2026-05-27
2026-05-27 09:16Z
HIGH

CVE-2026-40851 — This can result in a total loss of confidentiality, integrity and availability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40851

A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability. CVSSv3.1 8.4 (HIGH)

CWECWE 1287TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-27
2026-05-27 09:16Z
HIGH

CVE-2025-30028 — Active: A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-30028

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDActiveTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-27
2026-05-27 09:16Z
HIGH

CVE-2025-13392 — Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-13392

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). CVSSv3.1 8.1 (HIGH)

CWECWE 754TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 09:16Z
CRIT

CVE-2025-12686 — Buffer: copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-12686

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation Manager (BSM) before 1.3.2-65648 and Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDBufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 08:16Z
HIGH

CVE-2026-8832 — WPCode: The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8832

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_type or capability restrictions in the wpcode_register_post_type() function, allowing WordPress core to fall back to standard post capabilities for all creation paths including XML-RPC. This makes it po CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDWpcodeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 08:16Z
HIGH

CVE-2025-41669 — Web: The Web-based Management allows a remote low privileged Engineer user to install additional APPs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-41669

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control. CVSSv3.1 8.8 (HIGH)

CWECWE 347VNDWebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 07:16Z
HIGH

CVE-2026-8994 — Login: The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8994

The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered as a `wp_ajax_nopriv` action and therefore reachable by unauthenticated users — accepts an attacker-supplied `account` POST parameter and issues a valid WordPress authentication cookie based solely on a substring check for `.near`, with no nonce verification, cryptographic signature validation, challenge-r CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDLoginTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-27
2026-05-27 07:16Z
HIGH

CVE-2026-8787 — Firebase: The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8787

The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email` POST parameter without verifying ownership of that email (no Firebase ID token signature/issuer/audience verification). This makes it possible for authenticated attackers, with Subscriber-level acce CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDFirebaseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 07:16Z
CRIT

CVE-2026-8760 — Login: The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8760

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the OTP-validation branch, and the generated 6-digit OTP additionally has no expiration. This makes it possible for unauthenticated attackers to brute-force the 900,000-v CVSSv3.1 9.8 (CRITICAL)

CWECWE 307VNDLoginTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 05:16Z
CRIT

CVE-2026-8450 — HTTP: HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8450

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The wr CVSSv3.1 9.1 (CRITICAL)

CWECWE 73CWECWE 78VNDHttpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-27
2026-05-27 02:16Z
HIGH

CVE-2026-9632 — Executing a manipulation of the argument Profile can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9632

A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 02:16Z
HIGH

CVE-2026-9631 — UTT: Performing a manipulation of the argument Profile results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9631

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDUttTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 02:16Z
HIGH

CVE-2026-9628 — This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9628

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 02:16Z
HIGH

CVE-2026-9627 — The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9627

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 02:16Z
HIGH

CVE-2026-9207 — Tanium: addressed an unauthorized code execution vulnerability in Connect.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9207

Tanium addressed an unauthorized code execution vulnerability in Connect. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDTaniumTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 00:16Z
HIGH

CVE-2026-9312 — Github Enterprise_server: A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9312

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulner CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDGithubVNDSsrfTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 22:16Z
HIGH

CVE-2026-5260 — This memory corruption vulnerability could lead to information disclosure.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5260

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure. CVSSv3.1 8.2 (HIGH)

CWECWE 1284TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 22:16Z
MED

CVE-2026-48710 — Encode Starlette: Prior to version 1.0.1, the HTTP `Host` request header was not validated before being

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48710in the wild

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than th CVSSv3.1 6.5 (MEDIUM) · EPSS 80th percentile

CWECWE 444CWECWE 1289VNDEncodeVNDStarletteTYPVulnerabilitySTAitw exploited
6.5
CVSS v3.1
83
Edit Score
2026-05-26
2026-05-26 22:16Z
HIGH

CVE-2026-45574 — Java: epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45574

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2. CVSSv3.1 8.1 (HIGH)

CWECWE 295TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 22:16Z
HIGH

CVE-2026-45298 — Dozzle: Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45298

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the tar CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDDozzleTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-26
2026-05-26 22:16Z
CRIT

CVE-2026-44985 — Amirraminfar Dozzle: Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44985

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH). An attacker hosting a page on a same-site origin (e.g., a sibling subdomain, or another service on localhost) can initiate a WebSocket connec CVSSv3.1 9.6 (CRITICAL)

CWECWE 346VNDDozzleVNDAmirraminfarTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-26
2026-05-26 22:16Z
HIGH

CVE-2026-44966 — Velocity: If an application renders a template controlled by an attacker, it is possible to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44966

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE) depending on the server environment. CVSSv3.1 8.3 (HIGH)

CWECWE 1321VNDVelocityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-26
2026-05-26 22:16Z
HIGH

CVE-2026-44900 — Java: epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44900

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm setup, but never checks whether the signature actually matches. For any structurally valid signature, it returns true. This vulnerabilit CVSSv3.1 8.1 (HIGH)

CWECWE 295TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 22:16Z
HIGH

CVE-2026-42013 — This could allow a remote attacker to bypass proper certificate validation, potentially leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42013

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks. CVSSv3.1 8.2 (HIGH)

CWECWE 1284TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 21:16Z
CRIT

CVE-2026-9642 — There: is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9642

There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView project. CVSSv3.1 9.8 (CRITICAL)

CWECWE 321VNDThereTYPVulnerability
9.8
CVSS v3.1
99
Edit Score