2026-05-12
2026-05-12 20:16Z
CRIT

CVE-2026-45185 — Exim: before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45185

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDEximTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 20:16Z
CRIT

CVE-2026-44225 — Pulpy: Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44225

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath() function is supposed to sandbox this access, but its blocklist is incomplete. Any web app packaged with Pulpy can read and write arbitrary files in the user's home directory — including ~/.ssh/id_rsa, ~/.aws/credentials, and ~/Library/Keychains/ CVSSv3.1 9.3 (CRITICAL)

CWECWE 284CWECWE 22VNDPulpyTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 20:16Z
CRIT

CVE-2026-44221 — ArcadeDB: Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44221

ArcadeDB is a Multi-Model DBMS. Prior to 2.6.4, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database created via POST /api/v1 CVSSv3.1 9.0 (CRITICAL)

CWECWE 863VNDArcadedbTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-12
2026-05-12 20:16Z
CRIT

CVE-2026-42889 — Relay: Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42889

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token query parameter were incorrectly treated as having full server permissions. An unauthenticated network attacker who knows or guesses a document ID could connect to the document sync WebSocket and read or modify document contents without a va CVSSv3.1 9.1 (CRITICAL)

CWECWE 639CWECWE 863VNDRelayTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 20:16Z
HIGH

CVE-2026-34686 — Adobe: Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34686

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAdobeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 20:16Z
HIGH

CVE-2026-34653 — Adobe: Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34653

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system read and write. An authenticated attacker with administrative privileges could exploit this vulnerability to read or write files outside the restricted directory. Exploitation of this issue does not require user interaction. CVSSv3.1 8.7 (HIGH)

CWECWE 22VNDAdobeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 20:16Z
HIGH

CVE-2026-34650 — Adobe Commerce: versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34650

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction. CVSSv3.1 7.5 (HIGH) · EPSS 97th percentile

CWECWE 400VNDAdobeTYPVulnerability
7.5
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-12
2026-05-12 20:16Z
HIGH

CVE-2026-34649 — Adobe Commerce: versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34649

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction. CVSSv3.1 7.5 (HIGH) · EPSS 96th percentile

CWECWE 400VNDAdobeTYPVulnerability
7.5
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 20:16Z
HIGH

CVE-2026-34648 — Adobe Commerce: versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34648

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction. CVSSv3.1 7.5 (HIGH) · EPSS 98th percentile

CWECWE 400VNDAdobeTYPVulnerability
7.5
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 19:16Z
HIGH

CVE-2026-8430 — SPIP: versions prior to 4.4.14 contain a remote code execution vulnerability in the public

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8430

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuration scenarios to achieve code execution, and this issue is not mitigated by the SPIP security screen. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDSpipTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 19:16Z
HIGH

CVE-2026-8429 — SPIP: versions prior to 4.4.14 contain a remote code execution vulnerability in the private

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8429

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve code execution that bypasses the SPIP security screen protections. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDSpipTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 19:16Z
CRIT

CVE-2026-34660 — Adobe: Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34660

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or CVSSv3.1 9.3 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 19:16Z
CRIT

CVE-2026-34659 — Adobe: Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34659

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed. CVSSv3.1 9.6 (CRITICAL)

CWECWE 502VNDAdobeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 19:16Z
HIGH

CVE-2026-23819 — A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23819

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-44343 — Wgdashboard Wgdashboard: Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44343

WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is fixed in 4.3.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDWgdashboardTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-44277 — A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44277

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here> CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-44196 — Pingvin: From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287CWECWE 697VNDPingvinTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-44184 — Cleanuparr: Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44184

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API also authenticates requests purely by source IP via TrustedNetworkAuthenticationHandler. The combination lets any website that an admin (or any user on a truste CVSSv3.1 8.0 (HIGH)

CWECWE 942CWECWE 346VNDCleanuparrTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-44183 — Cleanuparr: Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44183

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry is attacker-controlled — X-Forwarded-For is append-only, so the leftmost value is whatever the original HTTP client claimed. By sending a spoofed local IP in the header, an unauthe CVSSv3.1 9.8 (CRITICAL)

CWECWE 290CWECWE 348VNDCleanuparrTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-43929 — ssrfcheck is a library that checks if a string contains a potential SSRF attack.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43929

ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. http://[::ffff:127.0.0.1]/). The WHATWG URL parser built into Node.js silently normalizes the IPv4 notation inside the brackets to compressed hex form ([::ffff:7f00:1]) before the library's private-IP regex ever runs. The regex was w CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 184TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-43892 — AntSword: Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43892

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16. CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 79CWECWE 1188VNDAntswordTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42898 — Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42833 — Execution: with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42833

Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 250VNDExecutionTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42823 — Azure: Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDAzureTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-42048 — Langflow: Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42048

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data l CVSSv3.1 9.6 (CRITICAL)

CWECWE 22VNDLangflowTYPVulnerability
9.6
CVSS v3.1
98
Edit Score