2026-05-12
2026-05-12 16:16Z
HIGH

CVE-2026-30807 — Artica Pandora_fms: Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30807

Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800 CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDArticaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 16:16Z
CRIT

CVE-2026-30805 — Artica Pandora_fms: Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30805

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800 CVSSv3.1 9.1 (CRITICAL)

CWECWE 1188VNDArticaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 16:16Z
HIGH

CVE-2023-27753 — An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-27753

An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file. CVSSv3.1 8.0 (HIGH)

CWECWE 434TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-12
2026-05-12 15:16Z
CRIT

CVE-2026-8401 — Sandbox: escape in the Profile Backup component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8401

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 15:16Z
HIGH

CVE-2026-8111 — SQL: injection in the web console of Ivanti Endpoint Manager before version 2024 SU6

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8111

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 15:16Z
CRIT

CVE-2026-8043 — External: control of a file name in Ivanti Xtraction before version 2026.2 allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8043

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks. CVSSv3.1 9.6 (CRITICAL)

CWECWE 73TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 15:16Z
HIGH

CVE-2026-43983 — Pocket-id Pocket_id: This allows (1) the client to refresh the token indefinitely after authorization revocation, (2)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43983

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new tokens. This allows (1) the client to refresh the token indefinitely after authorization revocation, (2) the refresh token to continue to work after the account is di CVSSv3.1 8.1 (HIGH)

CWECWE 285CWECWE 613VNDPocket IdVNDPocketTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-12
2026-05-12 15:16Z
HIGH

CVE-2026-43938 — YetAnotherForum: Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43938

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header into a JObject, serializes it with JsonConvert, and stores the result in the EventLog.Description column whenever an event (e.g., an unhandled exception) is logged. The admin event-log page (YetAnotherForum.NET/Pages/Admin/EventLog.cshtml.cs) later deserializes that JSON in FormatSt CVSSv3.1 8.1 (HIGH)

CWECWE 79CWECWE 80CWECWE 116VNDYetanotherforumTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 15:16Z
HIGH

CVE-2026-43937 — YetAnotherForum: YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43937

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSql, whose OnPostRunQuery binds Editor from the POST body and passes it straight to IDbAccess.RunSql with no caller check, yielding arbitrary SQL execution for any low-privileged user. This vulnerability is fixed in 4.0.5. CVSSv3.1 8.8 (HIGH)

CWECWE 89CWECWE 841VNDYetanotherforumTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 15:16Z
HIGH

CVE-2026-42260 — Open: Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42260

Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7. CVSSv3.1 8.2 (HIGH)

CWECWE 918TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 14:17Z
HIGH

CVE-2026-8389 — Mozilla Firefox: JIT miscompilation in the JavaScript Engine: JIT component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8389

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 843CWECWE 119CWECWE 686VNDMozillaVNDJitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 14:17Z
CRIT

CVE-2026-45091 — sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45091

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, kubectl describe pod, Sentry/Rollbar stack traces, log aggregators) could decode CVSSv3.1 9.1 (CRITICAL)

CWECWE 200CWECWE 522TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 14:17Z
HIGH

CVE-2026-35071 — Dell: PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35071

Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. CVSSv3.1 8.2 (HIGH)

CWECWE 78VNDDellTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 11:16Z
HIGH

CVE-2026-45214 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45214

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-12
2026-05-12 11:16Z
HIGH

CVE-2026-45211 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45211

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.1. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-12
2026-05-12 11:16Z
HIGH

CVE-2026-42742 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42742

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-12
2026-05-12 11:16Z
HIGH

CVE-2026-42741 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42741

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend: from n/a through <= 3.3.2. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-12
2026-05-12 11:16Z
HIGH

CVE-2026-41713 — Applications using the affected advisor with user-controlled input may be susceptible to manipulation of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41713

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns. CVSSv3.1 8.2 (HIGH)

CWECWE 1336TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 11:16Z
HIGH

CVE-2026-2465 — Incorrect: Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2465

Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026. CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 11:00Z
INFO

Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.

Trail of Bits·blog.trailofbits.com

Trail of Bits released gosentry, a fork of the Go toolchain that enhances Go's native fuzzing capabilities by integrating LibAFL, Nautilus grammar-based fuzzing, and additional bug detectors (integer overflows, data races, goroutine leaks, timeouts). The tool maintains backward compatibility with existing Go fuzz harnesses while adding struct-aware fuzzing, path constraint solving, and coverage reporting—capabilities previously unavailable in vanilla Go fuzzing.

SRFApplicationSWLibaflSWNautilusTYPResearchTYPToolSTGDiscoveryTECT1592
72
Edit Score
2026-05-12
2026-05-12 10:16Z
HIGH

CVE-2026-6001 — Authorization: bypass through User-Controlled key vulnerability in ABIS Technology Ltd.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6001

Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042. CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 10:16Z
CRIT

CVE-2026-41551 — Affected versions contain a path traversal vulnerability because user input is not properly sanitized.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41551

A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote attacker to access arbitrary files on the device. CVSSv3.1 9.1 (CRITICAL)

CWECWE 23TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 10:16Z
CRIT

CVE-2026-25787 — This could allow an authenticated attacker who is authorized to download a TIA project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25787

Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session. CVSSv3.1 9.1 (CRITICAL)

CWECWE 79TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 10:16Z
CRIT

CVE-2026-25786 — This could allow an authenticated attacker who is authorized to download a TIA project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25786

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session. CVSSv3.1 9.1 (CRITICAL)

CWECWE 79TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 10:16Z
CRIT

CVE-2026-22924 — The affected application does not properly restrict unauthenticated connections and is susceptible to resource

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22924

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially impacting system availability and integrity. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306TYPVulnerability
9.1
CVSS v3.1
96
Edit Score