2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-9114 — Use: after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9114

Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-9112 — Use: after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9112

Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-9111 — Use: after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9111

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
CRIT

CVE-2026-9082 — Drupal Drupal: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9082in the wild

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10. CVSSv3.1 9.8 (CRITICAL) · EPSS 100th percentile

CWECWE 89VNDDrupalTYPVulnerabilitySTAitw exploited
9.8
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 20:16Z
CRIT

CVE-2026-45444 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45444

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-39310 — Trilium: In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39310

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposing endpoints such as /api/clipper/notes to the network with no password, API token CVSSv3.1 8.6 (HIGH)

CWECWE 306CWECWE 284VNDTriliumTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-24218 — NVIDIA: The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24218

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of s CVSSv3.1 8.1 (HIGH)

CWECWE 321VNDNvidiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-24217 — NVIDIA: BioNeMo Core for Linux contains a vulnerability where a user could cause a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24217

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. CVSSv3.1 8.8 (HIGH)

CWECWE 29VNDNvidiaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 20:16Z
HIGH

CVE-2026-24188 — NVIDIA: TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24188

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-20
2026-05-20 20:16Z
INFO

CVE-2026-23734 — XWiki: Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23734

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be exploited via resources parameter the ssx and jsx endpoints by using leading slashes. This issue has been patched in 18.1.0-rc-1, 17.10.3, 17.4.9, 16.10.17. EPSS 97th percentile

CWECWE 23VNDXwikiTYPVulnerability
56
Edit Score
2026-05-20
2026-05-20 19:00Z
HIGH

CVE-2026-44578 | Next.js Server-Side Request Forgery Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-44578

CVE-2026-44578 is a high-severity SSRF vulnerability in self-hosted Next.js applications (versions 13.4.13–15.5.15 and 16.0.0–16.2.4) affecting WebSocket upgrade request handling. Crafted requests can force the Node.js server to proxy connections to arbitrary internal or external destinations, potentially exposing cloud metadata, internal services, and administrative interfaces. Vercel-hosted deployments are unaffected; patches are available in Next.js 15.5.16+ and 16.2.5+.

SRFApplicationTACTA0001SRFWebSWNextjsVNDVercelTYPVulnerabilitySTGInitial AccessTECT1190
72
Edit Score
2026-05-20
2026-05-20 17:16Z
HIGH

CVE-2026-44926 — InfoScale: CmdServer before 7.4.2 mishandles access control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44926

InfoScale CmdServer before 7.4.2 mishandles access control. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDInfoscaleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 17:16Z
HIGH

CVE-2026-44925 — Site: Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44925

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 17:16Z
CRIT

CVE-2026-20223 — A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20223

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the a CVSSv3.1 10.0 (CRITICAL)

CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 16:16Z
CRIT

CVE-2026-8598 — An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8598

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials. CVSSv3.1 9.1 (CRITICAL)

CWECWE 288TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-20
2026-05-20 14:16Z
HIGH

CVE-2026-24425 — Twig: versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24425

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDTwigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-20
2026-05-20 13:16Z
HIGH

CVE-2026-45584 — Heap: Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45584

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-20
2026-05-20 13:16Z
MED

CVE-2026-45498 — Microsoft Defender_antimalware_platform: Defender Denial of Service Vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45498in the wild

Microsoft Defender Denial of Service Vulnerability CVSSv3.1 4.0 (MEDIUM) · EPSS 99th percentile

CWECWE 400VNDMicrosoftTYPVulnerabilitySTAitw exploited
4.0
CVSS v3.1
89
Edit Score
2026-05-20
2026-05-20 13:16Z
HIGH

CVE-2026-41091 — Microsoft Malware_protection_engine: Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41091in the wild

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.8 (HIGH) · EPSS 94th percentile

CWECWE 59VNDMicrosoftTYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
92
Edit Score
2026-05-20
2026-05-20 13:16Z
HIGH

CVE-2025-11954 — Site: Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-11954

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.0 (HIGH)

CWECWE 352TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-20
2026-05-20 11:16Z
CRIT

CVE-2026-22314 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22314

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. CVSSv3.1 9.0 (CRITICAL)

CWECWE 94TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-20
2026-05-20 10:16Z
CRIT

CVE-2026-42960 — Nlnetlabs Unbound: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42960

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSe CVSSv3.1 10.0 (CRITICAL)

CWECWE 349VNDNlnetlabsVNDNlnetTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-20
2026-05-20 10:16Z
CRIT

CVE-2026-33278 — Nlnetlabs Unbound: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33278

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (int CVSSv3.1 9.8 (CRITICAL)

CWECWE 416CWECWE 672VNDNlnetlabsVNDNlnetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-20
2026-05-20 09:02Z
HIGH

How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)

Kaspersky Securelist·securelist.comCVE-2026-3102

CVE-2026-3102 is a command injection vulnerability in ExifTool versions 13.49 and earlier affecting macOS systems. An attacker can craft a malicious image file with injected shell commands in the FileCreateDate metadata field, which executes with the privileges of the user running ExifTool when the -n flag and -tagsFromFile feature are used. The vulnerability was patched in version 13.50 by replacing string-based system calls with list-form argument passing.

SRFApplicationTACTA0002OSMacosSWExiftoolTYPVulnerabilitySTGExecutionTECT1059EXPCommand Injection
76
Edit Score
2026-05-20
2026-05-20 08:16Z
HIGH

CVE-2026-5200 — AcyMailing: The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5200

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDAcymailingTYPVulnerability
8.8
CVSS v3.1
94
Edit Score