><a href=3D"https://go.= dev/cl/781700" target=3D"_blank" rel=3D"noopener">https://go.dev/cl/781700<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5025" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5025</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/net--golang.org/x/net/idna</td> <td>The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded=
    labels that decode to an ASCII-only label. For example, ToUnicode("xn--exa= mple-.com") incorrectly returns the name "example.com" rather than an error=
    . This behavior can lead to privilege escalation in programs using the idna=
    package. For example, a program which performs privilege checks on the ASC=
    II hostname may reject "example.com" but permit "xn--example-.com". If that=
    program subsequently converts the ASCII hostname to Unicode, it will inadv= ertently permits access to the Unicode name "example.com".</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39821" target=3D= "_blank" rel=3D"noopener">CVE-2026-39821</a></td>

    <a href=3D"https://go.dev/cl/767220" target=3D"_blank" rel=3D"noopener">htt= ps://go.dev/cl/767220</a><br><a href=3D"https://go.dev/issue/78760" target= =3D"_blank" rel=3D"noopener">https://go.dev/issue/78760</a><br><a href=3D"h= ttps://groups.google.com/g/golang-announce/c/iI-mYSI0lu8" target=3D"_blank"=
    rel=3D"noopener">https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8= </a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5026" target=3D"_blank" = rel=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5026</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">golang.org/x/sys--golang.org/x/sys/windows</td=

    <td>NewNTUnicodeString does not check for string length overflow. When prov= ided with a string that overflows the maximum size of a NTUnicodeString (a = 16-bit number of bytes), it returns a truncated string rather than an error= .</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39824" target=3D= "_blank" rel=3D"noopener">CVE-2026-39824</a></td>

    <a href=3D"https://go.dev/issue/78916" target=3D"_blank" rel=3D"noopener">h= ttps://go.dev/issue/78916</a><br><a href=3D"https://go.dev/cl/770080" targe= t=3D"_blank" rel=3D"noopener">https://go.dev/cl/770080</a><br><a href=3D"ht= tps://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg" target=3D"_blank" = rel=3D"noopener">https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg<= /a><br><a href=3D"https://pkg.go.dev/vuln/GO-2026-5024" target=3D"_blank" r= el=3D"noopener">https://pkg.go.dev/vuln/GO-2026-5024</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Inappropriate implementation in UI in Google Chrome on Windows prior to=
    148.0.7778.179 allowed a remote attacker who had compromised the renderer = process to perform UI spoofing via a crafted HTML page. (Chromium security = severity: Critical)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9110" target=3D"= _blank" rel=3D"noopener">CVE-2026-9110</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/50355115=
    4" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/50= 3551154</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.= 179 allowed a remote attacker to execute arbitrary code via a crafted HTML = page. (Chromium security severity: Critical)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9111" target=3D"= _blank" rel=3D"noopener">CVE-2026-9111</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/50455103=
    2" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/50= 4551032</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.1=
    79 allowed a remote attacker to execute arbitrary code inside a sandbox via=
    a crafted HTML page. (Chromium security severity: High)</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9112" target=3D"= _blank" rel=3D"noopener">CVE-2026-9112</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/48979142=
    5" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/48= 9791425</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.1=
    79 allowed a remote attacker to perform an out of bounds memory read via a = crafted HTML page. (Chromium security severity: High)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9113" target=3D"= _blank" rel=3D"noopener">CVE-2026-9113</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/48958504=
    4" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/48= 9585044</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allo= wed a remote attacker to execute arbitrary code inside a sandbox via malici= ous network traffic. (Chromium security severity: High)</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9114" target=3D"= _blank" rel=3D"noopener">CVE-2026-9114</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49579863=
    0" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 5798630</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Insufficient policy enforcement in Service Worker in Google Chrome on p= rior to 148.0.7778.179 allowed a remote attacker to bypass same origin poli=
    cy via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9115" target=3D"= _blank" rel=3D"noopener">CVE-2026-9115</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49599948=
    1" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 5999481</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Insufficient policy enforcement in ServiceWorker in Google Chrome on pr= ior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data v=
    ia a crafted HTML page. (Chromium security severity: High)</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9116" target=3D"= _blank" rel=3D"noopener">CVE-2026-9116</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49743627=
    3" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 7436273</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.= 0.7778.179 allowed a remote attacker who had compromised the renderer proce=
    ss to potentially perform a sandbox escape via a crafted video file. (Chrom= ium security severity: High)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9117" target=3D"= _blank" rel=3D"noopener">CVE-2026-9117</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49754253=
    7" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 7542537</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Use after free in XR in Google Chrome on Windows prior to 148.0.7778.17=
    9 allowed a remote attacker to execute arbitrary code via a crafted HTML pa= ge. (Chromium security severity: High)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9118" target=3D"= _blank" rel=3D"noopener">CVE-2026-9118</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49870223=
    3" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 8702233</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.= 179 allowed a remote attacker to execute arbitrary code inside a sandbox vi=
    a a crafted HTML page. (Chromium security severity: High)</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9119" target=3D"= _blank" rel=3D"noopener">CVE-2026-9119</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/50266110=
    1" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/50= 2661101</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allow=
    ed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch= romium security severity: High)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9120" target=3D"= _blank" rel=3D"noopener">CVE-2026-9120</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/50462082=
    4" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/50= 4620824</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 a= llowed a remote attacker to potentially exploit heap corruption via a craft=
    ed HTML page. (Chromium security severity: Medium)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9121" target=3D"= _blank" rel=3D"noopener">CVE-2026-9121</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/48806410=
    8" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/48= 8064108</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.1=
    79 allowed a remote attacker to obtain potentially sensitive information fr=
    om process memory via a crafted HTML page. (Chromium security severity: Med= ium)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9122" target=3D"= _blank" rel=3D"noopener">CVE-2026-9122</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/48957995=
    3" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/48= 9579953</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, = ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitr= ary code inside a sandbox via malicious network traffic. (Chromium security=
    severity: Medium)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9123" target=3D"= _blank" rel=3D"noopener">CVE-2026-9123</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49598850=
    7" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 5988507</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Insufficient validation of untrusted input in Input in Google Chrome on=
    prior to 148.0.7778.179 allowed a remote attacker who had compromised the = renderer process to leak cross-origin data via a crafted HTML page. (Chromi=
    um security severity: Medium)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9124" target=3D"= _blank" rel=3D"noopener">CVE-2026-9124</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49637569=
    5" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 6375695</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Google--Chrome</td>
    <td>Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allow=
    ed a remote attacker to execute arbitrary code inside a sandbox via a craft=
    ed HTML page. (Chromium security severity: Medium)</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9126" target=3D"= _blank" rel=3D"noopener">CVE-2026-9126</a></td>

    <a href=3D"https://chromereleases.googleblog.com/2026/05/stable-channel-upd= ate-for-desktop_0841193308.html" target=3D"_blank" rel=3D"noopener">https:/= /chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_08= 41193308.html</a><br><a href=3D"https://issues.chromium.org/issues/49628053=
    2" target=3D"_blank" rel=3D"noopener">https://issues.chromium.org/issues/49= 6280532</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HP Inc--HP Linux Imaging and Printing Software= </td>
    <td>A potential security vulnerability has been identified in the HP Linux = Imaging and Printing Software. This potential vulnerability may allow escal= ation of privileges and/or arbitrary code execution via an integer overflow=
    in the hpcups processing path when handling crafted print data.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8631" target=3D"= _blank" rel=3D"noopener">CVE-2026-8631</a></td>

    <a href=3D"https://support.hp.com/us-en/document/ish_14942099-14942126-16/h= psbpi04118" target=3D"_blank" rel=3D"noopener">https://support.hp.com/us-en= /document/ish_14942099-14942126-16/hpsbpi04118</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HP Inc--HP Linux Imaging and Printing Software= </td>
    <td>A potential security vulnerability has been identified in the HP Linux = Imaging and Printing Software. This potential vulnerability may allow escal= ation of privileges and/or arbitrary code execution via operating system co= mmand injection.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8632" target=3D"= _blank" rel=3D"noopener">CVE-2026-8632</a></td>

    <a href=3D"https://support.hp.com/us-en/document/ish_14942099-14942126-16/h= psbpi04118" target=3D"_blank" rel=3D"noopener">https://support.hp.com/us-en= /document/ish_14942099-14942126-16/hpsbpi04118</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HP-- ENVY 5000</td>
    <td>HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly man= age concurrent TCP connections to port 9100 (JetDirect/RAW printing). An un= authenticated remote attacker on the same network can establish a persisten=
    t connection to port 9100 and send keep-alive packets, causing the printer'=
    s session threads to remain locked in a waiting state. The firmware lacks c= onnection timeouts and concurrent session limits, resulting in a persistent=
    Denial of Service (DoS) that renders the printer unresponsive to all user = commands and print jobs. Physical intervention (manual restart) is required=
    to restore functionality, and the attack can be immediately re-initiated.<=

    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42626" target=3D= "_blank" rel=3D"noopener">CVE-2026-42626</a></td>

    <a href=3D"https://medium.com/@jacobmasse/hp-envy-5000-printer-dos-vulnerab= ility-8cae52c87b41" target=3D"_blank" rel=3D"noopener">https://medium.com/@= jacobmasse/hp-envy-5000-printer-dos-vulnerability-8cae52c87b41</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">HSC--MailInspector v5.3.3-7</td>
    <td>HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulner= ability caused by improper control of user-supplied file paths. The endpoin=
    t /vendor/phpunit/phpunit.php processes user-controlled parameters that dir= ectly affect file access operations without adequate validation, sanitizati= on, or path restriction. This allows a remote attacker to exploit Path Trav= ersal techniques to read arbitrary files from the underlying operating syst=
    em and application directories, leading to sensitive information disclosure= .</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29962" target=3D= "_blank" rel=3D"noopener">CVE-2026-29962</a></td>

    <a href=3D"https://github.com/sql3t0/cve-disclosures" target=3D"_blank" rel= =3D"noopener">https://github.com/sql3t0/cve-disclosures</a><br><a href=3D"h= ttps://hsclabs.com/pt-br/mailinspector" target=3D"_blank" rel=3D"noopener">= https://hsclabs.com/pt-br/mailinspector</a><br><a href=3D"https://github.co= m/sql3t0/cve-disclosures/blob/main/01_-_CVE-2026-29962_LFI%2BPath_Traversal= .md" target=3D"_blank" rel=3D"noopener">https://github.com/sql3t0/cve-discl= osures/blob/main/01_-_CVE-2026-29962_LFI%2BPath_Traversal.md</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">HSC--MailInspector v5.3.3-7</td>
    <td>HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to imp= roper validation of user-supplied input in the /tap/dw.php endpoint. The te=
    xt parameter is used to construct file paths without adequate normalization=
    or restriction to a safe base directory. A remote attacker can exploit thi=
    s flaw to access arbitrary files on the underlying operating system, result= ing in unauthorized disclosure of sensitive information.</td> <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29963" target=3D= "_blank" rel=3D"noopener">CVE-2026-29963</a></td>

    <a href=3D"https://hsclabs.com/pt-br/mailinspector/" target=3D"_blank" rel= =3D"noopener">https://hsclabs.com/pt-br/mailinspector/</a><br><a href=3D"ht= tps://github.com/sql3t0/cve-disclosures" target=3D"_blank" rel=3D"noopener"= >https://github.com/sql3t0/cve-disclosures</a><br><a href=3D"https://github= .com/sql3t0/cve-disclosures/blob/main/02_-_CVE-2026-29963_LFI%2BPath_Traver= sal.md" target=3D"_blank" rel=3D"noopener">https://github.com/sql3t0/cve-di= sclosures/blob/main/02_-_CVE-2026-29963_LFI%2BPath_Traversal.md</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">HSC--MailInspector v5.3.3-7</td>
    <td>HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulner= ability in the /tap/tap.php endpoint due to improper neutralization of user= -controlled input using alternate or obfuscated JavaScript syntax. The endp= oint reflects unsanitized user input in HTTP responses without adequate out= put encoding, allowing a remote attacker to execute arbitrary JavaScript co=
    de in the context of a victim's browser.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29964" target=3D= "_blank" rel=3D"noopener">CVE-2026-29964</a></td>

    <a href=3D"https://hsclabs.com/pt-br/mailinspector/" target=3D"_blank" rel= =3D"noopener">https://hsclabs.com/pt-br/mailinspector/</a><br><a href=3D"ht= tps://github.com/sql3t0/cve-disclosures" target=3D"_blank" rel=3D"noopener"= >https://github.com/sql3t0/cve-disclosures</a><br><a href=3D"https://github= .com/sql3t0/cve-disclosures/blob/main/03_-_CVE-2026-29964_XSS.md" target=3D= "_blank" rel=3D"noopener">https://github.com/sql3t0/cve-disclosures/blob/ma= in/03_-_CVE-2026-29964_XSS.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HSC--MailInspector v5.3.3-7</td>
    <td>HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) i=
    n the /police/WarningUrlPage.php endpoint due to improper neutralization of=
    user-supplied input that uses alternate or obfuscated JavaScript syntax.</=

    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-29965" target=3D= "_blank" rel=3D"noopener">CVE-2026-29965</a></td>

    <a href=3D"https://hsclabs.com/pt-br/mailinspector/" target=3D"_blank" rel= =3D"noopener">https://hsclabs.com/pt-br/mailinspector/</a><br><a href=3D"ht= tps://github.com/sql3t0/cve-disclosures" target=3D"_blank" rel=3D"noopener"= >https://github.com/sql3t0/cve-disclosures</a><br><a href=3D"https://github= .com/sql3t0/cve-disclosures/blob/main/04_-_CVE-2026-29965_XSS.md" target=3D= "_blank" rel=3D"noopener">https://github.com/sql3t0/cve-disclosures/blob/ma= in/04_-_CVE-2026-29965_XSS.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">huggingface--huggingface/transformers</td>
    <td>A critical remote code execution vulnerability exists in all versions o=
    f the HuggingFace transformers library prior to version 5.3.0. The vulnerab= ility allows an attacker to craft a malicious `config.json` file containing=
    the `_attn_implementation_internal` field set to an attacker-controlled Hu= ggingFace Hub repository ID. When a victim loads this model using the stand= ard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and=
    executes arbitrary Python code from the attacker's repository with the vic= tim's full OS privileges. This issue arises due to unfiltered deserializati=
    on of configuration attributes, insufficient sanitization of internal field=
    s, and unsandboxed execution of downloaded kernels. The vulnerability bypas= ses the `trust_remote_code` security mechanism, is invisible to the victim,=
    and exploits the standard documented usage pattern, making it particularly=
    severe. Users are advised to upgrade to version 5.3.0 or later to mitigate=
    this issue.</td>
    <td>2026-05-24</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4372" target=3D"= _blank" rel=3D"noopener">CVE-2026-4372</a></td>

    <a href=3D"https://huntr.com/bounties/1f693a6e-6836-4b8b-a0bd-ca036fba8884"=
    target=3D"_blank" rel=3D"noopener">https://huntr.com/bounties/1f693a6e-683= 6-4b8b-a0bd-ca036fba8884</a><br><a href=3D"https://github.com/huggingface/t= ransformers/commit/a7f8e7ff37d87d1a1a0c8cf607971c607741452f" target=3D"_bla= nk" rel=3D"noopener">https://github.com/huggingface/transformers/commit/a7f= 8e7ff37d87d1a1a0c8cf607971c607741452f</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">InfoScale--CmdServer</td>
    <td>InfoScale CmdServer before 7.4.2 mishandles access control.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44926" target=3D= "_blank" rel=3D"noopener">CVE-2026-44926</a></td>

    <a href=3D"https://www.veritas.com/support/en_US/doc/109864724-141543588-0/= v141217547-141543588" target=3D"_blank" rel=3D"noopener">https://www.verita= s.com/support/en_US/doc/109864724-141543588-0/v141217547-141543588</a><br><=
    a href=3D"https://supportinfoscale.cloud.com/support-home/kbsearch/article?= articleNumber=3D1000766081&articleTitle=3DInfoScale_Command_Server_Security= _Bulletin_for_CVE_2026_44926" target=3D"_blank" rel=3D"noopener">https://su= pportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=3D1000= 766081&articleTitle=3DInfoScale_Command_Server_Security_Bulletin_for_CVE_20= 26_44926</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">InfoScale--VIOM</td>
    <td>SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers t=
    o escalate privileges.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44923" target=3D= "_blank" rel=3D"noopener">CVE-2026-44923</a></td>

    <a href=3D"https://www.veritas.com/support/en_US/doc/120571566-166757640-0/= viom_tot_v118836641-166757640" target=3D"_blank" rel=3D"noopener">https://w= ww.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-= 166757640</a><br><a href=3D"https://supportinfoscale.cloud.com/support-home= /kbsearch/article?articleNumber=3D1000766080&articleTitle=3DInfoScale_Opera= tions_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_= 2026_44924_and_CVE_2026_44925" target=3D"_blank" rel=3D"noopener">https://s= upportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=3D100= 0766080&articleTitle=3DInfoScale_Operations_Manager_IOM_web_application_Sec= urity_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">InfoScale--VIOM</td>
    <td>InfoScale VIOM 9.1.3 allows XSS.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44924" target=3D= "_blank" rel=3D"noopener">CVE-2026-44924</a></td>

    <a href=3D"https://www.veritas.com/support/en_US/doc/120571566-166757640-0/= viom_tot_v118836641-166757640" target=3D"_blank" rel=3D"noopener">https://w= ww.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-= 166757640</a><br><a href=3D"https://supportinfoscale.cloud.com/support-home= /kbsearch/article?articleNumber=3D1000766080&articleTitle=3DInfoScale_Opera= tions_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_= 2026_44924_and_CVE_2026_44925" target=3D"_blank" rel=3D"noopener">https://s= upportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=3D100= 0766080&articleTitle=3DInfoScale_Operations_Manager_IOM_web_application_Sec= urity_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">InfoScale--VIOM</td>
    <td>Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Op= erations Manager (VIOM) allows an attacker to force the user with an active=
    session into clicking a malicious HTML link, which triggers unintended mod= ifications on VIOM web application without the user's knowledge.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44925" target=3D= "_blank" rel=3D"noopener">CVE-2026-44925</a></td>

    <a href=3D"https://www.veritas.com/support/en_US/doc/120571566-166757640-0/= viom_tot_v118836641-166757640" target=3D"_blank" rel=3D"noopener">https://w= ww.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-= 166757640</a><br><a href=3D"https://supportinfoscale.cloud.com/support-home= /kbsearch/article?articleNumber=3D1000766080&articleTitle=3DInfoScale_Opera= tions_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_= 2026_44924_and_CVE_2026_44925" target=3D"_blank" rel=3D"noopener">https://s= upportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=3D100= 0766080&articleTitle=3DInfoScale_Operations_Manager_IOM_web_application_Sec= urity_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Innoshop--Innoshop 0.6.0</td>
    <td>An authorization vulnerability exists in Innoshop 0.6.0. After logging = into the frontend, an attacker can directly access backend application inte= rfaces, leading to further dangerous operations.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39250" target=3D= "_blank" rel=3D"noopener">CVE-2026-39250</a></td>

    <a href=3D"https://www.innoshop.com/" target=3D"_blank" rel=3D"noopener">ht= tps://www.innoshop.com/</a><br><a href=3D"https://gist.github.com/hkdmh/4af= 513ea7589212cb1d49bc5d972972e" target=3D"_blank" rel=3D"noopener">https://g= ist.github.com/hkdmh/4af513ea7589212cb1d49bc5d972972e</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Jaspersoft--JasperReports Library Community Ed= ition</td>
    <td>Java Deserialisation Vulnerability in Jaspersoft Reports Library leads = to=C2=A0Remote Code Execution (RCE), potentially allowing code execution on=
    the affected system</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6009" target=3D"= _blank" rel=3D"noopener">CVE-2026-6009</a></td>

    <a href=3D"https://community.jaspersoft.com/advisories/jaspersoft-security-= advisory-may-19-2026-jaspersoft-library-cve-2026-6009-r11/" target=3D"_blan=
    k" rel=3D"noopener">https://community.jaspersoft.com/advisories/jaspersoft-= security-advisory-may-19-2026-jaspersoft-library-cve-2026-6009-r11/</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">JJNAPIORK--Catalyst::Plugin::Authentication</t=

    <td>Catalyst::Plugin::Authentication versions through 0.10024 for Perl is s= usceptible to timing attacks. These versions use Perl's built-in eq compari= son. Discrepencies in timing could be used to guess the underlying hash or = password.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5091" target=3D"= _blank" rel=3D"noopener">CVE-2026-5091</a></td>

    <a href=3D"https://metacpan.org/release/ETHER/Catalyst-Plugin-Authenticatio= n-0.10_025/changes" target=3D"_blank" rel=3D"noopener">https://metacpan.org= /release/ETHER/Catalyst-Plugin-Authentication-0.10_025/changes</a><br><a hr= ef=3D"https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commi= t/b0515f492257438cf07082acf1e10d06e8088a5e.patch" target=3D"_blank" rel=3D"= noopener">https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/c= ommit/b0515f492257438cf07082acf1e10d06e8088a5e.patch</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">LalanaChami--Pharmacy Management System=C2=A0<=

    <td>The LalanaChami Pharmacy Management System (commit 5c3d028) allows unau= thenticated remote attackers to escalate privileges by self-assigning an ad= ministrative role during registration. The /api/user/signup endpoint fails =
    to validate the role parameter in the request body</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31070" target=3D= "_blank" rel=3D"noopener">CVE-2026-31070</a></td>

    <a href=3D"https://github.com/LalanaChami/Pharmacy-Mangment-System/blob/5c3= d02888631166649856f71d542387114b3010b/backend/routes/user.js#L16" target=3D= "_blank" rel=3D"noopener">https://github.com/LalanaChami/Pharmacy-Mangment-= System/blob/5c3d02888631166649856f71d542387114b3010b/backend/routes/user.js= #L16</a><br><a href=3D"https://gist.github.com/nedlir/22bf6d1a3a07209be3e34= 3744bc81d51" target=3D"_blank" rel=3D"noopener">https://gist.github.com/ned= lir/22bf6d1a3a07209be3e343744bc81d51</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net=
    : qrtr: ns: Limit the maximum server registration per node Current code doe=
    s no bound checking on the number of servers added per node. A malicious cl= ient can flood NEW_SERVER messages and exhaust memory. Fix this issue by li= miting the maximum number of server registrations to 256 per node. If the N= EW_SERVER message is received for an old port, then don't restrict it as it=
    will get replaced. While at it, also rate limit the error messages in the = failure path of qrtr_ns_worker(). Note that the limit of 256 is chosen base=
    d on the current platform requirements. If requirement changes in the futur=
    e, this limit can be increased.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43491" target=3D= "_blank" rel=3D"noopener">CVE-2026-43491</a></td>

    <a href=3D"https://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb= 5e426ae7" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7</a><br><a href=3D"https://git.ke= rnel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/3efaad55cad1ded429e3a87= 3bfece389058a526b</a><br><a href=3D"https://git.kernel.org/stable/c/35fb4a0= c077c5d1049c2628b769e0a1b1e65df0d" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d= 782ec02c" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/868202aa2adae427060a42d5bd663b4d782ec02c</a><br><a href=3D"https://git.ke= rnel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/d5ee2ff98322337951c5639= 8e79d51815acbf955</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: lib= /crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming repor=
    ts an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros=
    " from the unsigned "nbytes". For this to happen, the scatterlist "sgl" nee=
    ds to occupy more bytes than the "nbytes" parameter and the first "nbytes +=
    1" bytes of the scatterlist must be zero. Under these conditions, the whil=
    e loop iterating over the scatterlist will count more zeroes than "nbytes",=
    subtract the number of zeroes from "nbytes" and cause the underflow. When = commit 2d4d1eea540b ("lib/mpi: Add mpi sgl helpers") originally introduced = the bug, it couldn't be triggered because all callers of mpi_read_raw_from_= sgl() passed a scatterlist whose length was equal to "nbytes". However sinc=
    e commit 63ba4d67594a ("KEYS: asymmetric: Use new crypto interface without = scatterlists"), the underflow can now actually be triggered. When invoking =
    a KEYCTL_PKEY_ENCRYPT system call with a larger "out_len" than "in_len" and=
    filling the "in" buffer with zeroes, crypto_akcipher_sync_prep() will crea=
    te an all-zero scatterlist used for both the "src" and "dst" member of stru=
    ct akcipher_request and thereby fulfil the conditions to trigger the bug: s= ys_keyctl() keyctl_pkey_e_d_s() asymmetric_key_eds_op() software_key_eds_op=
    () crypto_akcipher_sync_encrypt() crypto_akcipher_sync_prep() crypto_akciph= er_encrypt() rsa_enc() mpi_read_raw_from_sgl() To the user this will be vis= ible as a DoS as the kernel spins forever, causing soft lockup splats as a = side effect. Fix it.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43492" target=3D= "_blank" rel=3D"noopener">CVE-2026-43492</a></td>

    <a href=3D"https://git.kernel.org/stable/c/2aa77a18dc7f2670497fe3ee5acbeda0= b57659e5" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/2aa77a18dc7f2670497fe3ee5acbeda0b57659e5</a><br><a href=3D"https://git.ke= rnel.org/stable/c/26d3a97ad46c7a9226ec04d4bf35bd4998a97d16" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/26d3a97ad46c7a9226ec04d= 4bf35bd4998a97d16</a><br><a href=3D"https://git.kernel.org/stable/c/8637dfb= 4c1d8a7026ef681f2477c6de8b71c4003" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/8637dfb4c1d8a7026ef681f2477c6de8b71c4003</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/30e513e755bb381afce6fb57cdc86941= 36193f22" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/30e513e755bb381afce6fb57cdc8694136193f22</a><br><a href=3D"https://git.ke= rnel.org/stable/c/8c2f1288250a90a4b5cabed5d888d7e3aeed4035" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/8c2f1288250a90a4b5cabed= 5d888d7e3aeed4035</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net= /rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2(=
    ) fails in rds_message_zcopy_from_user(), the pinned pages are released wit=
    h put_page(), and rm-&gt;data.op_mmp_znotifier is cleared. But we fail to p= roperly clear rm-&gt;data.op_nents. Later when rds_message_purge() is calle=
    d from rds_sendmsg() the cleanup loop iterates over the incorrectly non zer=
    o number of op_nents and frees them again. Fix this by properly resetting o= p_nents when it should be in rds_message_zcopy_from_user().</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43494" target=3D= "_blank" rel=3D"noopener">CVE-2026-43494</a></td>

    <a href=3D"https://git.kernel.org/stable/c/9115669faedccdda100428e2d26fd0aa= c8c50799" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/9115669faedccdda100428e2d26fd0aac8c50799</a><br><a href=3D"https://git.ke= rnel.org/stable/c/0bbbff00a15b1df2cac9014d6cf4b6890f473353" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/0bbbff00a15b1df2cac9014= d6cf4b6890f473353</a><br><a href=3D"https://git.kernel.org/stable/c/640e37f= 58f991546a87540d067279c2c1fa9fe51" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/640e37f58f991546a87540d067279c2c1fa9fe51</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/290e833d1acb1093bc121fcdc97f5e61= 61157479" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/290e833d1acb1093bc121fcdc97f5e6161157479</a><br><a href=3D"https://git.ke= rnel.org/stable/c/e174929793195e0cd6a4adb0cad731b39f9019b4" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/e174929793195e0cd6a4adb= 0cad731b39f9019b4</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net=
    : wwan: t7xx: validate port_count against message length in t7xx_port_enum_= msg_handler t7xx_port_enum_msg_handler() uses the modem-supplied port_count=
    field as a loop bound over port_msg-&gt;data[] without checking that the m= essage buffer contains sufficient data. A modem sending port_count=3D65535 =
    in a 12-byte buffer triggers a slab-out-of-bounds read of up to 262140 byte=
    s. Add a sizeof(*port_msg) check before accessing the port message header f= ields to guard against undersized messages. Add a struct_size() check after=
    extracting port_count and before the loop. In t7xx_parse_host_rt_data(), g= uard the rt_feature header read with a remaining-buffer check before access= ing data_len, validate feat_data_len against the actual remaining buffer to=
    prevent OOB reads and signed integer overflow on offset. Pass msg_len from=
    both call sites: skb-&gt;len at the DPMAIF path after skb_pull(), and the = validated feat_data_len at the handshake path.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43495" target=3D= "_blank" rel=3D"noopener">CVE-2026-43495</a></td>

    <a href=3D"https://git.kernel.org/stable/c/f94450ce5053b36002995b72d1fa1db3= bb08c5bf" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/f94450ce5053b36002995b72d1fa1db3bb08c5bf</a><br><a href=3D"https://git.ke= rnel.org/stable/c/9855e063e063158cc5bded576382599dc3133202" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/9855e063e063158cc5bded5= 76382599dc3133202</a><br><a href=3D"https://git.kernel.org/stable/c/2b56d79= 03ab804481f5233a259d5f341e9fd513c" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/2b56d7903ab804481f5233a259d5f341e9fd513c</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/dd4f4c93c1488d7100b9964f2da4c8b3= c29652f1" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/dd4f4c93c1488d7100b9964f2da4c8b3c29652f1</a><br><a href=3D"https://git.ke= rnel.org/stable/c/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/0e7c074cfcd9bd93765505f= 9eb8b42f03ed2a744</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net= /sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_pe= eked When red qdisc has children (eg qfq qdisc) whose peek() callback is qd= isc_peek_dequeued(), we could get a kernel panic. When the parent of such q= discs (eg illustrated in patch #3 as tbf) wants to retrieve an skb from its=
    child (red in this case), it will do the following: 1a. do a peek() - and = when sensing there's an skb the child can offer, then - the child in this c= ase(red) calls its child's (qfq) peek. qfq does the right thing and will re= turn the gso_skb queue packet. Note: if there wasnt a gso_skb entry then qf=
    q will store it there. 1b. invoke a dequeue() on the child (red). And herei=
    n lies the problem. - red will call the child's dequeue() which will essent= ially just try to grab something of qfq's queue. [ 78.667668][ T363] KASAN:=
    null-ptr-deref in range [0x0000000000000048-0x000000000000004f] [ 78.66792= 7][ T363] CPU: 1 UID: 0 PID: 363 Comm: ping Not tainted 7.1.0-rc1-00033-g46= f74a3f7d57-dirty #790 PREEMPT(full) [ 78.668263][ T363] Hardware name: Boch=
    s Bochs, BIOS Bochs 01/01/2011 [ 78.668486][ T363] RIP: 0010:qfq_dequeue+0x= 446/0xc90 [sch_qfq] [ 78.668718][ T363] Code: 54 c0 e8 dd 90 00 f1 48 c7 c7=
    e0 03 54 c0 48 89 de e8 ce 90 00 f1 48 8d 7b 48 b8 ff ff 37 00 48 89 fa 48=
    c1 e0 2a 48 c1 ea 03 &lt;80&gt; 3c 02 00 74 05 e8 ef a1 e1 f1 48 8b 7b 48 =
    48 8d 54 24 58 48 8d [ 78.669312][ T363] RSP: 0018:ffff88810de573e0 EFLAGS:=
    00010216 [ 78.669533][ T363] RAX: dffffc0000000000 RBX: 0000000000000000 R= CX: 0000000000000000 [ 78.669790][ T363] RDX: 0000000000000009 RSI: 0000000= 000000004 RDI: 0000000000000048 [ 78.670044][ T363] RBP: ffff888110dc4000 R= 08: ffffffffb1b0885a R09: fffffbfff6ba9078 [ 78.670297][ T363] R10: 0000000= 000000003 R11: ffff888110e31c80 R12: 0000001880000000 [ 78.670560][ T363] R= 13: ffff888110dc4150 R14: ffff888110dc42b8 R15: 0000000000000200 [ 78.67081= 4][ T363] FS: 00007f66a8f09c40(0000) GS:ffff888163428000(0000) knlGS:000000= 0000000000 [ 78.671110][ T363] CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005= 0033 [ 78.671324][ T363] CR2: 000055db4c6a30a8 CR3: 000000010da67000 CR4: 0= 000000000750ef0 [ 78.671585][ T363] PKRU: 55555554 [ 78.671713][ T363] Call=
    Trace: [ 78.671843][ T363] &lt;TASK&gt; [ 78.671936][ T363] ? __pfx_qfq_de= queue+0x10/0x10 [sch_qfq] [ 78.672148][ T363] ? __pfx__printk+0x10/0x10 [ 7= 8.672322][ T363] ? srso_alias_return_thunk+0x5/0xfbef5 [ 78.672496][ T363] =
    ? lockdep_hardirqs_on_prepare+0xa8/0x1a0 [ 78.672706][ T363] ? srso_alias_r= eturn_thunk+0x5/0xfbef5 [ 78.672875][ T363] ? trace_hardirqs_on+0x19/0x1a0 =
    [ 78.673047][ T363] red_dequeue+0x65/0x270 [sch_red] [ 78.673217][ T363] ? = srso_alias_return_thunk+0x5/0xfbef5 [ 78.673385][ T363] tbf_dequeue.cold+0x= b0/0x70c [sch_tbf] [ 78.673566][ T363] __qdisc_run+0x169/0x1900 The right t= hing to do in #1b is to grab the skb off gso_skb queue. This patchset fixes=
    that issue by changing #1b to use qdisc_dequeue_peeked() method instead.</=

    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43496" target=3D= "_blank" rel=3D"noopener">CVE-2026-43496</a></td>

    <a href=3D"https://git.kernel.org/stable/c/36aa34f42cb6842cf371f3a2d3e855d2= 4fd57a50" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/36aa34f42cb6842cf371f3a2d3e855d24fd57a50</a><br><a href=3D"https://git.ke= rnel.org/stable/c/ce051eede433f876d322ac3550a36a3c6fc4c231" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/ce051eede433f876d322ac3= 550a36a3c6fc4c231</a><br><a href=3D"https://git.kernel.org/stable/c/8d09618= 840b99ef00154d3e731ce9b11e096196d" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/8d09618840b99ef00154d3e731ce9b11e096196d</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/587dcf970a525f543d8b5855d9f37a4c= a97b76ef" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/587dcf970a525f543d8b5855d9f37a4ca97b76ef</a><br><a href=3D"https://git.ke= rnel.org/stable/c/458d5615272d3de535748342eb68ca492343048c" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/458d5615272d3de53574834= 2eb68ca492343048c</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: fbd= ev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_m= map() uses remap_pfn_range() to map vmalloc framebuffer pages to userspace = but sets no vm_ops on the VMA. This means the kernel cannot track active mm= aps. When dlfb_realloc_framebuffer() replaces the backing buffer via FBIOPU= T_VSCREENINFO, existing mmap PTEs are not invalidated. On USB disconnect, d= lfb_ops_destroy() calls vfree() on the old pages while userspace PTEs still=
    reference them, resulting in a use-after-free: the process retains read/wr= ite access to freed kernel pages. Add vm_operations_struct with open/close = callbacks that maintain an atomic mmap_count on struct dlfb_data. In dlfb_r= ealloc_framebuffer(), check mmap_count and return -EBUSY if the buffer is c= urrently mapped, preventing buffer replacement while userspace holds stale = PTEs. Tested with PoC using dummy_hcd + raw_gadget USB device emulation.</t=

    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43497" target=3D= "_blank" rel=3D"noopener">CVE-2026-43497</a></td>

    <a href=3D"https://git.kernel.org/stable/c/4f312c30f0368e8d2a76aa650dff73f2= 3490b5e7" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/4f312c30f0368e8d2a76aa650dff73f23490b5e7</a><br><a href=3D"https://git.ke= rnel.org/stable/c/18dd358de72d57993422cbb5dfb29ccd74efe192" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/18dd358de72d57993422cbb= 5dfb29ccd74efe192</a><br><a href=3D"https://git.kernel.org/stable/c/da9b065= cedfd3b574f229d5be594e6aa47a27ae6" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/da9b065cedfd3b574f229d5be594e6aa47a27ae6</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/a2c53a3822ee26e8d758071815b9ed3b= f6669fc1" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/a2c53a3822ee26e8d758071815b9ed3bf6669fc1</a><br><a href=3D"https://git.ke= rnel.org/stable/c/8de779dc40d35d39fa07387b6f921eb11df0f511" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/8de779dc40d35d39fa07387= b6f921eb11df0f511</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: acc= el/ivpu: Disallow re-exporting imported GEM objects Prevent re-exporting of=
    imported GEM buffers by adding a custom prime_handle_to_fd callback that c= hecks if the object is imported and returns -EOPNOTSUPP if so. Re-exporting=
    imported GEM buffers causes loss of buffer flags settings, leading to inco= rrect device access and data corruption.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43498" target=3D= "_blank" rel=3D"noopener">CVE-2026-43498</a></td>

    <a href=3D"https://git.kernel.org/stable/c/3756043dd695bba34cc728cdc5688dcb= 49ac8043" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/3756043dd695bba34cc728cdc5688dcb49ac8043</a><br><a href=3D"https://git.ke= rnel.org/stable/c/7dd57d7a6350770dfc283287125c409e995200e0" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/7dd57d7a6350770dfc28328= 7125c409e995200e0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: rtm= utex: Use waiter::task instead of current in remove_waiter() remove_waiter(=
    ) is used by the slowlock paths, but it is also used for proxy-lock rollbac=
    k in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the = latter case waiter::task is not current, but remove_waiter() operates on cu= rrent for the dequeue operation. That results in several problems: 1) the r= btree dequeue happens without waiter::task::pi_lock being held 2) the waite=
    r task's pi_blocked_on state is not cleared, which leaves a dangling pointe=
    r primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wr= ong top priority waiter task Use waiter::task instead of current in all rel= ated operations in remove_waiter() to cure those problems. [ tglx: Fixup rt= _mutex_adjust_prio_chain(), add a comment and amend the changelog ]</td> <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43499" target=3D= "_blank" rel=3D"noopener">CVE-2026-43499</a></td>

    <a href=3D"https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d= 71f9611f" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f</a><br><a href=3D"https://git.ke= rnel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51= f8fcf2071b8085166</a><br><a href=3D"https://git.kernel.org/stable/c/3fb7394= a837740770f0d6b4b30567e60786a63f2" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095= ba17ac11" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/88614876370aac8ad1050ad785a4c095ba17ac11</a><br><a href=3D"https://git.ke= rnel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8= c280c0f3b5ae7d349</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: ipv=
    6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_r= cv() decompresses an RFC 6554 Source Routing Header, swaps the next segment=
    into ipv6_hdr-&gt;daddr, recompresses, then pulls the old header and pushe=
    s the new one plus the IPv6 header back. The recompressed header can be lar= ger than the received one when the swap reduces the common-prefix length th=
    e segments share with daddr (CmprI=3D0, CmprE&gt;0, seg[0][0] !=3D daddr[0]=
    gives the maximum +8 bytes). pskb_expand_head() was gated on segments_left=
    =3D=3D 0, so on earlier segments the push consumed unchecked headroom. Onc=
    e skb_push() leaves fewer than skb-&gt;mac_len bytes in front of data, skb_= mac_header_rebuild()'s call to: skb_set_mac_header(skb, -skb-&gt;mac_len); = will store (data - head) - mac_len into the u16 mac_header field, which wra=
    ps to ~65530, and the following memmove() writes mac_len bytes ~64KiB past = skb-&gt;head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a=
    two segment type-3 SRH (CmprI=3D0, CmprE=3D15) reaches headroom 8 after on=
    e pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by ex= panding the head whenever the remaining room is less than the push size plu=
    s mac_len, and request that much extra so the rebuilt MAC header fits after= wards.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43501" target=3D= "_blank" rel=3D"noopener">CVE-2026-43501</a></td>

    <a href=3D"https://git.kernel.org/stable/c/8e8be63465a5e80394c70324603dfea1= bfdad48f" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/8e8be63465a5e80394c70324603dfea1bfdad48f</a><br><a href=3D"https://git.ke= rnel.org/stable/c/4babc2d9fda2df43823b85d08a0180b68f1b0854" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/4babc2d9fda2df43823b85d= 08a0180b68f1b0854</a><br><a href=3D"https://git.kernel.org/stable/c/c261d07= a80576dc8ccf394ef8f074f8c67a06b37" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/c261d07a80576dc8ccf394ef8f074f8c67a06b37</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/7398ebefbfd4f8a31d4f665a4213302f= a995494b" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/7398ebefbfd4f8a31d4f665a4213302fa995494b</a><br><a href=3D"https://git.ke= rnel.org/stable/c/9e6bf146b55999a095bb14f73a843942456d1adc" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/9e6bf146b55999a095bb14f= 73a843942456d1adc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net= /rds: handle zerocopy send cleanup before the message is queued A zerocopy = send can fail after user pages have been pinned but before the message is a= ttached to the sending socket. The purge path currently infers zerocopy sta=
    te from rm-&gt;m_rs, so an unqueued message can be cleaned up as if it owne=
    d normal payload pages. However, zerocopy ownership is really determined by=
    the presence of op_mmp_znotifier, regardless of whether the message has re= ached the socket queue. Capture op_mmp_znotifier up front in rds_message_pu= rge() and use it as the cleanup discriminator. If the message is already as= sociated with a socket, keep the existing completion path. Otherwise, drop = the pinned page accounting directly and release the notifier before putting=
    the payload pages. This keeps early send failure cleanup consistent with t=
    he zerocopy lifetime rules without changing the normal queued completion pa= th.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43502" target=3D= "_blank" rel=3D"noopener">CVE-2026-43502</a></td>

    <a href=3D"https://git.kernel.org/stable/c/21d70744e6d3bbf9293aa1ee6fba7c53= ad75275e" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/21d70744e6d3bbf9293aa1ee6fba7c53ad75275e</a><br><a href=3D"https://git.ke= rnel.org/stable/c/3abc8983b2bae3f487f77d9da5527d7d6b210d46" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/3abc8983b2bae3f487f77d9= da5527d7d6b210d46</a><br><a href=3D"https://git.kernel.org/stable/c/14ef6fd= 18db2494098b21e0471bf27a1d8e9993e" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/14ef6fd18db2494098b21e0471bf27a1d8e9993e</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/0f5c185fc79a59ee9991234dd6d2a3e5= afa6e75b" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/0f5c185fc79a59ee9991234dd6d2a3e5afa6e75b</a><br><a href=3D"https://git.ke= rnel.org/stable/c/44b550d88b267320459d518c0743a241ab2108fa" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/44b550d88b267320459d518= c0743a241ab2108fa</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net=
    : skbuff: propagate shared-frag marker through frag-transfer helpers Two fr= ag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagat=
    e the SKBFL_SHARED_FRAG bit in skb_shinfo()-&gt;flags when moving frags fro=
    m source to destination. __pskb_copy_fclone() defers the rest of the shinfo=
    metadata to skb_copy_header() after copying frag descriptors, but that hel= per only carries over gso_{size,segs, type} and never touches skb_shinfo()-= &gt;flags; skb_shift() moves frag descriptors directly and leaves flags unt= ouched. As a result, the destination skb keeps a reference to the same exte= rnally-owned or page-cache-backed pages while reporting skb_has_shared_frag=
    () as false. The mismatch is harmful in any in-place writer that uses skb_h= as_shared_frag() to decide whether shared pages must be detoured through sk= b_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and a single n=
    ft 'dup to &lt;local&gt;' rule -- or any other nf_dup_ipv4() / xt_TEE calle=
    r -- is enough to land a pskb_copy()'d skb in esp_input() with the marker s= tripped, letting an unprivileged user write into the page cache of a root-o= wned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG =
    on the destination whenever frag descriptors were actually moved from the s= ource. skb_copy() and skb_copy_expand() share skb_copy_header() too but lin= earize all paged data into freshly allocated head storage and emerge with n= r_frags =3D=3D 0, so skb_has_shared_frag() returns false on its own; they n= eed no change. The same omission exists in skb_gro_receive() and skb_gro_re= ceive_list(). The former moves the incoming skb's frag descriptors into the=
    accumulator's last sub-skb via two paths (a direct frag-move loop and the = head_frag + memcpy path); the latter chains the incoming skb whole onto p's=
    frag_list. Downstream skb_segment() reads only skb_shinfo(p)-&gt;flags, an=
    d skb_segment_list() reuses each sub-skb's shinfo as the nskb -- both p and=
    lp must carry the marker. The same omission also exists in tcp_clone_paylo= ad(), which builds an MTU probe skb by moving frag descriptors from skbs on=
    sk_write_queue into a freshly allocated nskb. The helper falls into the sa=
    me family and warrants the same fix for consistency; no TCP TX-side in-plac=
    e writer is currently known to reach a user page through this gap, but a fu= ture consumer depending on the marker would regress silently. The same omis= sion exists in skb_segment(): the per-iteration flag merge takes only head_= skb's flag, and the inner switch that rebinds frag_skb to list_skb on head_= skb-frags exhaustion does not fold the new frag_skb's flag into nskb. Fold = frag_skb's flag at both sites so segments drawing frags from frag_list memb= ers carry the marker.</td>
    <td>2026-05-23</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-43503" target=3D= "_blank" rel=3D"noopener">CVE-2026-43503</a></td>

    <a href=3D"https://git.kernel.org/stable/c/fbeab9555564a1b98e8582cd106dfe46= c4606991" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/fbeab9555564a1b98e8582cd106dfe46c4606991</a><br><a href=3D"https://git.ke= rnel.org/stable/c/179f1852bdedc300e373e807cc102cd81feff196" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/179f1852bdedc300e373e80= 7cc102cd81feff196</a><br><a href=3D"https://git.kernel.org/stable/c/12401fc= fb01f53ccc63ab0a3246570fe8f3105ee" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/12401fcfb01f53ccc63ab0a3246570fe8f3105ee</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/989214c66884d70716d83dc1d0bf5e16= 287bf349" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/989214c66884d70716d83dc1d0bf5e16287bf349</a><br><a href=3D"https://git.ke= rnel.org/stable/c/fc6eb39c55e97df2f94ad974b8a5bbcd019da2c8" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/fc6eb39c55e97df2f94ad97= 4b8a5bbcd019da2c8</a><br><a href=3D"https://git.kernel.org/stable/c/ff375cc= 75f9167168db38e0464a482d5fbc8d81d" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/ff375cc75f9167168db38e0464a482d5fbc8d81d</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/9bc9d6d6967a2239aa57af2aa53554ed= dd640d20" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/9bc9d6d6967a2239aa57af2aa53554eddd640d20</a><br><a href=3D"https://git.ke= rnel.org/stable/c/48f6a5356a33dd78e7144ae1faef95ffc990aae0" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/48f6a5356a33dd78e7144ae= 1faef95ffc990aae0</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Linux--Linux</td>
    <td>In the Linux kernel, the following vulnerability has been resolved: net=
    : skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() = can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG se=
    t, the resulting @to skb can contain the same externally-owned or page-cach= e-backed frags, but the shared-frag marker is currently lost. That breaks t=
    he invariant relied on by later in-place writers. In particular, ESP input = checks skb_has_shared_frag() before deciding whether an uncloned nonlinear = skb can skip skb_cow_data(). If TCP receive coalescing has moved shared fra=
    gs into an unmarked skb, ESP can see skb_has_shared_frag() as false and dec= rypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG whe=
    n skb_try_coalesce() transfers paged frags. The tailroom copy path does not=
    need the marker because it copies bytes into @to's linear data rather than=
    transferring frag descriptors.</td>
    <td>2026-05-23</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46300" target=3D= "_blank" rel=3D"noopener">CVE-2026-46300</a></td>

    <a href=3D"https://git.kernel.org/stable/c/3599e6b3cc1ada96883d496a50a210d3= afbb6987" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/3599e6b3cc1ada96883d496a50a210d3afbb6987</a><br><a href=3D"https://git.ke= rnel.org/stable/c/2f2b16022a2e10ca7bccfb98db5ed2ec0f72641c" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/2f2b16022a2e10ca7bccfb9= 8db5ed2ec0f72641c</a><br><a href=3D"https://git.kernel.org/stable/c/9d3e5fd= 19fe1063bf607219e8562fbd567b8e8d5" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/9d3e5fd19fe1063bf607219e8562fbd567b8e8d5</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/78bf6b6bb19541d19fbda6242e7cfe2c= 682763c0" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/78bf6b6bb19541d19fbda6242e7cfe2c682763c0</a><br><a href=3D"https://git.ke= rnel.org/stable/c/760e1addc27ba1a7beb4a0a7e8b3e9ec49e7a34e" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/760e1addc27ba1a7beb4a0a= 7e8b3e9ec49e7a34e</a><br><a href=3D"https://git.kernel.org/stable/c/3bd9e11= 3d50034db99d7ef69fd8e5242d15e414a" target=3D"_blank" rel=3D"noopener">https= ://git.kernel.org/stable/c/3bd9e113d50034db99d7ef69fd8e5242d15e414a</a><br>=
    <a href=3D"https://git.kernel.org/stable/c/3884358a9286b17f389a72b1426fc454= 7c23c111" target=3D"_blank" rel=3D"noopener">https://git.kernel.org/stable/= c/3884358a9286b17f389a72b1426fc4547c23c111</a><br><a href=3D"https://git.ke= rnel.org/stable/c/f84eca5817390257cef78013d0112481c503b4a3" target=3D"_blan=
    k" rel=3D"noopener">https://git.kernel.org/stable/c/f84eca5817390257cef7801= 3d0112481c503b4a3</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">LiteSpeed Technologies--cPanel Plugin</td> <td>LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalati=
    on (possibly to root), as exploited in the wild in May 2026. Detection is b= est done via a command line of grep -rE "cpanel_jsonapi_func=3DredisAble" /= var/cpanel/logs /usr/local/cpanel/logs/ 2&gt;/dev/null in Bash. If you get =
    no output, you have not been hit with exploitation of the vulnerability. If=
    there is output, we recommend you examine the IP addresses in the list, de= termine if they are valid IP addresses, and if not, block them. To determin=
    e damage done, examine the system logs for use by the detected IP addresses=
    . The issue is related to mishandling of Redis enable/disable features. The=
    recommended minimum version is 2.4.7.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48172" target=3D= "_blank" rel=3D"noopener">CVE-2026-48172</a></td>

    <a href=3D"https://www.litespeedtech.com/products/litespeed-web-server/cont= rol-panel-support/cpanel" target=3D"_blank" rel=3D"noopener">https://www.li= tespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel<= /a><br><a href=3D"https://www.litespeedtech.com/products/litespeed-web-serv= er/control-panel-support/release-log" target=3D"_blank" rel=3D"noopener">ht= tps://www.litespeedtech.com/products/litespeed-web-server/control-panel-sup= port/release-log</a><br><a href=3D"https://blog.litespeedtech.com/2026/05/2= 1/security-update-for-litespeed-cpanel-plugin/" target=3D"_blank" rel=3D"no= opener">https://blog.litespeedtech.com/2026/05/21/security-update-for-lites= peed-cpanel-plugin/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">lostisland--faraday</td>
    <td>Faraday is an HTTP client library abstraction layer that provides a com= mon interface over many adapters. Versions 2.0.0 through 2.14.1 still allow=
    protocol-relative host override when the request target is passed as a URI=
    object (rather than a String) to Faraday::Connection#build_exclusive_url. = This bypasses the February 2026 fix for GHSA-33mh-2634-fwr2 and enables off= -host request forgery: a request built from a fixed-base Faraday::Connectio=
    n can be redirected to an attacker-controlled host, forwarding connection-s= coped values such as Authorization headers and default query parameters. Th=
    is issue has been fixed in version 2.14.3.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33637" target=3D= "_blank" rel=3D"noopener">CVE-2026-33637</a></td>

    <a href=3D"https://github.com/lostisland/faraday/security/advisories/GHSA-5= rv5-xj5j-3484" target=3D"_blank" rel=3D"noopener">https://github.com/lostis= land/faraday/security/advisories/GHSA-5rv5-xj5j-3484</a><br><a href=3D"http= s://github.com/advisories/GHSA-33mh-2634-fwr2" target=3D"_blank" rel=3D"noo= pener">https://github.com/advisories/GHSA-33mh-2634-fwr2</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">LXQt--PCManFM-Qt</td>
    <td>An issue was discovered in all versions of PCManFM-Qt starting from 1.1= .0. When a regular file's path is passed as a URI in an org.freedesktop.Fil= eManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a differen=
    t program (based on the file type) without user confirmation. This could be=
    used to achieve code execution or circumvent network namespace restriction=
    s. NOTE: those outcomes are potentially unwanted by most users; however, th=
    e behavior of the product does comply with the applicable specification, an=
    d a simplistic solution (ensuring that the URI does not name a regular file=
    ) may have adverse consequences for I/O.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48700" target=3D= "_blank" rel=3D"noopener">CVE-2026-48700</a></td>

    <a href=3D"https://www.openwall.com/lists/oss-security/2026/05/20/2" target= =3D"_blank" rel=3D"noopener">https://www.openwall.com/lists/oss-security/20= 26/05/20/2</a><br><a href=3D"https://www.openwall.com/lists/oss-security/20= 26/05/19/1" target=3D"_blank" rel=3D"noopener">https://www.openwall.com/lis= ts/oss-security/2026/05/19/1</a><br><a href=3D"https://github.com/lxqt/pcma= nfm-qt/releases" target=3D"_blank" rel=3D"noopener">https://github.com/lxqt= /pcmanfm-qt/releases</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">M-Files Corporation--M-Files Server</td> <td>Denial-of-service condition in M-Files Server versions before 26.5.1601= 5.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user =
    to cause the MFserver process to crash</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-0983" target=3D"= _blank" rel=3D"noopener">CVE-2026-0983</a></td>

    <a href=3D"https://empower.m-files.com/security-advisories/CVE-2026-0983" t= arget=3D"_blank" rel=3D"noopener">https://empower.m-files.com/security-advi= sories/CVE-2026-0983</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mailcow--mailcow-dockerized</td> <td>mailcow-dockerized contains a stored cross-site scripting vulnerability=
    in the administrator Queue Manager. The Queue Manager fetches mail queue e= ntries from /api/v1/get/mailq/all, copies server-controlled Postfix queue f= ields into DataTables rows, and renders several of those fields as HTML wit= hout adequate output encoding. This issue affects mailcow-dockerized: 2026-= 03b.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7460" target=3D"= _blank" rel=3D"noopener">CVE-2026-7460</a></td>

    <a href=3D"https://fluidattacks.com/advisories/mojabi" target=3D"_blank" re= l=3D"noopener">https://fluidattacks.com/advisories/mojabi</a><br><a href=3D= "https://github.com/mailcow/mailcow-dockerized" target=3D"_blank" rel=3D"no= opener">https://github.com/mailcow/mailcow-dockerized</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "= add_profile_threshold" permission to create a global profile despite not ha= ving manage_global_profile_threshold, by tampering with the user_id paramet=
    er in a valid profile creation request. This issue has been fixed in versio=
    n 2.28.2.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33052" target=3D= "_blank" rel=3D"noopener">CVE-2026-33052</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-68= w5-w573-q2r8" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-68w5-w573-q2r8</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/3f952e68fa864e0e60abc3e84adecf3cfa84c= 75e" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/3f952e68fa864e0e60abc3e84adecf3cfa84c75e</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36974" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36974</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and prior have a Privilege Escalation vulnerability where insuffici= ent access control checks in ProjectUsersAddCommand (manage_proj_user_add.p= hp) allow users having manage_project_threshold access level (manager by de= fault) to grant project-level administrator access to any user (including t= hemselves) in any Project they have manager rights in. The normal project-u= ser add form restricts the selectable access levels to the actor's own proj= ect role or below. However, the backend handler still accepts a forged high=
    er access_level value and writes it. The consequences of the privilege esca= lation are slight, as having administrator access at Project level is effec= tively not very different from being manager, and it does not actually give=
    administrator privileges on the whole MantisBT instance. In particular, it=
    does not let the upgraded user delete the Project or grant them any access=
    to global administrative functions such as managing Users, Projects, Plugi= ns, Custom Fields, etc. This issue has been fixed in version 2.28.2.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34390" target=3D= "_blank" rel=3D"noopener">CVE-2026-34390</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-fr= f7-jhp9-jxm6" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-frf7-jhp9-jxm6</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/69e0180f180ed5acf48a8d281a73683a7bf32= 461" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/69e0180f180ed5acf48a8d281a73683a7bf32461</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36995" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36995</a><br><a href=3D"https://man= tisbt.org/bugs/view.php?id=3D37002" target=3D"_blank" rel=3D"noopener">http= s://mantisbt.org/bugs/view.php?id=3D37002</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue=
    originating from a Project other than the current one, the clone form (bug= _report_page.php) prepends the source Project name before the category sele= ctor without proper escaping, allowing an attacker able to to inject HTML i=
    f they can set the Project's name (which typically requires manager or admi= nistrator access level). This issue has been resolved in version 2.28.2.</t=

    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34463" target=3D= "_blank" rel=3D"noopener">CVE-2026-34463</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-fv= jf-68wh-rwp2" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-fvjf-68wh-rwp2</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/df22697ae497ddd93f3d9132fdf4979db8d08= 1cd" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/df22697ae497ddd93f3d9132fdf4979db8d081cd</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36986" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36986</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and prior are vulnerable to Authorization Bypass through the privat=
    e issue monitoring feature . Using a crafted POST request to bug_monitor_ad= d.php, a user with project-level access can add themselves as a monitor for=
    a private issue they do not have access to. Despite displaying an Access D= enied error, the application accepts the request and creates a monitor rela= tionship for the private issue. Direct access to the private issue remains = blocked, but the user will receive email notifications for updates, leading=
    to disclosure of the private issue's metadata and content. This issue has = been fixed in version 2.28.2.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34579" target=3D= "_blank" rel=3D"noopener">CVE-2026-34579</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-gg= w7-9675-6v4v" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-ggw7-9675-6v4v</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/0a93267deba445fb9d15250c16e6fdb1246ff= a65" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/0a93267deba445fb9d15250c16e6fdb1246ffa65</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36975" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36975</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and prior permit a user to list and download their own attachments = from an Issue created by another user even after it becomes private, bypass= ing read access revocation. The loss of confidentiality caused by this vuln= erability is minimal, considering that only attachments previously uploaded=
    by the user themselves remain accessible. This issue has been fixed in ver= sion 2.82.2.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34744" target=3D= "_blank" rel=3D"noopener">CVE-2026-34744</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-rm= p5-5jj7-gmvf" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-rmp5-5jj7-gmvf</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/de7bdeec36de066235e38a77bf056917d951c= 84d" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/de7bdeec36de066235e38a77bf056917d951c84d</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36977" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36977</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.28.1 and prior allow a bugnote author to access the note's Revisions pag=
    e after losing access to the parent private issue. This issue has been fixe=
    d in version 2.28.2.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-34970" target=3D= "_blank" rel=3D"noopener">CVE-2026-34970</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-cr= mx-4p49-46m2" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-crmx-4p49-46m2</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/71df1f67e05b2050cd4bd87839e6cc13747cf= 03f" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/71df1f67e05b2050cd4bd87839e6cc13747cf03f</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D36978" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D36978</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions=
    2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTM=
    L by updating their account's font family. Upon exploitation, an XSS payloa=
    d would be reflected on every MantisBT page. Leveraging another vulnerabili=
    ty (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacker could achieve accoun=
    t takeover. This issue has been fixed in version 2.28.2.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40596" target=3D= "_blank" rel=3D"noopener">CVE-2026-40596</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-j3= v9-553h-x28j" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-j3v9-553h-x28j</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3" tar= get=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisbt/securi= ty/advisories/GHSA-9c3j-xm6v-j7j3</a><br><a href=3D"https://github.com/mant= isbt/mantisbt/commit/9e8409cdd979eba86ef532756fc47c1d8112d22d" target=3D"_b= lank" rel=3D"noopener">https://github.com/mantisbt/mantisbt/commit/9e8409cd= d979eba86ef532756fc47c1d8112d22d</a><br><a href=3D"https://mantisbt.org/bug= s/view.php?id=3D37011" target=3D"_blank" rel=3D"noopener">https://mantisbt.= org/bugs/view.php?id=3D37011</a><br><a href=3D"https://mantisbt.org/bugs/vi= ew.php?id=3D37016" target=3D"_blank" rel=3D"noopener">https://mantisbt.org/= bugs/view.php?id=3D37016</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versi= ons 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerabi= lity, an attacker can bypass the Content Security Policy's script-src direc= tive by uploading a crafted attachment to any issue that, when accessed via=
    the file_download.php link, will be downloaded with a valid JavaScript MIM=
    E type resulting in script execution. The uploaded payload must be sniffed =
    as a valid JavaScript MIME type by PHP finfo (see file_create_finfo() API f= unction). Non-JavaScript MIME types will not get imported in a &lt;script&g=
    t; tag by the browser, due to response header X-Content-Type-Options being = set to nosniff, which requires all imported JavaScript files to be a valid = JavaScript MIME type. This issue has been fixed in version 2.28.2.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40597" target=3D= "_blank" rel=3D"noopener">CVE-2026-40597</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c= 3j-xm6v-j7j3" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/9e3bee2e7b909f4e3596985892b8bc8bee9e0= bfe" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/9e3bee2e7b909f4e3596985892b8bc8bee9e0bfe</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D37016" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D37016</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versi= ons 2.28.1 and below, improper escaping of the redirection page (retrieved = from the request's Referer header) allows an attacker to inject HTML. While=
    this is generally not directly actionable as modern browsers will URL-enco=
    de special characters, on some specific server configurations this could po= ison the cache, leading to cross-site scripting. This issue has been fixed =
    in version 2.28.2.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40598" target=3D= "_blank" rel=3D"noopener">CVE-2026-40598</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-6j= h4-47v2-4g37" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-6jh4-47v2-4g37</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/b1ebc57763f104eb5f541b7b4d1ce6948168a= bd9" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/b1ebc57763f104eb5f541b7b4d1ce6948168abd9</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D37017" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D37017</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mantisbt--mantisbt</td>
    <td>Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versi= ons 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrec=
    t escaping of a saved filter's owner, allowing an attacker to inject arbitr= ary HTML on systems where $g_show_user_realname =3D ON. Note that By defaul=
    t, only users with Manager access level or above can save their filters pub= licly. This issue has been fixed in version 2.28.2. If developers are unabl=
    e to update immediately, they can work around this issue by preventing disp= lay of users' real names (set $g_ show_user_realname =3D OFF; in configurat= ion), and restricting the ability to store filters (set $g_stored_query_cre= ate_threshold / $g_stored_query_create_shared_threshold to NOBODY).</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40607" target=3D= "_blank" rel=3D"noopener">CVE-2026-40607</a></td>

    <a href=3D"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-f6= 33-865q-2mhh" target=3D"_blank" rel=3D"noopener">https://github.com/mantisb= t/mantisbt/security/advisories/GHSA-f633-865q-2mhh</a><br><a href=3D"https:= //github.com/mantisbt/mantisbt/commit/44f490bcf20fd491c1b8f3fc9dd041d8c2a30= 010" target=3D"_blank" rel=3D"noopener">https://github.com/mantisbt/mantisb= t/commit/44f490bcf20fd491c1b8f3fc9dd041d8c2a30010</a><br><a href=3D"https:/= /mantisbt.org/bugs/view.php?id=3D37015" target=3D"_blank" rel=3D"noopener">= https://mantisbt.org/bugs/view.php?id=3D37015</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mermaid-js--mermaid</td>
    <td>Mermaid is a JavaScript tool that uses Markdown-inspired text to create=
    and modify diagrams and charts. Versions 10.9.5 and prior, in addition to = 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through impr= oper sanitization. The state diagram (and any other diagram type that route=
    s user-controlled style strings through the createCssStyles parser) capture=
    s classDef values using an unrestricted regex that matches everything up to=
    a newline. That value then flows unsanitized through addStyleClass() into = createCssStyles() and is assigned to style.innerHTML, so a closing brace (}=
    ) in the value terminates the generated CSS selector and turns everything a= fter it into a new CSS rule on the page. This enables page defacement, user=
    tracking via url() callbacks, and DOM attribute exfiltration. This issue h=
    as been fixed in versions 10.9.6 and 11.15.0. If developers are unable to i= mmediately upgrade, they can work around this issue by setting "securityLev= el": "sandbox", which prevents the issue by rendering the mermaid diagram i=
    n a sandboxed &lt;iframe&gt;.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41148" target=3D= "_blank" rel=3D"noopener">CVE-2026-41148</a></td>

    <a href=3D"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-x= cj9-5m2h-648r" target=3D"_blank" rel=3D"noopener">https://github.com/mermai= d-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r</a><br><a href=3D"http= s://github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2= 859102" target=3D"_blank" rel=3D"noopener">https://github.com/mermaid-js/me= rmaid/commit/8fead23c59166b7bab6a39eac81acebee2859102</a><br><a href=3D"htt= ps://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d9= 0957a0f" target=3D"_blank" rel=3D"noopener">https://github.com/mermaid-js/m= ermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f</a><br><a href=3D"ht= tps://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0" target= =3D"_blank" rel=3D"noopener">https://github.com/mermaid-js/mermaid/releases= /tag/mermaid%4011.15.0</a><br><a href=3D"https://github.com/mermaid-js/merm= aid/releases/tag/v10.9.6" target=3D"_blank" rel=3D"noopener">https://github= .com/mermaid-js/mermaid/releases/tag/v10.9.6</a><br><a href=3D"https://merm= aid.js.org/config/schema-docs/config.html#securitylevel" target=3D"_blank" = rel=3D"noopener">https://mermaid.js.org/config/schema-docs/config.html#secu= ritylevel</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mermaid-js--mermaid</td>
    <td>Mermaid is a JavaScript tool that uses Markdown-inspired text to create=
    and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11= .0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the de= fault configuration. Specifically, the classDef directive in Mermaid state = diagrams permits DOM injection that escapes the SVG context. However, &lt;s= cript&gt; tags are stripped, which prevents cross-site scripting (XSS). Thi=
    s issue has been fixed in versions 10.9.6 and 11.15.0. If developers are un= able to immediately upgrade, they can work around this issue by setting "se= curityLevel": "sandbox", which prevents the issue by rendering the mermaid = diagram in a sandboxed &lt;iframe&gt;.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41149" target=3D= "_blank" rel=3D"noopener">CVE-2026-41149</a></td>

    <a href=3D"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-g= hcm-xqfw-q4vr" target=3D"_blank" rel=3D"noopener">https://github.com/mermai= d-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr</a><br><a href=3D"http= s://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d0= 1f4056" target=3D"_blank" rel=3D"noopener">https://github.com/mermaid-js/me= rmaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056</a><br><a href=3D"htt= ps://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d= 09ac4f3" target=3D"_blank" rel=3D"noopener">https://github.com/mermaid-js/m= ermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">misp--misp</td>
    <td>MISP's OIDC authentication plugin allowed automatic linking of an OIDC = identity to an existing local user account based on the email claim when th=
    e local account had no stored sub value. Under insecure or untrusted IdP co= nfigurations where email ownership is not enforced, an attacker with a vali=
    d OIDC token could assert a victim's email address and authenticate as that=
    user, leading to account takeover.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9084" target=3D"= _blank" rel=3D"noopener">CVE-2026-9084</a></td>

    <a href=3D"https://github.com/MISP/MISP/commit/71f5662c1b5886613d2cd5c72fd9= 3bb4ca6fa172" target=3D"_blank" rel=3D"noopener">https://github.com/MISP/MI= SP/commit/71f5662c1b5886613d2cd5c72fd93bb4ca6fa172</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">misp--misp</td>
    <td>A vulnerability was identified in the ShadowAttribute proposal creation=
    workflow. The add action accepted user-controlled ShadowAttribute request = data without removing the id field before saving the record. Because the un= derlying framework treats a supplied primary key as an instruction to updat=
    e an existing record, an authenticated user able to submit shadow attribute=
    proposals could provide the identifier of an existing ShadowAttribute and = cause that record to be updated instead of creating a new proposal. This ca=
    n result in unauthorized modification of existing shadow attributes, potent= ially affecting proposals associated with events the user should not be abl=
    e to alter. Depending on deployment configuration and accessible API respon= ses, the issue may also expose or move proposal data across event contexts.=
    The vulnerability is caused by trusting a client-supplied primary key duri=
    ng object creation. The fix removes the id field from incoming ShadowAttrib= ute data before processing, ensuring that the endpoint always creates a new=
    proposal rather than updating an existing one. This has been fixed in MISP=
    2.5.38.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9136" target=3D"= _blank" rel=3D"noopener">CVE-2026-9136</a></td>

    <a href=3D"https://github.com/MISP/MISP/commit/49911b1d4b6e4517d803e50e3d98= 0aaa4d37c16d" target=3D"_blank" rel=3D"noopener">https://github.com/MISP/MI= SP/commit/49911b1d4b6e4517d803e50e3d980aaa4d37c16d</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">misp--misp</td>
    <td>The CSP report endpoint intended to limit logged CSP reports to 1 KB bu=
    t incorrectly allowed reports up to 1 MB before truncation. On deployments = where the endpoint is reachable by untrusted clients, this could allow atta= ckers to generate excessive log volume and contribute to resource exhaustio=
    n or log flooding.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9137" target=3D"= _blank" rel=3D"noopener">CVE-2026-9137</a></td>

    <a href=3D"https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e= 363d30db0ec9" target=3D"_blank" rel=3D"noopener">https://github.com/MISP/MI= SP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mlflow--mlflow/mlflow</td>
    <td>In MLflow version 3.9.0, the MLflow Assistant feature introduced improp=
    er origin validation in its /ajax-api endpoints. This vulnerability allows =
    a remote attacker to exploit cross-origin requests from a malicious webpage=
    to interact with the MLflow Assistant running on a victim's local machine.=
    By bypassing the loopback-only restriction, the attacker can modify the As= sistant's configuration to enable full access, which in turn allows the exe= cution of arbitrary commands via the Claude Code sub-agent. This issue is r= esolved in version 3.10.0.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2611" target=3D"= _blank" rel=3D"noopener">CVE-2026-2611</a></td>

    <a href=3D"https://huntr.com/bounties/8462addd-b464-4a84-b6a2-5529604e6e5a"=
    target=3D"_blank" rel=3D"noopener">https://huntr.com/bounties/8462addd-b46= 4-4a84-b6a2-5529604e6e5a</a><br><a href=3D"https://github.com/mlflow/mlflow= /commit/8f9c8a53af90842944101eb8b7d60706822c81bc" target=3D"_blank" rel=3D"= noopener">https://github.com/mlflow/mlflow/commit/8f9c8a53af90842944101eb8b= 7d60706822c81bc</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mlflow--mlflow/mlflow</td>
    <td>In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST A=
    PI endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper p= er-model authorization checks when basic authentication is enabled. This al= lows any authenticated user to enumerate all model versions across all regi= stered models, regardless of their permission level. The issue arises due t=
    o the absence of `SearchModelVersions` in the `BEFORE_REQUEST_VALIDATORS` a=
    nd `AFTER_REQUEST_HANDLERS` for the REST API, and its omission from `GraphQ= LAuthorizationMiddleware.PROTECTED_FIELDS` for GraphQL. This vulnerability = can expose sensitive information such as model names, version descriptions,=
    source URIs, tags, and other metadata, potentially revealing proprietary o=
    r confidential details in multi-tenant environments. The issue is resolved =
    in version 3.10.0.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-2734" target=3D"= _blank" rel=3D"noopener">CVE-2026-2734</a></td>

    <a href=3D"https://huntr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08"=
    target=3D"_blank" rel=3D"noopener">https://huntr.com/bounties/d632f783-b2c= 7-4a3b-af5e-1d693e841c08</a><br><a href=3D"https://github.com/mlflow/mlflow= /commit/6989066af33fdcb03588fd71a1a67f8fc5ef12c9" target=3D"_blank" rel=3D"= noopener">https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a= 1a67f8fc5ef12c9</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">mlflow--mlflow/mlflow</td>
    <td>In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_d= ir()` function in `mlflow/utils/file_utils.py` creates temporary directorie=
    s with world-writable permissions (0o777), and the `_create_model_downloadi= ng_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories w= ith group-writable permissions (0o770). These insecure permissions allow lo= cal attackers to tamper with model artifacts, such as cloudpickle-serialize=
    d Python objects, and achieve arbitrary code execution when the tampered ar= tifacts are deserialized via `cloudpickle.load()`. This vulnerability is pa= rticularly critical in environments with shared NFS mounts, such as Databri= cks, where NFS is enabled by default. The issue is a continuation of the vu= lnerability class addressed in CVE-2025-10279, which was only partially fix= ed.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-4137" target=3D"= _blank" rel=3D"noopener">CVE-2026-4137</a></td>

    <a href=3D"https://huntr.com/bounties/648dc30b-76c7-4433-86b8-f43d926fd8d6"=
    target=3D"_blank" rel=3D"noopener">https://huntr.com/bounties/648dc30b-76c= 7-4433-86b8-f43d926fd8d6</a><br><a href=3D"https://github.com/mlflow/mlflow= /commit/1dcbb0c2fbd1f446c328830e601ca13a28219b8a" target=3D"_blank" rel=3D"= noopener">https://github.com/mlflow/mlflow/commit/1dcbb0c2fbd1f446c328830e6= 01ca13a28219b8a</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ModelScope--ModelScope 1.25.0</td>
    <td>An issue was discovered in ModelScope 1.25.0 allowing attackers to exec= ute arbitrary code via crafted module listed in the configuration file (dey= _mini.yaml) under the key ['nnet']['module'].</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-51427" target=3D= "_blank" rel=3D"noopener">CVE-2025-51427</a></td>

    <a href=3D"https://github.com/modelscope/modelscope/issues/1331" target=3D"= _blank" rel=3D"noopener">https://github.com/modelscope/modelscope/issues/13= 31</a><br><a href=3D"https://github.com/modelscope/modelscope/pull/1333" ta= rget=3D"_blank" rel=3D"noopener">https://github.com/modelscope/modelscope/p= ull/1333</a><br><a href=3D"https://github.com/JIRUWOZHI/vulnerability-discl= osure/blob/main/CVE-2025-51427/CVE_2025_51427.md" target=3D"_blank" rel=3D"= noopener">https://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/C= VE-2025-51427/CVE_2025_51427.md</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Sandbox escape in Firefox and Firefox Focus for Android. This vulnerabi= lity was fixed in Firefox 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8945" target=3D"= _blank" rel=3D"noopener">CVE-2026-8945</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2003171" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2003171</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Incorrect boundary conditions in the Audio/Video: Web Codecs component.=
    This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox E=
    SR 140.11, Thunderbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8946" target=3D"= _blank" rel=3D"noopener">CVE-2026-8946</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2029070" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2029070</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-47/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-47/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-48/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-50/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-50/</a><br><a href=3D"https://www.mozilla.org/security/advisories/mfsa2= 026-51/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/securit= y/advisories/mfsa2026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerabil= ity was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thund= erbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8947" target=3D"= _blank" rel=3D"noopener">CVE-2026-8947</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2038439" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2038439</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-47/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-47/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-48/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-50/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-50/</a><br><a href=3D"https://www.mozilla.org/security/advisories/mfsa2= 026-51/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/securit= y/advisories/mfsa2026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Same-origin policy bypass in the DOM: Networking component. This vulner= ability was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8948" target=3D"= _blank" rel=3D"noopener">CVE-2026-8948</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2038803" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2038803</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Integer overflow in the Widget: Win32 component. This vulnerability was=
    fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird=
    140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8949" target=3D"= _blank" rel=3D"noopener">CVE-2026-8949</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D1355639" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D1355639</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Same-origin policy bypass in the Networking: HTTP component. This vulne= rability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and=
    Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8950" target=3D"= _blank" rel=3D"noopener">CVE-2026-8950</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D1965430" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D1965430</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Spoofing issue in the Toolbar component in Firefox for Android. This vu= lnerability was fixed in Firefox 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8951" target=3D"= _blank" rel=3D"noopener">CVE-2026-8951</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2018513" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2018513</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Privilege escalation in the Application Update component. This vulnerab= ility was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8952" target=3D"= _blank" rel=3D"noopener">CVE-2026-8952</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2021727" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2021727</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Sandbox escape due to use-after-free in the Disability Access APIs comp= onent. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Fir= efox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8953" target=3D"= _blank" rel=3D"noopener">CVE-2026-8953</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2029511" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2029511</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-47/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-47/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-48/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-50/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-50/</a><br><a href=3D"https://www.mozilla.org/security/advisories/mfsa2= 026-51/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/securit= y/advisories/mfsa2026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Incorrect boundary conditions, integer overflow in the Audio/Video comp= onent. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thu= nderbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8954" target=3D"= _blank" rel=3D"noopener">CVE-2026-8954</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2030747" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2030747</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Privilege escalation in the DOM: Workers component. This vulnerability = was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderb= ird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8955" target=3D"= _blank" rel=3D"noopener">CVE-2026-8955</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2031064" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2031064</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Integer overflow in the Networking: JAR component. This vulnerability w=
    as fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbi=
    rd 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8956" target=3D"= _blank" rel=3D"noopener">CVE-2026-8956</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2032427" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2032427</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Privilege escalation in the Enterprise Policies component. This vulnera= bility was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and T= hunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8957" target=3D"= _blank" rel=3D"noopener">CVE-2026-8957</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2033850" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2033850</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Information disclosure, sandbox escape in the Security: Process Sandbox= ing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140= .11, Thunderbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8958" target=3D"= _blank" rel=3D"noopener">CVE-2026-8958</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2034713" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2034713</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Sandbox escape due to incorrect boundary conditions in the Widget: Win3=
    2 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.1=
    1, Thunderbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8959" target=3D"= _blank" rel=3D"noopener">CVE-2026-8959</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2034754" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2034754</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Spoofing issue in WebExtensions. This vulnerability was fixed in Firefo=
    x 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8960" target=3D"= _blank" rel=3D"noopener">CVE-2026-8960</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D1940116" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D1940116</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Spoofing issue in the Form Autofill component. This vulnerability was f= ixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 1= 40.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8961" target=3D"= _blank" rel=3D"noopener">CVE-2026-8961</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D1962625" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D1962625</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Mitigation bypass in the DOM: Security component. This vulnerability wa=
    s fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbir=
    d 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8962" target=3D"= _blank" rel=3D"noopener">CVE-2026-8962</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2004804" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2004804</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Spoofing issue in the Web Speech component. This vulnerability was fixe=
    d in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8963" target=3D"= _blank" rel=3D"noopener">CVE-2026-8963</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2021222" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2021222</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Spoofing issue in the Popup Blocker component. This vulnerability was f= ixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8964" target=3D"= _blank" rel=3D"noopener">CVE-2026-8964</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2025170" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2025170</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Information disclosure in the DOM: Security component. This vulnerabili=
    ty was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8965" target=3D"= _blank" rel=3D"noopener">CVE-2026-8965</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2025740" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2025740</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Information disclosure in the IP Protection component. This vulnerabili=
    ty was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8966" target=3D"= _blank" rel=3D"noopener">CVE-2026-8966</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2025849" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2025849</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Information disclosure in the Graphics: WebGPU component. This vulnerab= ility was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8967" target=3D"= _blank" rel=3D"noopener">CVE-2026-8967</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2027173" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2027173</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs=
    component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11=
    , Thunderbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8968" target=3D"= _blank" rel=3D"noopener">CVE-2026-8968</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2030467" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2030467</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Mitigation bypass in the DOM: Security component. This vulnerability wa=
    s fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8969" target=3D"= _blank" rel=3D"noopener">CVE-2026-8969</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2031123" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2031123</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Privilege escalation in the Security component. This vulnerability was = fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird = 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8970" target=3D"= _blank" rel=3D"noopener">CVE-2026-8970</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2032174" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2032174</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href=3D"https://ww= w.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"no= opener">https://www.mozilla.org/security/advisories/mfsa2026-50/</a><br><a = href=3D"https://www.mozilla.org/security/advisories/mfsa2026-51/" target=3D= "_blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2= 026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Same-origin policy bypass in the Networking: JAR component. This vulner= ability was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8971" target=3D"= _blank" rel=3D"noopener">CVE-2026-8971</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2032604" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2032604</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Privilege escalation in the WebRTC: Audio/Video component. This vulnera= bility was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8972" target=3D"= _blank" rel=3D"noopener">CVE-2026-8972</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2033275" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2033275</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/secu= rity/advisories/mfsa2026-50/" target=3D"_blank" rel=3D"noopener">https://ww= w.mozilla.org/security/advisories/mfsa2026-50/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Memory safety bugs present in Thunderbird 150. Some of these bugs showe=
    d evidence of memory corruption and we presume that with enough effort some=
    of these could have been exploited to run arbitrary code. This vulnerabili=
    ty was fixed in Firefox 151 and Thunderbird 151.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8973" target=3D"= _blank" rel=3D"noopener">CVE-2026-8973</a></td>

    <a href=3D"https://bugzilla.mozilla.org/buglist.cgi?bug_id=3D1362365%2C1860= 538%2C1929005%2C1983353%2C1998526%2C2023271%2C2023943%2C2024244%2C2024260%2= C2024443%2C2024665%2C2024774%2C2024916%2C2025346%2C2025357%2C2025406%2C2025= 434%2C2025488%2C2025496%2C2025942%2C2025947%2C2025968%2C2026279%2C2027159%2= C2027239%2C2027276%2C2027308%2C2027310%2C2027324%2C2027329%2C2027363%2C2027= 381%2C2027382%2C2027383%2C2028274%2C2028884%2C2029060%2C2029065%2C2029068%2= C2029281%2C2029293%2C2029297%2C2029303%2C2029439%2C2029448%2C2029703%2C2029= 720%2C2029721%2C2029723%2C2029770%2C2029771%2C2029782%2C2029818%2C2029885%2= C2030100%2C2030379%2C2030385%2C2030979%2C2031119%2C2031122%2C2034119%2C2034= 791%2C2035209%2C2036666%2C2037986" target=3D"_blank" rel=3D"noopener">Memor=
    y safety bugs fixed in Thunderbird 151</a><br><a href=3D"https://www.mozill= a.org/security/advisories/mfsa2026-46/" target=3D"_blank" rel=3D"noopener">= https://www.mozilla.org/security/advisories/mfsa2026-46/</a><br><a href=3D"= https://www.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_blank"=
    rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2026-50/<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. S= ome of these bugs showed evidence of memory corruption and we presume that = with enough effort some of these could have been exploited to run arbitrary=
    code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thu= nderbird 151, and Thunderbird 140.11.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8974" target=3D"= _blank" rel=3D"noopener">CVE-2026-8974</a></td>

    <a href=3D"https://bugzilla.mozilla.org/buglist.cgi?bug_id=3D1784128%2C1883= 230%2C1983677%2C2022390%2C2023116%2C2023657%2C2024255%2C2024418%2C2024441%2= C2024447%2C2024966%2C2025412%2C2025467%2C2025940%2C2025950%2C2025956%2C2026= 284%2C2027247%2C2027255%2C2027288%2C2027306%2C2027322%2C2027332%2C2027333%2= C2028266%2C2028292%2C2028319%2C2028526%2C2028870%2C2028876%2C2028882%2C2029= 062%2C2029309%2C2029414%2C2029422%2C2029428%2C2029447%2C2029732%2C2029785%2= C2029793%2C2029813%2C2029899%2C2031028%2C2031457%2C2032039%2C2033610%2C2033= 854%2C2034498%2C2034628%2C2034978%2C2035966%2C2036668%2C2036905%2C2036930" = target=3D"_blank" rel=3D"noopener">Memory safety bugs fixed in Thunderbird = 140.11 and Thunderbird 151</a><br><a href=3D"https://www.mozilla.org/securi= ty/advisories/mfsa2026-46/" target=3D"_blank" rel=3D"noopener">https://www.= mozilla.org/security/advisories/mfsa2026-46/</a><br><a href=3D"https://www.= mozilla.org/security/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noop= ener">https://www.mozilla.org/security/advisories/mfsa2026-48/</a><br><a hr= ef=3D"https://www.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_= blank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa202= 6-50/</a><br><a href=3D"https://www.mozilla.org/security/advisories/mfsa202= 6-51/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/security/= advisories/mfsa2026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox</td>
    <td>Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. S= ome of these bugs showed evidence of memory corruption and we presume that = with enough effort some of these could have been exploited to run arbitrary=
    code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Fir= efox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8975" target=3D"= _blank" rel=3D"noopener">CVE-2026-8975</a></td>

    <a href=3D"https://bugzilla.mozilla.org/buglist.cgi?bug_id=3D1860195%2C2029= 325%2C2029429%2C2029910%2C2035915%2C2038678%2C2038669" target=3D"_blank" re= l=3D"noopener">Memory safety bugs fixed in Thunderbird 140.11 and Thunderbi=
    rd 151</a><br><a href=3D"https://www.mozilla.org/security/advisories/mfsa20= 26-46/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/security= /advisories/mfsa2026-46/</a><br><a href=3D"https://www.mozilla.org/security= /advisories/mfsa2026-47/" target=3D"_blank" rel=3D"noopener">https://www.mo= zilla.org/security/advisories/mfsa2026-47/</a><br><a href=3D"https://www.mo= zilla.org/security/advisories/mfsa2026-48/" target=3D"_blank" rel=3D"noopen= er">https://www.mozilla.org/security/advisories/mfsa2026-48/</a><br><a href= =3D"https://www.mozilla.org/security/advisories/mfsa2026-50/" target=3D"_bl= ank" rel=3D"noopener">https://www.mozilla.org/security/advisories/mfsa2026-= 50/</a><br><a href=3D"https://www.mozilla.org/security/advisories/mfsa2026-= 51/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/security/ad= visories/mfsa2026-51/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Mozilla--Firefox for iOS</td>
    <td>Firefox for iOS hosted Reader mode on an unauthenticated local web serv= er, allowing another application on the same device to request arbitrary UR=
    Ls and receive the response rendered with the signed-in user's cookies. Thi=
    s vulnerability was fixed in Firefox for iOS 151.0.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8706" target=3D"= _blank" rel=3D"noopener">CVE-2026-8706</a></td>

    <a href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D2036618" target= =3D"_blank" rel=3D"noopener">https://bugzilla.mozilla.org/show_bug.cgi?id= =3D2036618</a><br><a href=3D"https://www.mozilla.org/security/advisories/mf= sa2026-49/" target=3D"_blank" rel=3D"noopener">https://www.mozilla.org/secu= rity/advisories/mfsa2026-49/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ngrok--ngrok v4.3.3 and 5.0.0-beta.2</td> <td>ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.</td> <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-57282" target=3D= "_blank" rel=3D"noopener">CVE-2025-57282</a></td>

    <a href=3D"https://www.npmjs.com" target=3D"_blank" rel=3D"noopener">https:= //www.npmjs.com</a><br><a href=3D"https://gist.github.com/Dremig/90c2a0a2f8= 5b0921f10e0bb3192a0c23" target=3D"_blank" rel=3D"noopener">https://gist.git= hub.com/Dremig/90c2a0a2f85b0921f10e0bb3192a0c23</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denia=
    l of service vulnerability when compiled with DNSCrypt support ('--enable-d= nscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet r= eading procedure that may lead to heap overflow. A malicious actor can expl= oit the vulnerability with a single bad DNSCrypt query that its decrypted p= laintext consists entirely of '0x00' bytes and does not contain the expecte=
    d '0x80' marker. Unbound would then start reading more bytes than necessary=
    until it finds a non-'0x00' byte. Based on the underlying memory allocator=
    and the memory layout, it could lead to heap overflow while reading follow=
    ed by a crash. Likelihood of a crash is low, since it relies heavily on the=
    underlying memory allocator and the memory layout. If the heap overflow do=
    es not happen, Unbound's later packet checks will deny the packet. Unbound = 1.25.1 contains a patch with a fix to bound reading in the given buffer spa= ce.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32792" target=3D= "_blank" rel=3D"noopener">CVE-2026-32792</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-32792.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-32792.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vuln= erability in the DNSSEC validator that enables denial of service and possib=
    le remote code execution as a result of deep copying a data structure and e= rroneously overwriting a destination pointer. An adversary can exploit the = vulnerability by controlling a malicious signed zone and querying a vulnera= ble Unbound. When DS sub-queries need to suspend validation due to NSEC3 co= mputational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-= copies response messages to preserve them across memory region teardown. A = struct-assignment bug overwrites the destination's pointer with the source'=
    s pointer. After the sub-query region is freed, the resumed validator deref= erences this dangling pointer, triggering a crash or potentially enabling a= rbitrary code execution. Unbound 1.25.1 contains a patch with a fix to pres= erve the correct pointer when deep copying the data structure.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33278" target=3D= "_blank" rel=3D"noopener">CVE-2026-33278</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-33278.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-33278.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vuln= erability of the 'ghost domain names' family of attacks that could extend t=
    he ghost domain window by up to one cached TTL configured value. Similar to=
    other 'ghost domain names' attacks, an adversary needs to control a (ghost=
    ) zone and be able to query a vulnerable Unbound. A single client NS query = can cause Unbound to overwrite the cached expired parent-side referral NS r= rset with the child-side apex NS rrset and essentially extend the ghost dom= ain window by up to one cached TTL configured value ('cache-max-ttl'). In c= onfigurations where 'harden-referral-path: yes' is used (non-default config= uration), no client NS query is required since Unbound implicitly performs = that query. Unbound 1.25.1 contains a patch with a fix that does not allow = extension of TTLs for (parent) NS records regardless of their trust.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-40622" target=3D= "_blank" rel=3D"noopener">CVE-2026-40622</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-40622.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-40622.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to =
    a degradation of service attack related to parsing long lists of incoming E= DNS options. An adversary sending queries with too many EDNS options can ho=
    ld Unbound threads hostage while they are parsing and creating internal dat=
    a structures for the options. Coordinated attacks can result in degradation=
    and/or denial of service. Unbound 1.25.1 contains a patch with a fix to li= mit acceptable incoming EDNS options (100).</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41292" target=3D= "_blank" rel=3D"noopener">CVE-2026-41292</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41292.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-41292.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabili=
    ty in the jostle logic that could defeat its purpose and degrade resolution=
    performance. Retransmits of the same query could renew the age of slow run= ning queries and not allow the jostle logic to see them as aged and potenti=
    al targets for replacement with new queries. An adversary who can query a v= ulnerable Unbound and who can control a domain name server that replies slo= wly and/or maliciously to Unbound's queries can exploit the vulnerability a=
    nd degrade the resolution performance of Unbound. When Unbound's 'num-queri= es-per-thread' reaches its limit, the jostle logic kicks in. When a new que=
    ry comes in, half of the available queries that are also slow to resolve ar=
    e candidates for replacement. The vulnerability then happens because duplic= ate queries that need resolution would skew the aging result by using the t= imestamp of the latest duplicate query instead of the original one that sta= rted the resolution effort. Cache and local data response performance remai=
    ns unaffected. Coordinated attacks could raise this to a denial of resoluti=
    on service. Unbound 1.25.1 contains a patch with a fix to attach an initial=
    , non-updatable start time for incoming queries that allow the jostle logic=
    to work as intended.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42534" target=3D= "_blank" rel=3D"noopener">CVE-2026-42534</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42534.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-42534.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabili=
    ty in the DNSSEC validator where the code path to consult the negative cach=
    e for DS records does not take into account the limit on NSEC3 hash calcula= tions introduced in 1.19.1. This leads to degradation of service during the=
    attack. An adversary that controls a DNSSEC signed zone can exploit this b=
    y signing NSEC3 records with acceptably high iterations for child delegatio=
    ns and querying a vulnerable Unbound. Unbound will keep performing the allo= wed hash calculations on the NSEC3 records and will not limit the work by t=
    he mitigation introduced in 1.19.1. As a side effect, a global lock for the=
    negative cache will be held for the duration of the hashing, blocking othe=
    r threads that need to consult the negative cache. Coordinated attacks coul=
    d raise the vulnerability to denial of service. Unbound 1.25.1 contains a p= atch with a fix to bound the vulnerable code path with the existing limit f=
    or NSEC3 hash calculations.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42923" target=3D= "_blank" rel=3D"noopener">CVE-2026-42923</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42923.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-42923.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vuln= erability that results in heap overflow when encoding multiple NSID and/or = DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The releva=
    nt options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be = enabled for the vulnerability to be exploited. An adversary who can query U= nbound can exploit the vulnerability by attaching multiple NSID and/or DNS = Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size ca= lculation of the EDNS field truncates the correct value which allows the en= coder to overflow the available space when writing. Those two combined lead=
    to a heap overflow write of Unbound controlled data and eventually a crash=
    . Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS optio=
    ns and a fix to prevent truncation of the EDNS field size calculation.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42944" target=3D= "_blank" rel=3D"noopener">CVE-2026-42944</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42944.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-42944.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound up to and including version 1.25.0 has a denial of s= ervice vulnerability in the DNSSEC validator that can lead to a crash given=
    malicious upstream replies. When Unbound constructs chase-reply messages f=
    or validation, the code uses the wrong counter to calculate write offsets f=
    or ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER s= ection count and authority filtering could decrease the AUTHORITY section c= ount and create an uninitialized array slot. Combining these two, the valid= ator later dereferences this uninitialized pointer, causing an immediate pr= ocess crash. An adversary controlling a DNSSEC-signed domain can trigger th=
    is bug with a single query by configuring a DNAME chain with unsigned CNAME=
    s and a response containing unsigned AUTHORITY records alongside signed ADD= ITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the=
    proper counters to calculate the write offsets.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42959" target=3D= "_blank" rel=3D"noopener">CVE-2026-42959</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42959.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-42959.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to = poisoning via promiscuous records for the authority section. Promiscuous RR= Sets that complement DNS replies in the authority section can be used to tr= ick Unbound to cache such records. If an adversary is able to attach such r= ecords in a reply (i.e., spoofed packet, fragmentation attack) he would be = able to poison Unbound's cache. A malicious actor can exploit the possible = poisonous effect by injecting RRSets other than NS that are also accompanie=
    d by address records in a reply, for example MX. This could be achieved by = trying to spoof a reply packet or fragmentation attacks. Unbound would then=
    accept the relative address records in the additional section and cache th=
    em if the authority RRSet has enough trust at this point, i.e., in-zone dat=
    a for the delegation point. Unbound 1.25.1 contains a patch with a fix that=
    disregards address records from the additional section if they are not exp= licitly relevant only to authority NS records, mitigating the possible pois=
    on effect. This is a complement fix to CVE-2025-11411.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42960" target=3D= "_blank" rel=3D"noopener">CVE-2026-42960</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-42960.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabili=
    ty when handling replies with very large RRsets that Unbound needs to perfo=
    rm name compression for. Malicious upstream responses with very large RRset=
    s with records that don't share a suffix above the root can cause Unbound t=
    o spend a considerable time applying name compression to downstream replies=
    . This can lead to degraded performance and eventually denial of service in=
    well orchestrated attacks. An adversary can exploit the vulnerability by q= uerying Unbound for the specially crafted contents of a malicious zone with=
    very large RRsets. Before Unbound replies to the query it will try to appl=
    y name compression which was an unbounded operation that could lock the CPU=
    until the whole packet was complete. A compression limit was introduced in=
    1.21.1 for this but it didn't account for the case where records would not=
    share any suffix above the root. That causes Unbound to go in a different = code path because of the compression tree lookup failure and eventually not=
    increment the compression counter for those operations. Unbound 1.25.1 con= tains a patch with a fix that increments the compression counter regardless=
    of the compression tree lookup. This is a complement fix to CVE-2024-8508.= </td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44390" target=3D= "_blank" rel=3D"noopener">CVE-2026-44390</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44390.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-44390.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NLnet Labs--Unbound</td>
    <td>NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a lock= ing inconsistency vulnerability that when certain conditions are met (multi= -threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers)=
    it could result in heap use-after-free and eventual crash. An adversary ca=
    n exploit the vulnerability if conditions are first met on a vulnerable Unb= ound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' trigg= ers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger th=
    e vulnerability. If the timing is right and an XFR happens at the same time=
    another thread needs to read that RPZ zone, the reader may not hold the lo=
    ck long enough and the thread applying the XFR may free objects that the re= ader is about to walk causing the use-after-free. Unbound 1.25.1 contains a=
    patch with a fix to the locking code.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44608" target=3D= "_blank" rel=3D"noopener">CVE-2026-44608</a></td>

    <a href=3D"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44608.txt" t= arget=3D"_blank" rel=3D"noopener">https://www.nlnetlabs.nl/downloads/unboun= d/CVE-2026-44608.txt</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NOVUS -- AirGate 4G</td>
    <td>Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G = firmware v1.1.16 allows unauthenticated attackers to obtain administrator c= redentials via a crafted POST request.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-24215" target=3D= "_blank" rel=3D"noopener">CVE-2023-24215</a></td>

    <a href=3D"http://airgate.com" target=3D"_blank" rel=3D"noopener">http://ai= rgate.com</a><br><a href=3D"http://novus.com" target=3D"_blank" rel=3D"noop= ener">http://novus.com</a><br><a href=3D"https://github.com/sql3t0/cve-disc= losures/blob/main/00_-_CVE-2023-24215.md" target=3D"_blank" rel=3D"noopener= ">https://github.com/sql3t0/cve-disclosures/blob/main/00_-_CVE-2023-24215.m= d</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Offline Hospital Management System--Offline Ho= spital Management System 5.3.0</td>
    <td>Offline Hospital Management System 5.3.0 allows remote code execution d=
    ue to an improper Electron renderer configuration. The application enables = Node.js integration while disabling context isolation, allowing JavaScript = executed in the renderer process to access Node.js APIs and execute arbitra=
    ry operating system commands.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-26462" target=3D= "_blank" rel=3D"noopener">CVE-2026-26462</a></td>

    <a href=3D"https://sourceforge.net/projects/hospital-management-system/file= s/" target=3D"_blank" rel=3D"noopener">https://sourceforge.net/projects/hos= pital-management-system/files/</a><br><a href=3D"https://medium.com/@husaai= npalh/remote-code-execution-in-offline-hospital-management-system-cve-2026-= 26462-bc7ac54314c4" target=3D"_blank" rel=3D"noopener">https://medium.com/@= husaainpalh/remote-code-execution-in-offline-hospital-management-system-cve= -2026-26462-bc7ac54314c4</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">OpENer--OpENer v2.3-558-g1e99582</td>
    <td>OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability i=
    n the Common Packet Format (CPF) parser, specifically in CreateCommonPacket= FormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF messag=
    e can supply an attacker-controlled item_count value that is not consistent=
    ly validated against the remaining data_length of the CPF slice</td> <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-38719" target=3D= "_blank" rel=3D"noopener">CVE-2026-38719</a></td>

    <a href=3D"https://github.com/EIPStackGroup/OpENer" target=3D"_blank" rel= =3D"noopener">https://github.com/EIPStackGroup/OpENer</a><br><a href=3D"htt= ps://github.com/EIPStackGroup/OpENer/issues/558" target=3D"_blank" rel=3D"n= oopener">https://github.com/EIPStackGroup/OpENer/issues/558</a><br>=C2=A0</=

    </tr>

    <td class=3D"vendor-product">Perforce--P4 (Helix Core)</td>
    <td>A Remote Code Execution vulnerability in P4 (Helix Core) Server's Comma= nd-Line Client, prior to the 2025.2 Patch 2, has been fixed to address pote= ntial security risks.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6902" target=3D"= _blank" rel=3D"noopener">CVE-2026-6902</a></td>

    <a href=3D"https://portal.perforce.com/s/cve/a91Qi000002zJB3IAM/code-inject= ion-in-perforce-helix-core" target=3D"_blank" rel=3D"noopener">https://port= al.perforce.com/s/cve/a91Qi000002zJB3IAM/code-injection-in-perforce-helix-c= ore</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">phenixdigital--phoenix_storybook</td> <td>Authorization Bypass Through User-Controlled Key vulnerability in pheni= xdigital phoenix_storybook allows cross-session PubSub topic injection via =
    a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':= handle_params/3 in lib/phoenix_storybook/live/story/component_iframe_live.e=
    x reads a PubSub topic directly from params["topic"] and broadcasts {:compo= nent_iframe_pid, self()} on it with no check that the topic belongs to the = requesting session. The shared PhoenixStorybook.PubSub is used to coordinat=
    e playground LiveViews with their iframes: a playground subscribes to a ses= sion-specific topic and uses the received iframe pid to direct subsequent c= ontrol messages (variation state, theme switches, extra-assign payloads) vi=
    a send/2. Because the iframe trusts the query parameter, an attacker who lo= ads /storybook/iframe/&lt;story&gt;?topic=3D&lt;victim_topic&gt; causes the=
    ir iframe process pid to be announced on the victim's topic. The victim's p= layground then addresses its private messages to the attacker's iframe proc= ess. This issue affects phoenix_storybook from 0.4.0 before 1.1.0.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47068" target=3D= "_blank" rel=3D"noopener">CVE-2026-47068</a></td>

    <a href=3D"https://github.com/phenixdigital/phoenix_storybook/security/advi= sories/GHSA-mrhx-6pw9-q5fh" target=3D"_blank" rel=3D"noopener">https://gith= ub.com/phenixdigital/phoenix_storybook/security/advisories/GHSA-mrhx-6pw9-q= 5fh</a><br><a href=3D"https://cna.erlef.org/cves/CVE-2026-47068.html" targe= t=3D"_blank" rel=3D"noopener">https://cna.erlef.org/cves/CVE-2026-47068.htm= l</a><br><a href=3D"https://osv.dev/vulnerability/EEF-CVE-2026-47068" targe= t=3D"_blank" rel=3D"noopener">https://osv.dev/vulnerability/EEF-CVE-2026-47= 068</a><br><a href=3D"https://github.com/phenixdigital/phoenix_storybook/co= mmit/6ee03f1c738d4436dde1b066cf65c80663d489f5" target=3D"_blank" rel=3D"noo= pener">https://github.com/phenixdigital/phoenix_storybook/commit/6ee03f1c73= 8d4436dde1b066cf65c80663d489f5</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">phenixdigital--phoenix_storybook</td>
    <td>Code Injection vulnerability in phenixdigital phoenix_storybook allows = unauthenticated remote code execution via unsanitized attribute value inter= polation in HEEx template generation. The psb-assign WebSocket event handle=
    r in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_event/3 a= ccepts arbitrary attribute names and values from unauthenticated clients. T= hese values are passed to 'Elixir.PhoenixStorybook.Helpers.ExtraAssignsHelp= ers':handle_set_variation_assign/3, which stores them verbatim. When render= ing, 'Elixir.PhoenixStorybook.Rendering.ComponentRenderer':attributes_marku= p/1 interpolates binary attribute values directly into a HEEx template stri=
    ng as name=3D"&lt;val&gt;" without escaping double quotes or HEEx expressio=
    n delimiters. An attacker can supply a value containing a closing quote fol= lowed by a HEEx expression block (e.g. foo" injected=3D{EXPR} bar=3D"), whi=
    ch causes EXPR to be treated as an inline Elixir expression. The resulting = template is compiled via EEx.compile_string/2 and executed via Code.eval_qu= oted_with_env/3 with full Kernel imports and no sandbox, giving the attacke=
    r arbitrary code execution on the server. This issue affects phoenix_storyb= ook from 0.5.0 before 1.1.0.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8467" target=3D"= _blank" rel=3D"noopener">CVE-2026-8467</a></td>

    <a href=3D"https://github.com/phenixdigital/phoenix_storybook/security/advi= sories/GHSA-55hg-8qxv-qj4p" target=3D"_blank" rel=3D"noopener">https://gith= ub.com/phenixdigital/phoenix_storybook/security/advisories/GHSA-55hg-8qxv-q= j4p</a><br><a href=3D"https://cna.erlef.org/cves/CVE-2026-8467.html" target= =3D"_blank" rel=3D"noopener">https://cna.erlef.org/cves/CVE-2026-8467.html<= /a><br><a href=3D"https://osv.dev/vulnerability/EEF-CVE-2026-8467" target= =3D"_blank" rel=3D"noopener">https://osv.dev/vulnerability/EEF-CVE-2026-846= 7</a><br><a href=3D"https://github.com/phenixdigital/phoenix_storybook/comm= it/56ab8464d4375fa52db806148a06cce126ad481d" target=3D"_blank" rel=3D"noope= ner">https://github.com/phenixdigital/phoenix_storybook/commit/56ab8464d437= 5fa52db806148a06cce126ad481d</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">phenixdigital--phoenix_storybook</td> <td>Allocation of Resources Without Limits or Throttling vulnerability in p= henixdigital phoenix_storybook allows unauthenticated denial-of-service via=
    BEAM atom table exhaustion. Multiple LiveView event handlers convert user-= supplied event parameter strings to atoms using String.to_atom/1 without va= lidation: 'Elixir.PhoenixStorybook.ExtraAssignsHelpers':handle_set_variatio= n_assign/3 interns every key of the psb-assign params map; 'Elixir.PhoenixS= torybook.ExtraAssignsHelpers':handle_toggle_variation_assign/3 interns the = "attr" value from psb-toggle events; 'Elixir.PhoenixStorybook.ExtraAssignsH= elpers':to_variation_id/2 interns elements of "variation_id"; and 'Elixir.P= hoenixStorybook.ExtraAssignsHelpers':to_value/4 interns raw string values f=
    or attributes declared as :atom or :boolean. BEAM atoms are never garbage-c= ollected, so each unique attacker-controlled string is a permanent allocati= on. Once the atom table ceiling (~1,048,576 atoms) is reached, the entire B= EAM node aborts, taking down all applications running on it. This issue aff= ects phoenix_storybook from 0.2.0 before 1.1.0.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8469" target=3D"= _blank" rel=3D"noopener">CVE-2026-8469</a></td>

    <a href=3D"https://github.com/phenixdigital/phoenix_storybook/security/advi= sories/GHSA-833p-95jq-929q" target=3D"_blank" rel=3D"noopener">https://gith= ub.com/phenixdigital/phoenix_storybook/security/advisories/GHSA-833p-95jq-9= 29q</a><br><a href=3D"https://cna.erlef.org/cves/CVE-2026-8469.html" target= =3D"_blank" rel=3D"noopener">https://cna.erlef.org/cves/CVE-2026-8469.html<= /a><br><a href=3D"https://osv.dev/vulnerability/EEF-CVE-2026-8469" target= =3D"_blank" rel=3D"noopener">https://osv.dev/vulnerability/EEF-CVE-2026-846= 9</a><br><a href=3D"https://github.com/phenixdigital/phoenix_storybook/comm= it/96d524690af0fe197a49f60d18e564a620b9ef81" target=3D"_blank" rel=3D"noope= ner">https://github.com/phenixdigital/phoenix_storybook/commit/96d524690af0= fe197a49f60d18e564a620b9ef81</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">prefecthq--prefecthq/prefect</td>
    <td>A vulnerability in the `GitHubRepository` block of the `prefect-github`=
    integration in Prefect version 3.6.18 allows an attacker to inject arbitra=
    ry git command-line options via the `reference` field. The `reference` fiel=
    d is concatenated directly into a `git clone` command string without proper=
    sanitization, and then parsed by `shlex.split()`. This enables injection o=
    f options such as `-c`, leading to potential Server-Side Request Forgery (S= SRF), credential theft, or remote code execution (RCE). The vulnerability a= ffects both the `aget_directory()` and `get_directory()` methods in `src/in= tegrations/prefect-github/prefect_github/repository.py`. This issue does no=
    t affect the GitLab and BitBucket integrations, which use a safer list-base=
    d command construction approach.</td>
    <td>2026-05-24</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3515" target=3D"= _blank" rel=3D"noopener">CVE-2026-3515</a></td>

    <a href=3D"https://huntr.com/bounties/f3b048b8-7f4e-45ef-a5a7-cb841c39acde"=
    target=3D"_blank" rel=3D"noopener">https://huntr.com/bounties/f3b048b8-7f4= e-45ef-a5a7-cb841c39acde</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">PrestaShop--upsshipping module</td>
    <td>An issue in prestashop upsshipping all versions through at least 2.4.0 = allows a remote attacker to obtain sensitive information via the /modules/u= psshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components</t=

    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-39079" target=3D= "_blank" rel=3D"noopener">CVE-2026-39079</a></td>

    <a href=3D"https://labs.esokia.com/cve/cve-2026-39079/" target=3D"_blank" r= el=3D"noopener">https://labs.esokia.com/cve/cve-2026-39079/</a><br>=C2=A0</=

    </tr>

    <td class=3D"vendor-product">Rocket.Chat--Rocket.Chat</td>
    <td>The /api/v1/autotranslate.translateMessage endpoint in versions &lt;8.5= .0, &lt;8.4.2, &lt;8.3.4, &lt;8.2.4, &lt;8.1.5, &lt;8.0.6, &lt;7.13.8, and = &lt;7.10.12 allows any authenticated user to retrieve the full content of a=
    ny message from any room (private groups, direct messages, channels) by sim= ply providing the target message ID. The endpoint fetches the message via M= essages.findOneById(messageId) with no room access check (canAccessRoomIdAs= ync is never called), returning the complete IMessage object including mess= age text, sender info, room ID, timestamps, and markdown content.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-32994" target=3D= "_blank" rel=3D"noopener">CVE-2026-32994</a></td>

    <a href=3D"https://hackerone.com/reports/3713682" target=3D"_blank" rel=3D"= noopener">https://hackerone.com/reports/3713682</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">RRWO--Crypt::SaltedHash</td>
    <td>Crypt::SaltedHash versions through 0.09 for Perl generate insecure rand=
    om values for salts. These versions use the built-in rand function, which i=
    s predictable and unsuitable for cryptography.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47372" target=3D= "_blank" rel=3D"noopener">CVE-2026-47372</a></td>

    <a href=3D"https://metacpan.org/release/RRWO/Crypt-SaltedHash-0.10/changes"=
    target=3D"_blank" rel=3D"noopener">https://metacpan.org/release/RRWO/Crypt= -SaltedHash-0.10/changes</a><br><a href=3D"https://github.com/robrwo/perl-C= rypt-SaltedHash/commit/9b68437d2cd420b819b3a795474c3870338d38d5.patch" targ= et=3D"_blank" rel=3D"noopener">https://github.com/robrwo/perl-Crypt-SaltedH= ash/commit/9b68437d2cd420b819b3a795474c3870338d38d5.patch</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">RRWO--Crypt::SaltedHash</td>
    <td>Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timi=
    ng attacks. These versions use Perl's built-in eq comparison. Discrepencies=
    in timing could be used to guess the underlying hash.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47373" target=3D= "_blank" rel=3D"noopener">CVE-2026-47373</a></td>

    <a href=3D"https://metacpan.org/release/RRWO/Crypt-SaltedHash-0.10/changes"=
    target=3D"_blank" rel=3D"noopener">https://metacpan.org/release/RRWO/Crypt= -SaltedHash-0.10/changes</a><br><a href=3D"https://github.com/robrwo/perl-C= rypt-SaltedHash/commit/c07bfc5c23185b0667233d0f2e1252d81f1f027a.patch" targ= et=3D"_blank" rel=3D"noopener">https://github.com/robrwo/perl-Crypt-SaltedH= ash/commit/c07bfc5c23185b0667233d0f2e1252d81f1f027a.patch</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">RRWO--Net::Statsd::Lite</td>
    <td>Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injec= tions. The values from the set_add method were not checked for newlines, co= lons or pipes. Metrics generated from untrusted sources could inject additi= onal statsd metrics. Note that version 0.9.0 fixed a similar issue CVE-2026= -46719 for metric names.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8788" target=3D"= _blank" rel=3D"noopener">CVE-2026-8788</a></td>

    <a href=3D"https://metacpan.org/release/RRWO/Net-Statsd-Lite-v0.10.1/change=
    s" target=3D"_blank" rel=3D"noopener">https://metacpan.org/release/RRWO/Net= -Statsd-Lite-v0.10.1/changes</a><br><a href=3D"https://www.cve.org/CVERecor= d?id=3DCVE-2026-46719" target=3D"_blank" rel=3D"noopener">https://www.cve.o= rg/CVERecord?id=3DCVE-2026-46719</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ScadaBR--ScadaBR</td>
    <td>In ScadaBR version 1.2.0, a Missing Authentication for Critical Functio=
    n vulnerability could allow an unauthenticated attacker to send a HTTP GET = requests to the SCADA system and inject arbitrary sensor readings.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8602" target=3D"= _blank" rel=3D"noopener">CVE-2026-8602</a></td>

    <a href=3D"https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03" = target=3D"_blank" rel=3D"noopener">https://www.cisa.gov/news-events/ics-adv= isories/icsa-26-139-03</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ScadaBR--ScadaBR</td>
    <td>In ScadaBR version 1.2.0, an OS Command Injection vulnerability could a= llow an attacker to execute commands as root on the SCADA system.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8603" target=3D"= _blank" rel=3D"noopener">CVE-2026-8603</a></td>

    <a href=3D"https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03" = target=3D"_blank" rel=3D"noopener">https://www.cisa.gov/news-events/ics-adv= isories/icsa-26-139-03</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ScadaBR--ScadaBR</td>
    <td>In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker =
    to trigger any authenticated action through a victim's session by luring an=
    y logged-in user to a malicious webpage.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8604" target=3D"= _blank" rel=3D"noopener">CVE-2026-8604</a></td>

    <a href=3D"https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03" = target=3D"_blank" rel=3D"noopener">https://www.cisa.gov/news-events/ics-adv= isories/icsa-26-139-03</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ScadaBR--ScadaBR</td>
    <td>In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability=
    could allow an attacker to access the SCADA system as admin.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8605" target=3D"= _blank" rel=3D"noopener">CVE-2026-8605</a></td>

    <a href=3D"https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03" = target=3D"_blank" rel=3D"noopener">https://www.cisa.gov/news-events/ics-adv= isories/icsa-26-139-03</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">scalar--astro v0.1.13</td>
    <td>scalar/astro v0.1.13 was discovered to contain an arbitrary file upload=
    vulnerability in the the scalar_url query parameter of the Scalar Proxy en= dpoint. This vulnerability allows attackers to execute arbitrary code via u= ploading a crafted SVG file.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-30117" target=3D= "_blank" rel=3D"noopener">CVE-2026-30117</a></td>

    <a href=3D"https://github.com/prassan10/XSS-Open-Redirect-via-scalar_url" t= arget=3D"_blank" rel=3D"noopener">https://github.com/prassan10/XSS-Open-Red= irect-via-scalar_url</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">scalar--astro v0.1.13</td>
    <td>scalar/astro v0.1.13 was discovered to contain a Server-Side Request Fo= rgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint=
    . This vulnerability allows unauthenticated attackers to force the backend = server to send HTTP requests to attacker-controlled URLs, leading to authen= tication cookies and headers exposure and possible privilege escalation.</t=

    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-30118" target=3D= "_blank" rel=3D"noopener">CVE-2026-30118</a></td>

    <a href=3D"https://github.com/prassan10/ssrf-zero-click-ato-scalar" target= =3D"_blank" rel=3D"noopener">https://github.com/prassan10/ssrf-zero-click-a= to-scalar</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">SGLang--SGLang</td>
    <td>SGLangs multimodal generation runtime scheduler's ROUTER socket binds t=
    o 0.0.0.0 by default and contains a sink that calls pickle.loads() on incom= ing messages, enabling RCE when exposed to the internet.</td> <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7301" target=3D"= _blank" rel=3D"noopener">CVE-2026-7301</a></td>

    <a href=3D"https://github.com/sgl-project/sglang/tree/main/python/sglang" t= arget=3D"_blank" rel=3D"noopener">https://github.com/sgl-project/sglang/tre= e/main/python/sglang</a><br><a href=3D"https://antiproof.ai/blog/three-rces= -in-sglang/" target=3D"_blank" rel=3D"noopener">https://antiproof.ai/blog/t= hree-rces-in-sglang/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">SGLang--SGLang</td>
    <td>SGLangs multimodal generation runtime is vulnerable to an unauthenticat=
    ed path traversal vulnerability, allowing an attacker to write arbitrary fi= les anywhere the server process has write access, by including ../ sequence=
    s in the upload filename when sent to specific endpoints.</td> <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7302" target=3D"= _blank" rel=3D"noopener">CVE-2026-7302</a></td>

    <a href=3D"https://github.com/sgl-project/sglang/tree/main/python/sglang" t= arget=3D"_blank" rel=3D"noopener">https://github.com/sgl-project/sglang/tre= e/main/python/sglang</a><br><a href=3D"https://antiproof.ai/blog/three-rces= -in-sglang/" target=3D"_blank" rel=3D"noopener">https://antiproof.ai/blog/t= hree-rces-in-sglang/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">SGLang--SGLang</td>
    <td>SGLangs multimodal generation runtime is vulnerable to unauthenticated = remote code execution when the --enable-custom-logit-processor option is en= abled, as Python objects loaded via dill.loads() will be deserialized witho=
    ut validation.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7304" target=3D"= _blank" rel=3D"noopener">CVE-2026-7304</a></td>

    <a href=3D"https://github.com/sgl-project/sglang/tree/main/python/sglang" t= arget=3D"_blank" rel=3D"noopener">https://github.com/sgl-project/sglang/tre= e/main/python/sglang</a><br><a href=3D"https://antiproof.ai/blog/three-rces= -in-sglang/" target=3D"_blank" rel=3D"noopener">https://antiproof.ai/blog/t= hree-rces-in-sglang/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Siber Systems, Inc.--Android App "RoboForm Pas= sword Manager"</td>
    <td>Android App "RoboForm Password Manager" provided by Siber Systems, Inc.=
    handles Android intents without sufficient URL validation, user confirmati=
    on nor notification. If a URL to some malicious web page is given through a=
    n intent, RoboForm may silently download files without user confirmation no=
    r notification.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-47782" target=3D= "_blank" rel=3D"noopener">CVE-2026-47782</a></td>

    <a href=3D"https://play.google.com/store/apps/details?id=3Dcom.siber.robofo= rm" target=3D"_blank" rel=3D"noopener">https://play.google.com/store/apps/d= etails?id=3Dcom.siber.roboform</a><br><a href=3D"https://www.roboform.com/n= ews-android" target=3D"_blank" rel=3D"noopener">https://www.roboform.com/ne= ws-android</a><br><a href=3D"https://jvn.jp/en/vu/JVNVU93461473/" target=3D= "_blank" rel=3D"noopener">https://jvn.jp/en/vu/JVNVU93461473/</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">simplesamlphp--simplesamlphp-module-casserver<=

    <td>SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in th=
    e form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the lo= gout endpoint accepts a url query parameter to redirect to. casserver treat=
    s that url as trusted, and either (depending on configuration) redirects th=
    e browser there, or shows a "you've been logged out" page with a link to co= ntinue to that url. Impacted configs include 'enable_logout' =3D&gt; true, = and 'skip_logout_page' -&gt; true. This issue has been resolved in versions=
    6.3.1 and 7.0.0.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-65954" target=3D= "_blank" rel=3D"noopener">CVE-2025-65954</a></td>

    <a href=3D"https://github.com/simplesamlphp/simplesamlphp-module-casserver/= security/advisories/GHSA-cvrm-5hp6-h523" target=3D"_blank" rel=3D"noopener"= >https://github.com/simplesamlphp/simplesamlphp-module-casserver/security/a= dvisories/GHSA-cvrm-5hp6-h523</a><br><a href=3D"https://github.com/simplesa= mlphp/simplesamlphp-module-casserver/commit/0462f50f00b3bb300d83067d11b7414= 6a57bb8e0" target=3D"_blank" rel=3D"noopener">https://github.com/simplesaml= php/simplesamlphp-module-casserver/commit/0462f50f00b3bb300d83067d11b74146a= 57bb8e0</a><br><a href=3D"https://github.com/simplesamlphp/simplesamlphp-mo= dule-casserver/commit/fb6c6f1c7b9e757c93c5c306e1d36405e64f6dc5" target=3D"_= blank" rel=3D"noopener">https://github.com/simplesamlphp/simplesamlphp-modu= le-casserver/commit/fb6c6f1c7b9e757c93c5c306e1d36405e64f6dc5</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">Six Apart Ltd.--Movable Type</td>
    <td>Missing authorization vulnerability exists in Movable Type. Under certa=
    in conditions, when a user without administrator privileges signs in to the=
    product, unintended update processing may be executed.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-44392" target=3D= "_blank" rel=3D"noopener">CVE-2026-44392</a></td>

    <a href=3D"https://movabletype.org/news/2026/05/mt-908-released.html" targe= t=3D"_blank" rel=3D"noopener">https://movabletype.org/news/2026/05/mt-908-r= eleased.html</a><br><a href=3D"https://www.sixapart.jp/movabletype/news/202= 6/05/20-1100.html" target=3D"_blank" rel=3D"noopener">https://www.sixapart.= jp/movabletype/news/2026/05/20-1100.html</a><br><a href=3D"https://jvn.jp/e= n/jp/JVN66473735/" target=3D"_blank" rel=3D"noopener">https://jvn.jp/en/jp/= JVN66473735/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Sparx Systems--Enterprise Architect</td>
    <td>Sparx Enterprise Architect software has a security feature that limits = user's actions to those specified in the role. An authenticated attacker ca=
    n modify the Enterprise Architect client behavior (e.g. using a debugger) a=
    nd log in as any other user or administrator - then it is possible to do ev= ery possible change to the repository. The vendor was notified early about = this vulnerability, but didn't respond with the details of vulnerability or=
    vulnerable version range. Only version 17.1 and below were tested and conf= irmed as vulnerable, other versions were not tested and might also be vulne= rable.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42098" target=3D= "_blank" rel=3D"noopener">CVE-2026-42098</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-42096" target=3D"_blan=
    k" rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-42096</a><br>=
    <a href=3D"https://sparxsystems.com/products/ea/" target=3D"_blank" rel=3D"= noopener">https://sparxsystems.com/products/ea/</a><br><a href=3D"https://s= ploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html" target=3D"_blank=
    " rel=3D"noopener">https://sploit.tech/2026/05/19/Sparx-Enterprise-Architec= t-PCS.html</a><br><a href=3D"https://efigo.pl/blog/CVE-2026-42096/" target= =3D"_blank" rel=3D"noopener">https://efigo.pl/blog/CVE-2026-42096/</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Sparx Systems--Pro Cloud Server</td>
    <td>Sparx Pro Cloud Server is vulnerable to Broken Access Control within co= mmunication with the database. Due to lack of permission checks, any low pr= ivileged user can run arbitrary SQL queries within database user context. T=
    he vendor was notified early about this vulnerability, but didn't respond w= ith the details of vulnerability or vulnerable version range. Only version = 6.1 (build 167) and below were tested and confirmed as vulnerable, other ve= rsions were not tested and might also be vulnerable.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42096" target=3D= "_blank" rel=3D"noopener">CVE-2026-42096</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-42096" target=3D"_blan=
    k" rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-42096</a><br>=
    <a href=3D"https://sparxsystems.com/products/procloudserver/" target=3D"_bl= ank" rel=3D"noopener">https://sparxsystems.com/products/procloudserver/</a>= <br><a href=3D"https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PC= S.html" target=3D"_blank" rel=3D"noopener">https://sploit.tech/2026/05/19/S= parx-Enterprise-Architect-PCS.html</a><br><a href=3D"https://efigo.pl/blog/= CVE-2026-42096/" target=3D"_blank" rel=3D"noopener">https://efigo.pl/blog/C= VE-2026-42096/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Sparx Systems--Pro Cloud Server</td>
    <td>Sparx Pro Cloud Server=C2=A0requires authentication based on requested = URL. An=C2=A0attacker can omit the "model" query parameter and send the mod=
    el name only in the binary blob in POST request=C2=A0allowing SQL query exe= cution without authentication. The vendor was notified early about this vul= nerability, but didn't respond with the details of vulnerability or vulnera= ble version range. Only version 6.1 (build 167) and below were tested and c= onfirmed as vulnerable, other versions were not tested and might also be vu= lnerable.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42097" target=3D= "_blank" rel=3D"noopener">CVE-2026-42097</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-42096" target=3D"_blan=
    k" rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-42096</a><br>=
    <a href=3D"https://sparxsystems.com/products/procloudserver/" target=3D"_bl= ank" rel=3D"noopener">https://sparxsystems.com/products/procloudserver/</a>= <br><a href=3D"https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PC= S.html" target=3D"_blank" rel=3D"noopener">https://sploit.tech/2026/05/19/S= parx-Enterprise-Architect-PCS.html</a><br><a href=3D"https://efigo.pl/blog/= CVE-2026-42096/" target=3D"_blank" rel=3D"noopener">https://efigo.pl/blog/C= VE-2026-42096/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Sparx Systems--Pro Cloud Server</td>
    <td>Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_a= pi/dl_internal_artifact.php endpoint. The application downloads the propert= ies of the object pointed by guid parameter and saves loaded content in cur= rent location=C2=A0(__DIR__)=C2=A0under the specified name. An attacker wit=
    h repository access can control both the filename and file contents, allowi=
    ng the creation of a malicious PHP file in a current directory. Although th=
    e file is deleted after processing, a race condition exists: if the respons=
    e transmission is delayed (e.g., via a large file or slow client connection=
    ), the file remains accessible. During this window, the attacker can issue =
    a second request to execute the malicious PHP file, resulting in remote cod=
    e execution. The vendor was notified early about this vulnerability, but di= dn't respond with the details of vulnerability or vulnerable version range.=
    Only version 6.1 (build 167) and below were tested and confirmed as vulner= able, other versions were not tested and might also be vulnerable.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42099" target=3D= "_blank" rel=3D"noopener">CVE-2026-42099</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-42096" target=3D"_blan=
    k" rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-42096</a><br>=
    <a href=3D"https://sparxsystems.com/products/procloudserver/" target=3D"_bl= ank" rel=3D"noopener">https://sparxsystems.com/products/procloudserver/</a>= <br><a href=3D"https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PC= S.html" target=3D"_blank" rel=3D"noopener">https://sploit.tech/2026/05/19/S= parx-Enterprise-Architect-PCS.html</a><br><a href=3D"https://efigo.pl/blog/= CVE-2026-42096/" target=3D"_blank" rel=3D"noopener">https://efigo.pl/blog/C= VE-2026-42096/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Sparx Systems--Pro Cloud Server</td>
    <td>Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud=
    Server allows Denial of Service (DoS) attack to be executed by=C2=A0sendin=
    g an specially crafted SQL query. This causes the Pro Cloud Server service =
    to terminate unexpectedly.=C2=A0 The vendor was notified early about this v= ulnerability, but didn't respond with the details of vulnerability or vulne= rable version range. Only version 6.1 (build 167) and below were tested and=
    confirmed as vulnerable, other versions were not tested and might also be = vulnerable.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-42100" target=3D= "_blank" rel=3D"noopener">CVE-2026-42100</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-42096" target=3D"_blan=
    k" rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-42096</a><br>=
    <a href=3D"https://sparxsystems.com/products/procloudserver/" target=3D"_bl= ank" rel=3D"noopener">https://sparxsystems.com/products/procloudserver/</a>= <br><a href=3D"https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PC= S.html" target=3D"_blank" rel=3D"noopener">https://sploit.tech/2026/05/19/S= parx-Enterprise-Architect-PCS.html</a><br><a href=3D"https://efigo.pl/blog/= CVE-2026-42096/" target=3D"_blank" rel=3D"noopener">https://efigo.pl/blog/C= VE-2026-42096/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">strukturag--libheif</td>
    <td>libheif is a HEIF and AVIF file format decoder and encoder. In versions=
    1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares=
    more samples than actually exist in the track's chunk table causes a heap-= buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor=
    . The SampleAuxInfoReader constructor iterates over saiz-&gt;get_num_sample= s() samples but doesn't validate that this count is consistent with the num= ber of chunks in the chunks vector. When saiz declares more samples than th=
    e chunks cover, the loop increments current_chunk past chunks.size(), causi=
    ng an out-of-bounds read on the chunks vector. The vulnerability is trigger=
    ed during file parsing (heif_context_read_from_file) without any additional=
    user interaction. Any application using libheif to open untrusted HEIF fil=
    es is affected. This issue has been fixed in version 1.22.0.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41071" target=3D= "_blank" rel=3D"noopener">CVE-2026-41071</a></td>

    <a href=3D"https://github.com/strukturag/libheif/security/advisories/GHSA-x= j92-xjff-h8w3" target=3D"_blank" rel=3D"noopener">https://github.com/strukt= urag/libheif/security/advisories/GHSA-xj92-xjff-h8w3</a><br><a href=3D"http= s://github.com/strukturag/libheif/releases/tag/v1.22.0" target=3D"_blank" r= el=3D"noopener">https://github.com/strukturag/libheif/releases/tag/v1.22.0<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TCHATZI--Authen::TOTP</td>
    <td>Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand=
    . Secrets were generated using Perl's built-in rand function, which is pred= ictable and unsuitable for security usage.</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46473" target=3D= "_blank" rel=3D"noopener">CVE-2026-46473</a></td>

    <a href=3D"https://metacpan.org/release/TCHATZI/Authen-TOTP-0.1.1/changes" = target=3D"_blank" rel=3D"noopener">https://metacpan.org/release/TCHATZI/Aut= hen-TOTP-0.1.1/changes</a><br><a href=3D"https://github.com/tchatzi/Authen-= TOTP/commit/d04f30cc6538d77fc6b6d550da450cf3017b8561.patch" target=3D"_blan=
    k" rel=3D"noopener">https://github.com/tchatzi/Authen-TOTP/commit/d04f30cc6= 538d77fc6b6d550da450cf3017b8561.patch</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">The Qt Company--Qt</td>
    <td>An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS ba= ckend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attac= ker to load a rogue CA certificate as a trusted system authority via a craf= ted certificate file placed in the application's working directory.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14575" target=3D= "_blank" rel=3D"noopener">CVE-2025-14575</a></td>

    <a href=3D"https://codereview.qt-project.org/c/qt/qtbase/+/642967" target= =3D"_blank" rel=3D"noopener">Gerrit: QSslCertificate::fromPath =C3=A2=E2=82= =AC=E2=80=9D reject empty path strings (Qt 6.9.2+)</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Thermo Fisher--Scientific Torrent Suite Dx</td=

    <td>Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privileg=
    e escalation vulnerability that may allow an authenticated user with limite=
    d access privileges to gain unauthorized administrator-level privileges thr= ough exploitation of specific system interfaces.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-41085" target=3D= "_blank" rel=3D"noopener">CVE-2026-41085</a></td>

    <a href=3D"https://thermofisher.com" target=3D"_blank" rel=3D"noopener">htt= ps://thermofisher.com</a><br><a href=3D"https://documents.thermofisher.com/= TFS-Assets/CORP/Product-Guides/TorrentSuiteDxSoftware_v5_14_2.pdf" target= =3D"_blank" rel=3D"noopener">https://documents.thermofisher.com/TFS-Assets/= CORP/Product-Guides/TorrentSuiteDxSoftware_v5_14_2.pdf</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">tinyMQTT--<span style=3D"-webkit-text-stroke-w= idth: 0px; background-color: #fcfcfc; color: #000000; display: inline !impo= rtant; float: none; font-family: Arial, 'Source Sans Pro', 'Public Sans Web=
    ', sans-serif, Arial; font-size: 16px; font-style: normal; font-variant-cap=
    s: normal; font-variant-ligatures: normal; font-weight: 400; letter-spacing=
    : normal; orphans: 2; text-align: left; text-decoration-color: initial; tex= t-decoration-style: initial; text-decoration-thickness: initial; text-inden=
    t: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing:=
    0px;">tinyMQTT</span>
    </td>
    <td>In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18=
    ), the broker mishandles protocol violations during CONNECT packet parsing.=
    When receiving a CONNECT packet with a zero-length Client ID while CleanSe= ssion is set to 0, the broker correctly replies with a CONNACK return code = 0x02 (Identifier Rejected) but fails to explicitly close the TCP connection=
    . Since the surrounding connection teardown logic is not guaranteed to exec= ute, each such invalid CONNECT attempt leaves the underlying socket open. R= epeated attempts cause server-side resource exhaustion due to accumulating = file descriptors and memory usage, potentially resulting in denial of servi= ce.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-56352" target=3D= "_blank" rel=3D"noopener">CVE-2025-56352</a></td>

    <a href=3D"https://github.com/JustDoIt0910/tinyMQTT/issues/19" target=3D"_b= lank" rel=3D"noopener">https://github.com/JustDoIt0910/tinyMQTT/issues/19</= a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TODDR--Template::Plugin::HTML</td> <td>Template::Plugin::HTML versions through 3.102 for Perl allows HTML and = JavaScript to be injected. The html_filter function did not escape single q= uotes. HTML attributes inside of single quotes could be have code injected.=
    For example, the variable "var" in &lt;a id=3D'ref' title=3D'[% var | html=
    %]'&gt; would not be properly escaped. An attacker could insert some limit=
    ed HTML and JavaScript, for example, var =3D " ' onclick=3D'while (true) { = alert(1) }'" Note that arbitrary HTML and JavaScript would be difficult to = inject, because angle brackets, ampersands and double-quotes would still be=
    escaped.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5090" target=3D"= _blank" rel=3D"noopener">CVE-2026-5090</a></td>

    <a href=3D"https://github.com/abw/Template2/issues/327" target=3D"_blank" r= el=3D"noopener">https://github.com/abw/Template2/issues/327</a><br><a href= =3D"https://github.com/abw/Template2/pull/337/changes/11c78a7a771d4af505efe= b754a0b8775689c2eae" target=3D"_blank" rel=3D"noopener">https://github.com/= abw/Template2/pull/337/changes/11c78a7a771d4af505efeb754a0b8775689c2eae</a>= <br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TP-Link Systems Inc.--Archer AX72 (SG) v1.0</t=

    <td>In the web management interface of Archer AX72 (SG) v1, the network dia= gnostic feature improperly handles invalid user input, resulting in limited=
    exposure of diagnostic command usage information.=C2=A0 An authenticated a= ttacker with administrative privileges could exploit this issue to confirm = the presence of the diagnostic utility and view its valid command-line synt=
    ax and options.=C2=A0 The exposed information is limited in scope and does = not include sensitive system data.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5511" target=3D"= _blank" rel=3D"noopener">CVE-2026-5511</a></td>

    <a href=3D"https://www.tp-link.com/sg/support/download/archer-ax72/#Firmwar=
    e" target=3D"_blank" rel=3D"noopener">https://www.tp-link.com/sg/support/do= wnload/archer-ax72/#Firmware</a><br><a href=3D"https://www.tp-link.com/us/s= upport/faq/5096/" target=3D"_blank" rel=3D"noopener">https://www.tp-link.co= m/us/support/faq/5096/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TP-Link Systems Inc.--Archer RE650 v1</td>
    <td>An authentication logic vulnerability in multiple TP-Link range extende=
    rs allows an unauthenticated attacker on an adjacent network to manipulate =
    a login parameter and reset the administrator password due to insufficient = validation. Successful exploitation allows an attacker to obtain full admin= istrative control of the affected device, potentially impacting on confiden= tiality, integrity, and availability.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3294" target=3D"= _blank" rel=3D"noopener">CVE-2026-3294</a></td>

    <a href=3D"https://www.tp-link.com/en/support/download/re650/v1/#Firmware" = target=3D"_blank" rel=3D"noopener">https://www.tp-link.com/en/support/downl= oad/re650/v1/#Firmware</a><br><a href=3D"https://www.tp-link.com/us/support= /download/re650/v1/#Firmware" target=3D"_blank" rel=3D"noopener">https://ww= w.tp-link.com/us/support/download/re650/v1/#Firmware</a><br><a href=3D"http= s://www.tp-link.com/us/support/download/re305/v1/#Firmware" target=3D"_blan=
    k" rel=3D"noopener">https://www.tp-link.com/us/support/download/re305/v1/#F= irmware</a><br><a href=3D"https://www.tp-link.com/en/support/download/re305= /v1/#Firmware" target=3D"_blank" rel=3D"noopener">https://www.tp-link.com/e= n/support/download/re305/v1/#Firmware</a><br><a href=3D"https://www.tp-link= .com/us/support/download/re360/v1/#Firmware" target=3D"_blank" rel=3D"noope= ner">https://www.tp-link.com/us/support/download/re360/v1/#Firmware</a><br>=
    <a href=3D"https://www.tp-link.com/en/support/download/re360/v1/#Firmware" = target=3D"_blank" rel=3D"noopener">https://www.tp-link.com/en/support/downl= oad/re360/v1/#Firmware</a><br><a href=3D"https://www.tp-link.com/us/support= /download/tl-wa860re/v4/#Firmware" target=3D"_blank" rel=3D"noopener">https= ://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware</a><br><a hr= ef=3D"https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware" = target=3D"_blank" rel=3D"noopener">https://www.tp-link.com/en/support/downl= oad/tl-wa860re/v4/#Firmware</a><br><a href=3D"https://www.tp-link.com/en/su= pport/download/re580d/#Firmware" target=3D"_blank" rel=3D"noopener">https:/= /www.tp-link.com/en/support/download/re580d/#Firmware</a><br><a href=3D"htt= ps://www.tp-link.com/us/support/download/re580d/#Firmware" target=3D"_blank=
    " rel=3D"noopener">https://www.tp-link.com/us/support/download/re580d/#Firm= ware</a><br><a href=3D"https://www.tp-link.com/us/support/faq/5101/" target= =3D"_blank" rel=3D"noopener">https://www.tp-link.com/us/support/faq/5101/</= a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One (Mac)</td> <td>An origin validation error vulnerability in the Trend Micro Apex One (m= ac) agent iCore service could allow a local attacker to escalate privileges=
    on affected installations. Please note: an attacker must first obtain the = ability to execute low-privileged code on the target system in order to exp= loit this vulnerability. The following information is provided as informati= onal only for CVE references, as these were addressed already via ActiveUpd= ate/SaaS updates in mid to late 2025 (SaaS 2507 &amp; 2005 Yearly Release).= </td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71214" target=3D= "_blank" rel=3D"noopener">CVE-2025-71214</a></td>

    <a href=3D"https://success.trendmicro.com/en-US/solution/KA-0022458" target= =3D"_blank" rel=3D"noopener">https://success.trendmicro.com/en-US/solution/= KA-0022458</a><br><a href=3D"https://www.zerodayinitiative.com/advisories/Z= DI-26-139/" target=3D"_blank" rel=3D"noopener">https://www.zerodayinitiativ= e.com/advisories/ZDI-26-139/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One (Mac)</td> <td>A time-of-check time-of-use vulnerability in the Trend Micro Apex One (= mac) agent iCore service signature verification could allow a local attacke=
    r to escalate privileges on affected installations. Please note: an attacke=
    r must first obtain the ability to execute low-privileged code on the targe=
    t system in order to exploit this vulnerability. The following information =
    is provided as informational only for CVE references, as these were address=
    ed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 &am=
    p; 2005 Yearly Release).</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71215" target=3D= "_blank" rel=3D"noopener">CVE-2025-71215</a></td>

    <a href=3D"https://success.trendmicro.com/en-US/solution/KA-0022458" target= =3D"_blank" rel=3D"noopener">https://success.trendmicro.com/en-US/solution/= KA-0022458</a><br><a href=3D"https://www.zerodayinitiative.com/advisories/Z= DI-26-141/" target=3D"_blank" rel=3D"noopener">https://www.zerodayinitiativ= e.com/advisories/ZDI-26-141/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One (Mac)</td> <td>A time-of-check time-of-use vulnerability in the Trend Micro Apex One (= mac) agent cache mechanism could allow a local attacker to escalate privile= ges on affected installations. Please note: an attacker must first obtain t=
    he ability to execute low-privileged code on the target system in order to = exploit this vulnerability. The following information is provided as inform= ational only for CVE references, as these were addressed already via Active= Update/SaaS updates in mid to late 2025 (SaaS 2507 &amp; 2005 Yearly Releas= e).</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71216" target=3D= "_blank" rel=3D"noopener">CVE-2025-71216</a></td>

    <a href=3D"https://success.trendmicro.com/en-US/solution/KA-0022458" target= =3D"_blank" rel=3D"noopener">https://success.trendmicro.com/en-US/solution/= KA-0022458</a><br><a href=3D"https://www.zerodayinitiative.com/advisories/Z= DI-26-142/" target=3D"_blank" rel=3D"noopener">https://www.zerodayinitiativ= e.com/advisories/ZDI-26-142/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Trend Micro, Inc.--TrendAI Apex One (Mac)</td> <td>An origin validation error vulnerability in the Trend Micro Apex One (m= ac) agent self-protection mechanism could allow a local attacker to escalat=
    e privileges on affected installations. Please note: an attacker must first=
    obtain the ability to execute low-privileged code on the target system in = order to exploit this vulnerability. The following information is provided =
    as informational only for CVE references, as these were addressed already v=
    ia ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 &amp; 2005 Year=
    ly Release).</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-71217" target=3D= "_blank" rel=3D"noopener">CVE-2025-71217</a></td>

    <a href=3D"https://success.trendmicro.com/en-US/solution/KA-0022458" target= =3D"_blank" rel=3D"noopener">https://success.trendmicro.com/en-US/solution/= KA-0022458</a><br><a href=3D"https://www.zerodayinitiative.com/advisories/Z= DI-26-143/" target=3D"_blank" rel=3D"noopener">https://www.zerodayinitiativ= e.com/advisories/ZDI-26-143/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Trimble--SketchUp</td>
    <td>A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic C= omponents feature allows remote code execution and local file exfiltration = through maliciously crafted SKP files. The vulnerability stems from imprope=
    r input sanitization in the component options window, enabling attackers to=
    execute arbitrary system commands and read local files without user intera= ction by exploiting an embedded Internet Explorer 11 browser.</td> <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-9264" target=3D"= _blank" rel=3D"noopener">CVE-2026-9264</a></td>

    <a href=3D"https://trust.trimble.com/?tcuUid=3D52252bc0-c196-4b1f-9f13-4e4c= 9ba247d9" target=3D"_blank" rel=3D"noopener">https://trust.trimble.com/?tcu= Uid=3D52252bc0-c196-4b1f-9f13-4e4c9ba247d9</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Address List"</td>
    <td>The AddressRepository::getSqlQuery() method constructs a database query=
    without properly sanitizing user input, leading to SQL Injection. The meth=
    od is not invoked anywhere within the extension itself and therefore poses =
    no direct risk in a default installation. However, custom extensions that c= all this method with untrusted input would expose the site to SQL injection= .</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8827" target=3D"= _blank" rel=3D"noopener">CVE-2026-8827</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-012" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-012</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Content Element Selector"</t=

    <td>The extension passes an attacker-controlled cookie directly to PHP's un= serialize() without safely processing the input. A remote, unauthenticated = attacker can supply a crafted serialized payload to trigger PHP Object Inje= ction, leading to Remote Code Execution on the TYPO3 server. Exploitation r= equires the content element to be configured with "Persistent Mode: Static"=
    in the plugin settings.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46725" target=3D= "_blank" rel=3D"noopener">CVE-2026-46725</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-013" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-013</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Faceted Search"</td>
    <td>The OOXML parsing of the file indexer does not disable external entity = resolution. A crafted xlsx or pptx document placed in an indexed directory = can cause local files to be read or outbound HTTP requests to be performed,=
    with the retrieved content being written to the search index.</td> <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46722" target=3D= "_blank" rel=3D"noopener">CVE-2026-46722</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-011" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-011</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Faceted Search"</td>
    <td>The additional_tables configuration of the page and tt_content indexers=
    accepts arbitrary table and field names. A backend user with permission to=
    edit indexer configurations can copy sensitive data from internal TYPO3 ta= bles into the search index.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46723" target=3D= "_blank" rel=3D"noopener">CVE-2026-46723</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-011" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-011</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Faceted Search"</td>
    <td>The file indexer does not normalize the configured directory path. A ba= ckend user with permission to edit indexer configurations can index documen=
    ts from arbitrary locations on the server file system through path traversa=
    l sequences.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46724" target=3D= "_blank" rel=3D"noopener">CVE-2026-46724</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-011" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-011</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Frontend User Registration"<=

    <td>The create and edit flows do not restrict which user properties may be = submitted and do not enforce access control on the frontend user group assi= gnment. As a result, an attacker can assign an arbitrary frontend user grou=
    p to a newly registered or edited account, gaining unauthorized access to c= ontent and functionality restricted to privileged frontend user groups.</td=

    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-46721" target=3D= "_blank" rel=3D"noopener">CVE-2026-46721</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-009" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-009</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "News system"</td>
    <td>The extension fails to properly sanitize user input before using it in =
    a database query. As a result, an unauthenticated attacker can inject arbit= rary SQL through a URL parameter on pages using the "Date Menu of news arti= cles" plugin. Exploitation requires the "Date Menu of news articles" plugin=
    to be in use and the TypoScript/Plugin setting disableOverrideDemand not t=
    o be enabled.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8726" target=3D"= _blank" rel=3D"noopener">CVE-2026-8726</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-010" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-010</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">TYPO3--Extension "Site Crawler"</td>
    <td>The Crawler extension passes the X-T3Crawler-Meta response header from = crawled URLs directly to PHP's unserialize(). An attacker controlling a cra= wled endpoint can inject arbitrary serialized PHP objects, leading to Remot=
    e Code Execution on the TYPO3 server. Exploitation requires administrative = privileges to configure a crawler-enabled page and trigger the crawl via a = Scheduler task.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8727" target=3D"= _blank" rel=3D"noopener">CVE-2026-8727</a></td>

    <a href=3D"https://typo3.org/security/advisory/typo3-ext-sa-2026-008" targe= t=3D"_blank" rel=3D"noopener">https://typo3.org/security/advisory/typo3-ext= -sa-2026-008</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--Ajax Load More</td>
    <td>The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and = escape a parameter before outputting it back in the page, leading to a Refl= ected Cross-Site Scripting which could be used against high privilege users=
    such as admin</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6495" target=3D"= _blank" rel=3D"noopener">CVE-2026-6495</a></td>

    <a href=3D"https://wpscan.com/vulnerability/c52f28c5-547d-48ae-89dd-edcdaea= dcec5/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /c52f28c5-547d-48ae-89dd-edcdaeadcec5/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--Autoptimize</td>
    <td>The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress=
    plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vul= nerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predi= ctable replacement hash used during the HTML minification process and abusi=
    ng a regular expression. This allows an attacker to inject arbitrary HTML a= ttributes in the final HTML output by anticipating the placeholder format.<=

    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-3220" target=3D"= _blank" rel=3D"noopener">CVE-2026-3220</a></td>

    <a href=3D"https://wpscan.com/vulnerability/3ceabf11-23cd-4c38-ba14-014348b= 0ff2d/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /3ceabf11-23cd-4c38-ba14-014348b0ff2d/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--Decent Comments</td>
    <td>The Decent Comments WordPress plugin before 3.0.2 does not restrict acc= ess to comment author email addresses and post author email addresses via i=
    ts REST API endpoint, allowing unauthenticated attackers to enumerate regis= tered user email addresses.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7385" target=3D"= _blank" rel=3D"noopener">CVE-2026-7385</a></td>

    <a href=3D"https://wpscan.com/vulnerability/1c5949d0-cf50-45d3-a7e2-2f94cdb= 42405/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /1c5949d0-cf50-45d3-a7e2-2f94cdb42405/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--Email Encoder</td>
    <td>The Email Encoder WordPress plugin before 2.4.7 does not escape email a= ddresses retrieved via user input, allowing unauthenticated attackers to pe= rform Stored XSS attacks</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5776" target=3D"= _blank" rel=3D"noopener">CVE-2026-5776</a></td>

    <a href=3D"https://wpscan.com/vulnerability/00c0b9f7-c559-463e-80ae-97d99e0= ef99f/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /00c0b9f7-c559-463e-80ae-97d99e0ef99f/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--Feeds for YouTube (YouTube video, cha= nnel, and gallery plugin)</td>
    <td>The Feeds for YouTube (YouTube video, channel, and gallery plugin) Word= Press plugin before 2.6.4 is vulnerable to unauthorized modification of the=
    Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress p= lugin before 2.6.4's license key due to a missing capability check on the '= actions' function. This makes it possible for subscribers and above delete = the license key.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-1631" target=3D"= _blank" rel=3D"noopener">CVE-2026-1631</a></td>

    <a href=3D"https://wpscan.com/vulnerability/b19596c2-69bc-4e15-8632-eb80f45= 77e3c/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /b19596c2-69bc-4e15-8632-eb80f4577e3c/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--Fortis for WooCommerce</td>
    <td>The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensi= tive API keys to unauthenticated attackers, allowing them to query Fortis' = API and retrieve sensitive customer information, like past orders, PII, etc= .</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15609" target=3D= "_blank" rel=3D"noopener">CVE-2025-15609</a></td>

    <a href=3D"https://wpscan.com/vulnerability/220f72ea-e3b4-44c9-8c9b-15662ae= bb6cb/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /220f72ea-e3b4-44c9-8c9b-15662aebb6cb/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--WP Maps</td>
    <td>The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a = parameter before using it in a file path, allowing authenticated users to p= erform Local File Inclusion attacks.</td>
    <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6381" target=3D"= _blank" rel=3D"noopener">CVE-2026-6381</a></td>

    <a href=3D"https://wpscan.com/vulnerability/18b36672-58d7-44fa-b653-b728e9e= f257a/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /18b36672-58d7-44fa-b653-b728e9ef257a/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Unknown--WP Photo Album Plus</td>
    <td>The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not pro= perly sanitize and escape a parameter before using it in a SQL query, allow= ing unauthenticated users to perform SQL injection attacks.</td> <td>2026-05-18</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-6379" target=3D"= _blank" rel=3D"noopener">CVE-2026-6379</a></td>

    <a href=3D"https://wpscan.com/vulnerability/60b88fd2-4048-4773-b319-63caaf5= bd8eb/" target=3D"_blank" rel=3D"noopener">https://wpscan.com/vulnerability= /60b88fd2-4048-4773-b319-63caaf5bd8eb/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">vaadin--flow</td>
    <td>A possible information disclosure vulnerability exists in the Vaadin Ma= ven plugin and Vaadin Gradle plugin that exposes the full set of environmen=
    t variables in build logs whenever the frontend build process exits with a = non-zero status. Because the build environment may contain credentials supp= lied as secrets, any failed frontend build can expose those secrets in clea=
    r text in CI logs and archived build artifacts. Users of affected versions = should apply the following mitigation or upgrade. Releases that have fixed = this issue include: Product version Vaadin 23.0.0 - 23.6.9 Vaadin 24.0.0 - = 24.9.16 Vaadin 24.10.0 - 24.10.3 Vaadin 25.0.0 - 25.0.10 Vaadin 25.1.0 - 25= .1.4 Mitigation Upgrade to 23.6.10 Upgrade to 24.9.17 or newer Upgrade to 2= 4.10.4 or newer Upgrade to 25.0.11 or newer Upgrade to 25.1.5 or newer Plea=
    se note that Vaadin versions 10-13 and 15-22 are no longer supported and yo=
    u should update either to the latest 23, 24, or 25 version. ArtifactsMaven = coordinatesVulnerable versionsFixed versioncom.vaadin:flow-plugin-base23.0.=
    0 - 23.6.10=C3=A2=E2=80=B0=C2=A523.6.11com.vaadin:flow-plugin-base24.0.0 - = 24.9.17=C3=A2=E2=80=B0=C2=A524.9.18com.vaadin:flow-plugin-base24.10.0 - 24.= 10.3=C3=A2=E2=80=B0=C2=A524.10.4com.vaadin:flow-plugin-base25.0.0 - 25.0.11= =C3=A2=E2=80=B0=C2=A525.0.12com.vaadin:flow-plugin-base25.1.0 - 25.1.4=C3= =A2=E2=80=B0=C2=A525.1.5com.vaadin:flow-maven-plugin23.0.0 - 23.6.10=C3=A2= =E2=80=B0=C2=A523.6.11com.vaadin:flow-maven-plugin24.0.0 - 24.9.17=C3=A2=E2= =80=B0=C2=A524.9.18com.vaadin:flow-maven-plugin24.10.0 - 24.10.3=C3=A2=E2= =80=B0=C2=A524.10.4com.vaadin:flow-maven-plugin25.0.0 - 25.0.11=C3=A2=E2=80= =B0=C2=A525.0.12com.vaadin:flow-maven-plugin25.1.0 - 25.1.4=C3=A2=E2=80=B0= =C2=A525.1.5com.vaadin:flow-gradle-plugin24.0.0 - 24.9.17=C3=A2=E2=80=B0=C2= =A524.9.18com.vaadin:flow-gradle-plugin24.10.0 - 24.10.3=C3=A2=E2=80=B0=C2= =A524.10.4com.vaadin:flow-gradle-plugin25.0.0 - 25.0.11=C3=A2=E2=80=B0=C2= =A525.0.12com.vaadin:flow-gradle-plugin25.1.0 - 25.1.4=C3=A2=E2=80=B0=C2=A5= 25.1.5</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-7860" target=3D"= _blank" rel=3D"noopener">CVE-2026-7860</a></td>

    <a href=3D"https://vaadin.com/security/cve-2026-7860" target=3D"_blank" rel= =3D"noopener">https://vaadin.com/security/cve-2026-7860</a><br><a href=3D"h= ttps://github.com/vaadin/flow/pull/24219" target=3D"_blank" rel=3D"noopener= ">https://github.com/vaadin/flow/pull/24219</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">vifm--vifm</td>
    <td>vifm is vulnerable to a heap buffer overflow during the history merge p= rocess when saving the state file (vifminfo.json). This flaw occurs because=
    the application lacks a runtime check on the length of history entries in = release builds, potentially allowing a crafted long path or command in the = history to cause memory corruption or application crashes. Releases from 0.= 12.1 to=C2=A00.14.3 (including) are considered vulnerable. This issue was f= ixed in commit 23063c7</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-8997" target=3D"= _blank" rel=3D"noopener">CVE-2026-8997</a></td>

    <a href=3D"https://cert.pl/en/posts/2026/05/CVE-2026-8997" target=3D"_blank=
    " rel=3D"noopener">https://cert.pl/en/posts/2026/05/CVE-2026-8997</a><br><a=
    href=3D"https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5= b779f6910d" target=3D"_blank" rel=3D"noopener">https://github.com/vifm/vifm= /commit/23063c741f15a85621fd232dfc3ac5b779f6910d</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">WineHQ--Wine</td>
    <td>Wine ships a .desktop file that registers itself as a MIME handler for = EXE files and several other Windows executable file types. In some configur= ations, handling of an EXE file causes that file to be blindly executed wit=
    h the permissions of the invoker. This allows escaping Flatpak and Snap san= dboxes, because MIME handlers are not intended for use by code interpreters=
    and loaders. NOTE: some parties feel that this is not a bug to be addresse=
    d in Wine, because there is no known solution that avoids a severe loss of = usability (Wine could be a binfmt-misc handler, but binfmt-misc does not ex= ist on all platforms supported by Wine).</td>
    <td>2026-05-24</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-48831" target=3D= "_blank" rel=3D"noopener">CVE-2026-48831</a></td>

    <a href=3D"https://bugs.winehq.org/show_bug.cgi?id=3D59767" target=3D"_blan=
    k" rel=3D"noopener">https://bugs.winehq.org/show_bug.cgi?id=3D59767</a><br>=
    <a href=3D"https://www.openwall.com/lists/oss-security/2026/05/19/1" target= =3D"_blank" rel=3D"noopener">https://www.openwall.com/lists/oss-security/20= 26/05/19/1</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Xen--Xen</td>
    <td>Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES co= mmand within a transaction due to an assert() triggering. In case xenstored=
    was built with NDEBUG #defined nothing bad will happen, as assert() is doi=
    ng nothing in this case. Note that the default is not to define NDEBUG for = xenstored builds even in release builds of Xen.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-23557" target=3D= "_blank" rel=3D"noopener">CVE-2026-23557</a></td>

    <a href=3D"https://xenbits.xenproject.org/xsa/advisory-484.html" target=3D"= _blank" rel=3D"noopener">https://xenbits.xenproject.org/xsa/advisory-484.ht= ml</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Xen--Xen</td>
    <td>The adjustments made for XSA-379 as well as those subsequently becoming=
    XSA-387 still left a race window, when a HVM or PVH guest does a grant tab=
    le version change from v2 to v1 in parallel with mapping the status page(s)=
    via XENMEM_add_to_physmap. Some of the status pages may then be freed whil=
    e mappings of them would still be inserted into the guest's secondary (P2M)=
    page tables.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-23558" target=3D= "_blank" rel=3D"noopener">CVE-2026-23558</a></td>

    <a href=3D"https://xenbits.xenproject.org/xsa/advisory-486.html" target=3D"= _blank" rel=3D"noopener">https://xenbits.xenproject.org/xsa/advisory-486.ht= ml</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">xwiki--xwiki-commons</td>
    <td>XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-=
    1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files b=
    y using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=3D= /../../WEB-INF/xwiki.cfg&amp;minify=3Dfalse, leading to Path Traversal. The=
    vulnerability is can be exploited via resources parameter the ssx and jsx = endpoints by using leading slashes. This issue has been patched in 18.1.0-r= c-1, 17.10.3, 17.4.9, 16.10.17.</td>
    <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-23734" target=3D= "_blank" rel=3D"noopener">CVE-2026-23734</a></td>

    <a href=3D"https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-= xq3r-2qv5-vqqm" target=3D"_blank" rel=3D"noopener">https://github.com/xwiki= /xwiki-commons/security/advisories/GHSA-xq3r-2qv5-vqqm</a><br><a href=3D"ht= tps://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672= df64429bf" target=3D"_blank" rel=3D"noopener">https://github.com/xwiki/xwik= i-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf</a><br><a href=3D= "https://jira.xwiki.org/browse/XCOMMONS-3547" target=3D"_blank" rel=3D"noop= ener">https://jira.xwiki.org/browse/XCOMMONS-3547</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">xwiki--xwiki-platform</td>
    <td>XWiki Platform is a generic wiki platform offering runtime services for=
    applications built on top of it. XWiki Platform is a generic wiki platform=
    . In versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST=
    /wikis/{wikiName} API executes a XAR import without performing any authent= ication or authorization checks, allowing an unauthenticated attacker to cr= eate or update documents in the target wiki. This vulnerability has been pa= tched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.</td> <td>2026-05-20</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-33137" target=3D= "_blank" rel=3D"noopener">CVE-2026-33137</a></td>

    <a href=3D"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA= -qrvh-r3f2-9h4r" target=3D"_blank" rel=3D"noopener">https://github.com/xwik= i/xwiki-platform/security/advisories/GHSA-qrvh-r3f2-9h4r</a><br><a href=3D"= https://github.com/xwiki/xwiki-platform/commit/4b7b95b79256374d487e9ece1dc4= 8f527966990f" target=3D"_blank" rel=3D"noopener">https://github.com/xwiki/x= wiki-platform/commit/4b7b95b79256374d487e9ece1dc48f527966990f</a><br><a hre= f=3D"https://jira.xwiki.org/browse/XWIKI-23953" target=3D"_blank" rel=3D"no= opener">https://jira.xwiki.org/browse/XWIKI-23953</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Zenshin--hitarth-gg</td>
    <td>An OS command injection vulnerability in the /stream-to-vlc Express rou=
    te in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute ar= bitrary commands via the url parameter.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-37281" target=3D= "_blank" rel=3D"noopener">CVE-2026-37281</a></td>

    <a href=3D"https://github.com/hitarth-gg/zenshin" target=3D"_blank" rel=3D"= noopener">https://github.com/hitarth-gg/zenshin</a><br><a href=3D"https://g= ithub.com/hitarth-gg/zenshin/commit/7d31c6edfbac978f0ad44c66d761bab9dcd2fa2=
    7" target=3D"_blank" rel=3D"noopener">https://github.com/hitarth-gg/zenshin= /commit/7d31c6edfbac978f0ad44c66d761bab9dcd2fa27</a><br><a href=3D"https://= gist.github.com/MitruStefan/cf016709252aabbec7f95b7a70e0cfba" target=3D"_bl= ank" rel=3D"noopener">https://gist.github.com/MitruStefan/cf016709252aabbec= 7f95b7a70e0cfba</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">zephyrproject-rtos--Zephyr</td>
    <td>A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote=
    attacker to cause undefined behavior and potential system crashes. An atta= cker sends a crafted PTP_MSG_MANAGEMENT message to set an unvalidated negat= ive log_announce_interval value in the port's data set. When a subsequent P= TP_MSG_ANNOUNCE message is processed, port_timer_set_timeout_random compute=
    s a timeout as NSEC_PER_SEC &gt;&gt; -log_seconds; if the attacker-supplied=
    value is sufficiently negative (e.g., -127), the shift amount exceeds the = 64-bit integer width, triggering undefined behavior in C. This can cause a = system crash via a compiler-generated illegal instruction trap on some arch= itectures, or produce an erroneous zero timeout leading to resource starvat= ion loops or other logical errors.</td>
    <td>2026-05-22</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-5072" target=3D"= _blank" rel=3D"noopener">CVE-2026-5072</a></td>

    <a href=3D"https://github.com/zephyrproject-rtos/zephyr/security/advisories= /GHSA-3v98-458v-388r" target=3D"_blank" rel=3D"noopener">https://github.com= /zephyrproject-rtos/zephyr/security/advisories/GHSA-3v98-458v-388r</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">=C2=A0LalanaChami--Pharmacy Management System<=

    <td>API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028=
    ) lack authentication middleware. Unauthenticated remote attackers can expl= oit this to dump all user records (including bcrypt password hashes) via /a= pi/user/getUserData, modify drug inventory, and access private medical pres= cription data via /api/doctorOder.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-31071" target=3D= "_blank" rel=3D"noopener">CVE-2026-31071</a></td>

    <a href=3D"https://github.com/LalanaChami/Pharmacy-Mangment-System/tree/5c3= d02888631166649856f71d542387114b3010b/backend/routes" target=3D"_blank" rel= =3D"noopener">https://github.com/LalanaChami/Pharmacy-Mangment-System/tree/= 5c3d02888631166649856f71d542387114b3010b/backend/routes</a><br><a href=3D"h= ttps://gist.github.com/nedlir/bc8ad4693c53256819280e8f5de49286" target=3D"_= blank" rel=3D"noopener">https://gist.github.com/nedlir/bc8ad4693c5325681928= 0e8f5de49286</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">=C2=A0Panabit--PAP-XM320</td>
    <td>A command injection vulnerability exists in Panabit PAP-XM320 up to and=
    including V7.7. The web management interface invokes the backend helper /u= sr/sbin/pappiw and passes user-controlled parameters to it. The helper perf= orms unsafe argument processing using eval, which allows command injection = when attacker-controlled input is included in the arguments. As a result, a=
    n authenticated remote attacker with access to the management interface may=
    execute arbitrary shell commands.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36827" target=3D= "_blank" rel=3D"noopener">CVE-2026-36827</a></td>

    <a href=3D"https://www.panabit.com/" target=3D"_blank" rel=3D"noopener">htt= ps://www.panabit.com/</a><br><a href=3D"https://secreu.notion.site/CVE-2026= -36827-3652c0ab46158036a888ef4a12b104bf" target=3D"_blank" rel=3D"noopener"= >https://secreu.notion.site/CVE-2026-36827-3652c0ab46158036a888ef4a12b104bf= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">=C2=A0Panabit--PAP-XM320</td>
    <td>A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd=
    endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component = allows authenticated users to execute arbitrary shell commands with root pr= ivileges via the action=3Druncmd parameter.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36828" target=3D= "_blank" rel=3D"noopener">CVE-2026-36828</a></td>

    <a href=3D"https://www.panabit.com/" target=3D"_blank" rel=3D"noopener">htt= ps://www.panabit.com/</a><br><a href=3D"https://secreu.notion.site/CVE-2026= -36828-3652c0ab461580f28f50ddc37ce4e1d6" target=3D"_blank" rel=3D"noopener"= >https://secreu.notion.site/CVE-2026-36828-3652c0ab461580f28f50ddc37ce4e1d6= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">=C2=A0Panabit--PAP-XM320</td>
    <td>An authentication bypass vulnerability exists in the embedded HTTP serv=
    er of Panabit PAP-XM320 up to and including v7.7. The server validates sess= ion cookies using a filesystem existence check based on a user-controlled c= ookie value without proper sanitization, allowing directory traversal and b= ypass of authentication.</td>
    <td>2026-05-19</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36829" target=3D= "_blank" rel=3D"noopener">CVE-2026-36829</a></td>

    <a href=3D"https://www.panabit.com/" target=3D"_blank" rel=3D"noopener">htt= ps://www.panabit.com/</a><br><a href=3D"https://secreu.notion.site/CVE-2026= -36829-3652c0ab461580e19704e87b18865714" target=3D"_blank" rel=3D"noopener"= >https://secreu.notion.site/CVE-2026-36829-3652c0ab461580e19704e87b18865714= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">=C2=A0Uncrustify-- Uncrustify</td>
    <td>Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrusti= fy_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a= 4f510972bdc allows a local attacker to cause a denial of service via the ch= eck_template.cpp, check_template function, tokenize_cleanup function, uncru= stify executable components</td>
    <td>2026-05-21</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2026-36189" target=3D= "_blank" rel=3D"noopener">CVE-2026-36189</a></td>

    <a href=3D"https://github.com/uncrustify/uncrustify%2Chttps://github.com/un= crustify/uncrustify/issues/4636%2C" target=3D"_blank" rel=3D"noopener">http= s://github.com/uncrustify/uncrustify%2Chttps://github.com/uncrustify/uncrus= tify/issues/4636%2C</a><br><a href=3D"https://github.com/uncrustify/uncrust= ify/pull/4641" target=3D"_blank" rel=3D"noopener">https://github.com/uncrus= tify/uncrustify/pull/4641</a><br><a href=3D"https://gist.github.com/Critica= yon/5da6d6c9cf068e494347c659d01982a9" target=3D"_blank" rel=3D"noopener">ht= tps://gist.github.com/Criticayon/5da6d6c9cf068e494347c659d01982a9</a><br>= =C2=A0</td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    </div>
    </div>
    <style>body {
    font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
    l; font-style: normal; color: #333333;
    }
    </style>
    =20


    <div id=3D"mail_footer">
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
    r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/4190013" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"https://www.cisa.gov/privacy-policy=
    " target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
    r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
    : #757575;">=C2=A0 |=C2=A0 </span><a href=3D"https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
    an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>

    </div>
    <div id=3D"tagline">
    <hr>
    <table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=

    <tbody>

    <td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to cisa@toolazy.synchro.net using GovDelivery Com= munications Cloud, on behalf of: Cybersecurity and Infrastructure Security = Agency =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
    <td align=3D"right" width=3D"11%"><a href=3D"https://subscriberhelp.granicu= s.com/" target=3D"_blank" rel=3D"noopener"><img src=3D"https://content.govd= elivery.com/images/govd-logo-dark.png" border=3D"0" alt=3D"GovDelivery logo=
    " width=3D"115"></a></td>
    </tr>
    </tbody>
    </table>
    <style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
    img {margin-left:0px; margin-right:0px;}</style>

    </div>
    </td>
    </tr>
    </table>

    <img alt=3D"" src=3D"https://links-2.govdelivery.com/CI0/0101019e6511d824-8= d283ffd-dc0e-447c-925e-5fac8ca47810-000000/4qGiy9yWmFEcSKCgy_IyyxqzwdvRxg0Q= xQfKuG50w6M=3D452" style=3D"display: none; width: 1px; height: 1px;">
    </body>
    </html>

    --===============5510240496706666731==--

    --===============4836405085985877004==--