Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH
CVE-2026-9112 — Use: after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed
Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH
CVE-2026-9111 — Use: after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
CRIT
CVE-2026-9082 — Drupal Drupal: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in
NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9082in the wild
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
CVSSv3.1 9.8 (CRITICAL) · EPSS 100th percentile
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files.
This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 434TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH
CVE-2026-39310 — Trilium: In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposing endpoints such as /api/clipper/notes to the network with no password, API token
CVSSv3.1 8.6 (HIGH)
CWECWE 306CWECWE 284VNDTriliumTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH
CVE-2026-24218 — NVIDIA: The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or
NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of s
CVSSv3.1 8.1 (HIGH)
CWECWE 321VNDNvidiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-20
2026-05-20 20:16Z
HIGH
CVE-2026-24217 — NVIDIA: BioNeMo Core for Linux contains a vulnerability where a user could cause a
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
CVSSv3.1 8.8 (HIGH)
CWECWE 29VNDNvidiaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH
CVE-2026-24188 — NVIDIA: TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write.
NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.
CVSSv3.1 8.2 (HIGH)
CWECWE 787VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-20
2026-05-20 20:16Z
INFO
CVE-2026-23734 — XWiki: Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be exploited via resources parameter the ssx and jsx endpoints by using leading slashes. This issue has been patched in 18.1.0-rc-1, 17.10.3, 17.4.9, 16.10.17.
EPSS 97th percentile
CVE-2026-44578 is a high-severity SSRF vulnerability in self-hosted Next.js applications (versions 13.4.13–15.5.15 and 16.0.0–16.2.4) affecting WebSocket upgrade request handling. Crafted requests can force the Node.js server to proxy connections to arbitrary internal or external destinations, potentially exposing cloud metadata, internal services, and administrative interfaces. Vercel-hosted deployments are unaffected; patches are available in Next.js 15.5.16+ and 16.2.5+.
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.
CVSSv3.1 8.8 (HIGH)
CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 17:16Z
CRIT
CVE-2026-20223 — A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role.
This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the a
CVSSv3.1 10.0 (CRITICAL)
CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 16:16Z
CRIT
CVE-2026-8598 — An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras.
An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as open services and
camera account credentials.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 288TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-20
2026-05-20 14:16Z
HIGH
CVE-2026-24425 — Twig: versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.
CVSSv3.1 8.8 (HIGH)
CWECWE 693VNDTwigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 13:16Z
HIGH
CVE-2026-45584 — Heap: Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over
CVE-2026-41091 — Microsoft Malware_protection_engine: Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized
NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41091in the wild
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVSSv3.1 7.8 (HIGH) · EPSS 94th percentile
Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery.
This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.0 (HIGH)
CWECWE 352TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-20
2026-05-20 11:16Z
CRIT
CVE-2026-22314 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher
Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.
CVSSv3.1 9.0 (CRITICAL)
CWECWE 94TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-20
2026-05-20 10:16Z
CRIT
CVE-2026-42960 — Nlnetlabs Unbound: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSe
CVSSv3.1 10.0 (CRITICAL)
CWECWE 349VNDNlnetlabsVNDNlnetTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 10:16Z
CRIT
CVE-2026-33278 — Nlnetlabs Unbound: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (int
CVSSv3.1 9.8 (CRITICAL)
CVE-2026-3102 is a command injection vulnerability in ExifTool versions 13.49 and earlier affecting macOS systems. An attacker can craft a malicious image file with injected shell commands in the FileCreateDate metadata field, which executes with the privileges of the user running ExifTool when the -n flag and -tagsFromFile feature are used. The vulnerability was patched in version 13.50 by replacing string-based system calls with list-form argument passing.
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these
CVSSv3.1 8.8 (HIGH)