2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-44196 — Pingvin: From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287CWECWE 697VNDPingvinTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-44184 — Cleanuparr: Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44184

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API also authenticates requests purely by source IP via TrustedNetworkAuthenticationHandler. The combination lets any website that an admin (or any user on a truste CVSSv3.1 8.0 (HIGH)

CWECWE 942CWECWE 346VNDCleanuparrTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-44183 — Cleanuparr: Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44183

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry is attacker-controlled — X-Forwarded-For is append-only, so the leftmost value is whatever the original HTTP client claimed. By sending a spoofed local IP in the header, an unauthe CVSSv3.1 9.8 (CRITICAL)

CWECWE 290CWECWE 348VNDCleanuparrTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-43929 — ssrfcheck is a library that checks if a string contains a potential SSRF attack.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43929

ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. http://[::ffff:127.0.0.1]/). The WHATWG URL parser built into Node.js silently normalizes the IPv4 notation inside the brackets to compressed hex form ([::ffff:7f00:1]) before the library's private-IP regex ever runs. The regex was w CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 184TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-43892 — AntSword: Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43892

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16. CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 79CWECWE 1188VNDAntswordTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42898 — Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42833 — Execution: with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42833

Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 250VNDExecutionTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42823 — Azure: Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDAzureTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42048 — Langflow: Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42048

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data l CVSSv3.1 9.6 (CRITICAL)

CWECWE 22VNDLangflowTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41613 — Session: fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 384TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41109 — Improper neutralization of special elements in output used by a downstream component ('injection') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 74TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-41103 — Incorrect: implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41103

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 303TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-41096 — Heap: Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41096

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41094 — Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41094

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-41089 — Stack: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDStackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41086 — Windows: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40420 — Microsoft: Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40420

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40415 — Use: after free in Windows TCP/IP allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40415

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40403 — Heap: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-40402 — Use: after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. CVSSv3.1 9.3 (CRITICAL)

CWECWE 416TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-40379 — Exposure: of sensitive information to an unauthorized actor in Azure Entra ID allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40379

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 200TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40370 — External: control of file name or path in SQL Server allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40370

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 73TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40368 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40368

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 502TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40367 — Untrusted: pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40367

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40366 — Use: after free in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40366

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416TYPVulnerability
8.4
CVSS v3.1
92
Edit Score