| CVE-2026-9632 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. | high | 2026-05-27 |
| CVE-2026-9631 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used. | high | 2026-05-27 |
| CVE-2026-9628 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | high | 2026-05-27 |
| CVE-2026-9627 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | high | 2026-05-27 |
| CVE-2026-9609 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | medium | 2026-05-27 |
| CVE-2026-9608 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | medium | 2026-05-27 |
| CVE-2026-9207 | Tanium addressed an unauthorized code execution vulnerability in Connect. | high | 2026-05-27 |
| CVE-2026-9156 | Tanium addressed a denial of service vulnerability in Tanium Server. | medium | 2026-05-27 |
| CVE-2026-7493 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied delay parameter without any rate limiting. This makes it possible for unauthenticated attackers to exhaust PHP worker processes, denying access to the site to legitimate users. | medium | 2026-05-27 |
| CVE-2026-6565 | The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping in an admin attribute context. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | medium | 2026-05-27 |
| CVE-2026-49017 | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0. | high | 2026-05-27 |
| CVE-2026-49014 | In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp. | high | 2026-05-27 |
| CVE-2026-44979 | @hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects | medium | |
| CVE-2026-44974 | @hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters | high | |
| CVE-2026-44741 | Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter | high | |
| CVE-2026-44739 | Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration | high | |
| CVE-2026-44705 | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | high | |
| CVE-2026-44646 | LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` | medium | |
| CVE-2026-9607 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. | medium | 2026-05-27 |
| CVE-2026-9606 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | medium | 2026-05-27 |
| CVE-2026-9605 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue. | medium | 2026-05-27 |
| CVE-2026-9312 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.1. This vulnerability was reported via the GitHub Bug Bounty program. | critical | 2026-05-27 |
| CVE-2026-8606 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the values of sensitive environment variables, including signing secrets and private keys. Exploitation required GitHub Packages to be enabled; on instances not running in private mode the vulnerability was exploitable without authentication, otherwise any authenticated user could exploit it. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21.1 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, 3.17.16, and 3.16.19. This vulnerability was reported via the GitHub Bug Bounty program. | high | 2026-05-27 |
| CVE-2026-44645 | LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body | medium | |
| CVE-2026-44644 | LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS | medium | |
| CVE-2026-44632 | Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` | critical | |
| CVE-2026-44596 | Yamcs has No Rate Limiting on Authentication Endpoint | medium | |
| CVE-2026-44595 | Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints | medium | |
| CVE-2026-44587 | CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters | medium | |
| CVE-2026-44210 | Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations | medium | |
| CVE-2026-44177 | Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup | high | |
| CVE-2026-44176 | Kirby CMS's `pages.access` permission is not checked during rendering of page drafts | medium | |
| CVE-2026-44175 | Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend | high | |
| CVE-2026-44174 | Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints | high | |
| CVE-2026-43947 | FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass | critical | |
| CVE-2026-43946 | FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue | high | |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | critical | |
| CVE-2026-42568 | Yamcs Vulnerable to LDAP Injection in LdapAuthModule | medium | |
| CVE-2026-42462 | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring | high | |
| CVE-2026-9604 | A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded. | medium | 2026-05-26 |
| CVE-2026-8680 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | No Score | 2026-05-26 |
| CVE-2026-8647 | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available. | high | 2026-05-27 |
| CVE-2026-46740 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a separate statsd client. It defaults to using a version of Net::Statsd::Tiny that fixes a similar issue (CVE-2026-46720). | critical | 2026-05-26 |
| CVE-2026-42089 | yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation | high | |
| CVE-2026-41207 | netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures | medium | |
| CVE-2026-9603 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | medium | 2026-05-26 |
| CVE-2026-9584 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | medium | 2026-05-26 |
| CVE-2026-5260 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure. | high | 2026-05-26 |
| CVE-2026-48710 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values. | medium | 2026-05-26 |
| CVE-2026-45574 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2. | high | 2026-05-26 |