2026-05-13
2026-05-13 22:16Z
HIGH

CVE-2026-44447 — ERPNext: Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44447

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDErpnextTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 22:16Z
HIGH

CVE-2026-44446 — ERPNext: Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44446

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16.14.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDErpnextTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 22:16Z
CRIT

CVE-2026-44442 — ERPNext: Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44442

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862VNDErpnextTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-13
2026-05-13 22:16Z
CRIT

CVE-2026-44194 — OPNsense: Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44194

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underlying operating system. The flaw exists in the local user synchronization flow, wi CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDOpnsenseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 22:16Z
CRIT

CVE-2026-44193 — OPNsense: Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44193

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7. CVSSv3.1 9.1 (CRITICAL)

CWECWE 88VNDOpnsenseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 22:16Z
HIGH

CVE-2026-42463 — Fit2cloud Sqlbot: Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42463

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoints. An attacker can access and modify database schemas and data sources belonging to other tenants/workspaces. This vulnerability is fixed in 1.8.0. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDFit2cloudVNDSqlbotTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 22:16Z
HIGH

CVE-2026-32993 — Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32993

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response. CVSSv3.1 8.3 (HIGH)

CWECWE 93TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-13
2026-05-13 22:16Z
HIGH

CVE-2026-32992 — SSL: This could allow for a malicious server to man-in-the-middle the request and capture credentials.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32992

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. CVSSv3.1 8.2 (HIGH)

CWECWE 295VNDSslTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 22:16Z
HIGH

CVE-2026-29205 — Incorrect: privileges management and insufficient path filtering allow to read arbitrary file on the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-29205

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. CVSSv3.1 8.6 (HIGH)

CWECWE 250TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-13
2026-05-13 21:16Z
CRIT

CVE-2026-45714 — CubeCart: Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45714

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated user with administrative privileges to execute arbitrary operating system commands CVSSv3.1 9.1 (CRITICAL)

CWECWE 94CWECWE 1336VNDCubecartTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 21:16Z
HIGH

CVE-2026-45229 — Quark: Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45229

Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services. CVSSv3.1 8.8 (HIGH)

CWECWE 915VNDQuarkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 21:16Z
HIGH

CVE-2026-45055 — CubeCart: Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45055

CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordRequest() (and the admin equivalent in Admin::passwordRequest()). An unauthenticated attacker who knows a target email can POST /index.php?_a=recover with Host: evil.com; CubeCart wri CVSSv3.1 8.1 (HIGH)

CWECWE 345CWECWE 20CWECWE 601CWECWE 784VNDCubecartTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 21:16Z
CRIT

CVE-2026-45053 — CubeCart: Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45053

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the web-accessible images/source/ directory, where they are executed by the web server. Combined with a path-traversal flaw in the same endpoint's filepath parameter, a single API reques CVSSv3.1 9.1 (CRITICAL)

CWECWE 434VNDCubecartTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 21:16Z
CRIT

CVE-2026-44377 — CubeCart: Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44377

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty template engine. By leveraging this, an authenticated attacker with administrative privileges can bypass current restrictions and call native PHP functions within the templates, such as CVSSv3.1 9.1 (CRITICAL)

CWECWE 94CWECWE 1336VNDCubecartTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 21:16Z
HIGH

CVE-2026-42602 — Azure: From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42602

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access token for any scope the collector's configured identity can mint for to authenticate to any OpenTelemetry receiver that uses auth: azure_auth. The extension's Authenticate method does not validate incoming bearer tokens as JWTs. Instead, it calls its own configured credential to obtai CVSSv3.1 8.1 (HIGH)

CWECWE 287CWECWE 290CWECWE 208CWECWE 294VNDAzureTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 21:16Z
HIGH

CVE-2026-21821 — HCL: Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21821

The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks such as Cross-Site Scripting (XSS) or manipulation through vulnerable third-party components. CVSSv3.1 8.3 (HIGH)

CWECWE 1104VNDHclTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-13
2026-05-13 21:16Z
CRIT

CVE-2025-27851 — The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-27851

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this vulnerability, the victim must (1) be utilizing a web browser on a multihomed host that has local interfaces on the Garmin Marine Network as well as another netwo CVSSv3.1 9.3 (CRITICAL)

CWECWE 352TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-13
2026-05-13 20:16Z
CRIT

CVE-2026-44351 — JSON: Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44351

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an empty string (''), for example via the common keys[decoded.header.kid] || '' JWKS-style fallback, fast-jwt converts it to a zero-length Buffer, hands it to crypto.createSecretKey, CVSSv3.1 9.1 (CRITICAL)

CWECWE 287CWECWE 1391CWECWE 326TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 20:16Z
HIGH

CVE-2026-42550 — Flight: Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL statements by concatenating the $table

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42550

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL statements by concatenating the $table argument and the keys of the $data array directly into the query, with no identifier quoting and no validation. When an application forwards user-controlled data shapes to these helpers — a common and documented pattern, e.g. $db->insert('users', $request->data->getData()) — an attacker can inject CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDFlightTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 19:17Z
CRIT

CVE-2026-42032 — Okfn Ckan: Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42032

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863VNDOkfnVNDCkanTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 19:17Z
CRIT

CVE-2026-42031 — Okfn Ckan: Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42031

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDOkfnVNDCkanTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 19:17Z
HIGH

CVE-2026-33583 — Exposure: of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33583

Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03. CVSSv3.1 8.7 (HIGH)

CWECWE 749TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 19:17Z
HIGH

CVE-2026-0259 — Paloaltonetworks Pan-os: An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0259

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note tha CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 73VNDPaloaltonetworksTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 19:17Z
CRIT

CVE-2026-0258 — Paloaltonetworks Pan-os: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0258

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities. CVSSv3.1 9.1 (CRITICAL) · EPSS 24th percentile

CWECWE 918VNDPaloaltonetworksVNDSsrfTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 19:17Z
CRIT

CVE-2026-0257 — Paloaltonetworks Pan-os: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS®

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0257

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. CVSSv3.1 9.1 (CRITICAL)

CWECWE 565VNDPaloaltonetworksTYPVulnerability
9.1
CVSS v3.1
96
Edit Score