2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28995 — A logic issue was addressed with improved restrictions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28995

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28978 — Apple Macos: A permissions issue was addressed with additional restrictions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28978

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDAppleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28955 — Apple Ipados: Processing maliciously crafted web content may lead to an unexpected process crash.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28955

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDAppleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28947 — A use-after-free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28947

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28923 — A logging issue was addressed with improved data redaction.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28923

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox. CVSSv3.1 8.8 (HIGH)

CWECWE 532TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28907 — The issue was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28907

The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. CVSSv3.1 8.1 (HIGH)

CWECWE 20CWECWE 116TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 21:18Z
HIGH

CVE-2026-28847 — Apple Ipados: Processing maliciously crafted web content may lead to an unexpected process crash.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28847

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDAppleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-11
2026-05-11 20:25Z
CRIT

CVE-2026-42882 — Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42882

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the percent-encoded request URI (r.URL.RequestURI()), while the bucket handler constructs S3 object keys from the decoded path (r.URL.Path). This mismatch, combined with the glob library CVSSv3.1 9.4 (CRITICAL)

CWECWE 863CWECWE 22TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-11
2026-05-11 20:25Z
CRIT

CVE-2026-42869 — SOCFortress: CoPilot focuses on providing a single pane of glass for all your security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42869

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly set — including the default Docker Compose setup — signs all authentication tokens with this publicly known value. An unauthenticated attacker can forge arbitrar CVSSv3.1 10.0 (CRITICAL)

CWECWE 287CWECWE 522CWECWE 798VNDSocfortressTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-11
2026-05-11 20:25Z
HIGH

CVE-2026-36734 — EDIMAX: BR-6428nS V3 1.15 is vulnerable to Command Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36734

EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient input validation, the attacker is able to execute arbitrary system commands on the device. CVSSv3.1 8.8 (HIGH)

CWECWE 77VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 19:16Z
HIGH

CVE-2026-45223 — Crabbox: before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45223

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease CVSSv3.1 8.8 (HIGH)

CWECWE 290VNDCrabboxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 19:16Z
CRIT

CVE-2026-42864 — FireFighter: On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42864

FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permissions.AllowAny]). Its attachments payload is fetched server-side via httpx.get() with no URL validation, then uploaded as an attachment on the Jira ticket that gets created. An unauthenticated caller able to reach the ingress can coerce the pod into fetching arbitrary URLs a CVSSv3.1 9.9 (CRITICAL)

CWECWE 306CWECWE 918VNDFirefighterTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-11
2026-05-11 18:16Z
CRIT

CVE-2026-7210 — Libexpat_project Libexpat: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7210

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. CVSSv3.1 9.8 (CRITICAL)

CWECWE 331VNDLibexpat ProjectTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-4892 — A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4892

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet. CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-45006 — OpenClaw: before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45006

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete denylist protection. Attackers can persist malicious config modifications affecting command execution, network behavior, credentials, and operator policies that survive restart. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-44413 — JetBrains: In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44413

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDJetbrainsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 18:16Z
CRIT

CVE-2026-43995 — Flowiseai Flowise: Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43995

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. These tools include (1) OpenAPIToolkit/OpenAPIToolkit.ts, (2) WebScraperTool/WebScraperTool.ts, (3) MCP/core.ts, and (4) Arxiv/core.ts. This vulnerability is fixed in 3.1.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 918VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-43640 — Bitwarden: Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43640

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session. CVSSv3.1 8.1 (HIGH)

CWECWE 303VNDBitwardenTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-43639 — Bitwarden: Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43639

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true). CVSSv3.1 8.0 (HIGH)

CWECWE 862VNDBitwardenTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-42860 — Open: The Open edx Enterprise Service app provides enterprise features to the Open edX platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42860

The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SAMLProviderDataViewSet fetches SAML metadata from a URL stored in SAMLProviderConfig.metadata_source. An authenticated user with the Enterprise Admin role can set this field to an arbitrary URL via the SAMLProviderConfigViewSet PATCH endpoint, then trigger a server-side HTTP request by calling sync_provider_data. The fetch in fetc CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-42858 — Open: edX Platform enables the authoring and delivery of online learning at any scale.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42858

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed directly to requests.get() in fetch_metadata_xml() without any URL validation, IP filtering, or scheme enforcement. An attacker with Enterprise Admin privileges can force the server to make HTTP requests to i CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-42315 — pyLoad is a free and open-source download manager written in Python.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42315

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package. This vulnerability is fixed in 0.5.0b3.dev100. CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 36TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-42313 — Any authenticated user with the non-admin SETTINGS permission can enable proxying and point pyload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42313

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The allowlist contains ("proxy", "username") and ("proxy", "password") — which protect the proxy credentials — but it does not include ("proxy", "enabled"), ("proxy", "host"), ("proxy", "port"), CVSSv3.1 8.3 (HIGH)

CWECWE 918CWECWE 863CWECWE 441TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-41431 — Zen: Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41431

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signatures, and the updater binary contains zero cryptographic verification code. This eliminates the defense-in-depth that MAR signing provides. If the update server or GitHub release pipe CVSSv3.1 8.0 (HIGH)

CWECWE 347VNDZenTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-11
2026-05-11 18:16Z
HIGH

CVE-2026-38568 — HireFlow: v1.2 is vulnerable to Incorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38568

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner or has an authorized role. Any authenticated user can access any other user's candidate profiles and interview notes by iterating the integer ID in the URL path, constituting a horizontal privi CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDHireflowTYPVulnerability
8.1
CVSS v3.1
91
Edit Score