2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-46037 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46037

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describes the traditional ICMP types up to NR_ICMP_TYPES. Avoid consulting icmp_pointers[] for reply types outside that range, and use array_index_nospec() for the remaining in-range lookup. Normal ICMP rep CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-46010 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46010

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling in rxgk_extract_token() Fix a missing bit of error handling in rxgk_extract_token(): in the event that rxgk_decrypt_skb() returns -ENOMEM, it should just return that rather than continuing on (for anything else, it generates an abort). CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-45988 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45988

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a retry. Fix this by just discarding the packet; we will send another CHALLENGE packet and thereby elicit a further response. Similarly, discard an incoming CHALLENGE packet if we get an error whilst generating a RESPONSE; th CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-45972 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45972

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a double free. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-45945 — Linux: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45945

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition during PASID entry replacement The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing an active PASID entry (e.g., during domain replacement), the current implementation calculates a new entry on the stack and copies it to the table using a single structure assignment. struct pasid_entry *pte, new_pte; pte = intel_pasid_get_entry(dev, pasid); CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-45898 — Linux: It could then get reused (INIT_WORK...) and lead to list corruption in the workqueue

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45898

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168f0 ("RDMA/iwcm: Simplify cm_event_handler()") changed the work submission logic to unconditionally call queue_work() with the expectation that queue_work() would have no effect if work was already pending. The problem is that a free list of struct iwcm_work is used (for which struct work_struct is embedded), so each call to queue CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 14:16Z
HIGH

CVE-2026-36044 — @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36044

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child_process.exec(). Because exec() spawns a shell, shell metacharacters in those values are interpreted by the host shell, resulting in arbitrary OS command execution with the privi CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-27
2026-05-27 14:16Z
HIGH

CVE-2025-71311 — Linux Linux_kernel: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71311

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked uptodate and ni_read_frame() is skipped because the caller expects the frame to be completely overwritten, some reserved folios may remain only partially filled, leaving the rest memory uninitialized. CVSSv3.1 8.2 (HIGH) · EPSS 5th percentile

CWECWE 908TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 11:16Z
HIGH

CVE-2026-48906 — Tassos Advanced_custom_fields: The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48906

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDTassosTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 11:16Z
HIGH

CVE-2026-45843 — Linux: In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45843

In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neither helper bounds-checks against isize, and decode() masks its return with & 0xffff so it can never return the -1 that callers test for -- those error paths are dead code. A short compressed frame whose change byte reque CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42761 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42761

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42758 — Incorrect: Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42758

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42757 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42757

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42756 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42756

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly: from n/a through <= 3.2.7. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42755 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42755

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42748 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42748

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42747 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42747

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42740 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42740

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a through <= 1.0.3. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 11:16Z
HIGH

CVE-2026-42737 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42737

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-27
2026-05-27 11:16Z
HIGH

CVE-2026-42735 — Authentication: Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42735

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0. CVSSv3.1 8.2 (HIGH)

CWECWE 288TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42731 — Incorrect: Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42731

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 11:16Z
HIGH

CVE-2026-42730 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42730

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.7.29. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-27
2026-05-27 11:16Z
CRIT

CVE-2026-42727 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42727

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 11:16Z
HIGH

CVE-2026-3012 — A flaw was found in Samba’s certificate auto-enrollment Group Policy handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3012

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted c CVSSv3.1 8.0 (HIGH)

TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-27
2026-05-27 09:16Z
CRIT

CVE-2026-49002 — Access: control failure means that an application does not effectively check user access permissions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49002

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDAccessTYPVulnerability
9.1
CVSS v3.1
96
Edit Score