<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Information Disclosure (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/info-leak.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/info-leak-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Information Disclosure (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-24237 – NVIDIA NVTabular contains a vulnerability where an attacker could cause improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24237</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24237</strong></p>
  <p>NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24221 – NVIDIA NVTabular contains a vulnerability where an attacker could cause improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24221</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24221</strong></p>
  <p>NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10118 – A flaw was found in Poppler's Splash backend. A remote attacker could exploit th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10118</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10118</strong></p>
  <p>A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9051 – There is an authentication bypass vulnerability in the NI SystemLink Enterprise ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9051</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9051</strong></p>
  <p>There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  Successful exploitation requires an attacker to send a specially crafted HTTP request.  This vulnerability affects NI SystemLink Enterprise 2026-04 and p…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45044 – RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45044</guid>
    <pubDate>Thu, 28 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45044</strong></p>
  <p>RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e.g., glibc), the handler invokes a fixed 60-second CPU profiling operation (dump_cpu_pprof_for(Dura…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9804 – A flaw was found in KubeVirt's virt-exportserver component. An attacker with spe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9804</guid>
    <pubDate>Thu, 28 May 2026 09:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9804</strong></p>
  <p>A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's files…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5260 – A flaw was found in libgnutls. A remote attacker, by sending an extremely short ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5260</guid>
    <pubDate>Tue, 26 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5260</strong></p>
  <p>A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3603 – IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3603</guid>
    <pubDate>Tue, 26 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3603</strong></p>
  <p>IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8835 – IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8835</guid>
    <pubDate>Tue, 26 May 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8835</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24200 – NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24200</guid>
    <pubDate>Tue, 26 May 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24200</strong></p>
  <p>NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24196 – NVIDIA Display Driver for Linux contains a vulnerability where a user could caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24196</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24196</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24194 – NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24194</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24194</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24193 – NVIDIA Display Driver for Windows and Linux contains a vulnerability where an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24193</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24193</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24192 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24192</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24192</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24191 – NVIDIA Display Driver for Windows contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24191</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24191</strong></p>
  <p>NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24190 – NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24190</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24190</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24187 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24187</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24187</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48864 – A flaw was found in libsolv. This heap buffer overflow occurs during the decompr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48864</guid>
    <pubDate>Tue, 26 May 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48864</strong></p>
  <p>A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of progr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24212 – NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24212</guid>
    <pubDate>Tue, 26 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24212</strong></p>
  <p>NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24162 – NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24162</guid>
    <pubDate>Tue, 26 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24162</strong></p>
  <p>NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48843 – Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48843</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48843</strong></p>
  <p>Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9284 – The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9284</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9284</strong></p>
  <p>The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order o…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6895 – The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6895</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6895</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39850 – Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39850</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39850</strong></p>
  <p>Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled _file_ key in the $params array overwrites the internal local variable specifyin…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24218 – NVIDIA DGX OS contains a vulnerability in the factory provisioning process, wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24218</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24218</strong></p>
  <p>NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where  the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution,…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24217 – NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24217</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24217</strong></p>
  <p>NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24216 – NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a des...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24216</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24216</strong></p>
  <p>NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32750 – Dell PowerFlex Manager, version(s) &lt;=4.6.2, contain(s) an Exposure of Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32750</guid>
    <pubDate>Wed, 20 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32750</strong></p>
  <p>Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-548</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24213 – NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24213</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24213</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24207 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24207</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24207</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24206 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24206</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24206</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24163 – NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24163</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24163</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could  cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33255 – NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33255</guid>
    <pubDate>Wed, 20 May 2026 04:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33255</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8967 – Information disclosure in the Graphics: WebGPU component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8967</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8967</strong></p>
  <p>Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8966 – Information disclosure in the IP Protection component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8966</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8966</strong></p>
  <p>Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8965 – Information disclosure in the DOM: Security component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8965</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8965</strong></p>
  <p>Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8958 – Information disclosure, sandbox escape in the Security: Process Sandboxing compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8958</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8958</strong></p>
  <p>Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7571 – A flaw was found in Keycloak. A low-privilege user, with knowledge of user crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7571</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7571</strong></p>
  <p>A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29962 – HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29962</guid>
    <pubDate>Mon, 18 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29962</strong></p>
  <p>HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arb…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46366 – phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46366</guid>
    <pubDate>Fri, 15 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46366</strong></p>
  <p>phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially iterate solution IDs to discover all FAQs including those restricted to specific users or groups,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28761 – Cross-site request forgery vulnerability exists in Musetheque V4 Information Dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28761</guid>
    <pubDate>Fri, 15 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28761</strong></p>
  <p>Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4031 – The Database Backup for WordPress plugin for WordPress is vulnerable to authoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4031</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4031</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attackers to send a request to wp-cron.php with a poisoned wp_db_temp_dir value point…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4030 – The Database Backup for WordPress plugin for WordPress is vulnerable to unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4030</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4030</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4029 – The Database Backup for WordPress plugin for WordPress is vulnerable to unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4029</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4029</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables, leading to Sensitive Information Exposure. Note: This vulnerability is only exp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44377 – CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44377</guid>
    <pubDate>Wed, 13 May 2026 21:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44377</strong></p>
  <p>CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty template engine. By leveraging this, an authenticated attacker with administrative privileges can bypass…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26289 – PowerSYSTEM Center REST API endpoint for device account export allows an authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26289</guid>
    <pubDate>Tue, 12 May 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26289</strong></p>
  <p>PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8043 – External control of a file name in Ivanti Xtraction before version 2026.2 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8043</guid>
    <pubDate>Tue, 12 May 2026 15:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8043</strong></p>
  <p>External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6104 – In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6104</guid>
    <pubDate>Sun, 10 May 2026 06:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6104</strong></p>
  <p>In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or cr…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7261 – In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7261</guid>
    <pubDate>Sun, 10 May 2026 05:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7261</strong></p>
  <p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which m…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7821 – Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7821</guid>
    <pubDate>Thu, 07 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7821</strong></p>
  <p>Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-54346 – WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54346</guid>
    <pubDate>Tue, 05 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-54346</strong></p>
  <p>WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then construct direct download URLs to retrieve sensitive backup archives containing full database dumps.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41471 – The Easy PayPal Events &amp; Tickets plugin for WordPress before version 1.4 contain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41471</guid>
    <pubDate>Mon, 04 May 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41471</strong></p>
  <p>The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to enumerate and retrieve all customer order records. Attackers can iterate over sequential WordPress post IDs through the scan_qr.php endpoint to harvest the complete set of orders stored in the database w…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42476 – Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42476</guid>
    <pubDate>Fri, 01 May 2026 15:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42476</strong></p>
  <p>Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 exist in RWStl_Reader::ReadAscii because buffers returned by Standard_ReadLineBuffer::ReadLine() are not properly length-validated before strncasecmp or direct byte access. User-assisted attackers can trigger these issues by persuading a victim to open a crafted STL file wit…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33845 – A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33845</guid>
    <pubDate>Thu, 30 Apr 2026 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33845</strong></p>
  <p>A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14576 – Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaSc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14576</guid>
    <pubDate>Thu, 30 Apr 2026 13:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14576</strong></p>
  <p>Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data a…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24222 – NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initializati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24222</guid>
    <pubDate>Tue, 28 Apr 2026 19:36:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24222</strong></p>
  <p>NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24178 – NVIDIA NVFlare Dashboard contains a vulnerability in the user management and aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24178</guid>
    <pubDate>Tue, 28 Apr 2026 19:36:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24178</strong></p>
  <p>NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7320 – Information disclosure due to incorrect boundary conditions in the Audio/Video c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7320</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7320</strong></p>
  <p>Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41475 – BACnet Stack is a BACnet open source protocol stack C library for embedded syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41475</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41475</strong></p>
  <p>BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM request. The vulnerability stems from wpm_decode_object_property() calling the deprecated decode_ta…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41266 – Flowise is a drag &amp; drop user interface to build a customized large language mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41266</guid>
    <pubDate>Thu, 23 Apr 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41266</strong></p>
  <p>Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID can retrieve credentials stored in password type fields and HTTP headers, leading…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24189 – NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24189</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24189</strong></p>
  <p>NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24177 – NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24177</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24177</strong></p>
  <p>NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6782 – Information disclosure in the IP Protection component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6782</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6782</strong></p>
  <p>Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6749 – Information disclosure due to uninitialized memory in the Graphics: Canvas2D com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6749</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6749</strong></p>
  <p>Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2262 – The Easy Appointments plugin for WordPress is vulnerable to Sensitive Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2262</guid>
    <pubDate>Sat, 18 Apr 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2262</strong></p>
  <p>The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`, which allows access without any authentication or authorization checks. This makes it possible for…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5720 – miniupnpd contains an integer underflow vulnerability in SOAPAction header parsi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5720</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5720</strong></p>
  <p>miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40245 – Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40245</guid>
    <pubDate>Thu, 16 Apr 2026 00:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40245</strong></p>
  <p>Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disclosure vulnerability in the UDR (Unified Data Repository) service. The handler for GET /nudr-dr/v2/application-data/influenceData/subs-to-notify sends an HTTP 400 error response when required query parameters are missing but does not return afterward…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33023 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33023</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33023</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its internal buffers without consulting the reference count, even though the object was created via the ref…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33019 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33019</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33019</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative val…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5936 – An attacker can control a server-side HTTP request by supplying a crafted URL, c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5936</guid>
    <pubDate>Mon, 13 Apr 2026 07:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5936</strong></p>
  <p>An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4155 – ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Informat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4155</guid>
    <pubDate>Sat, 11 Apr 2026 01:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4155</strong></p>
  <p>ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the genpw script. The issue results from the in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-540</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33461 – Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33461</guid>
    <pubDate>Wed, 08 Apr 2026 17:21:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33461</strong></p>
  <p>Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API endpoint to retrieve sensitive configuration data, including private keys and authentication tokens, that should only be accessible to users with higher-level settings privileges. The endpoint composes its response by fetc…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31017 – A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31017</guid>
    <pubDate>Wed, 08 Apr 2026 17:21:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31017</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion of HTML elements such as <iframe> that reference external resources. The PDF ren…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28386 – Issue summary: Applications using AES-CFB128 encryption or decryption on
systems...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28386</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28386</strong></p>
  <p>Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmappe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32864 – There is a memory corruption vulnerability due to an out-of-bounds read in mgcor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32864</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32864</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32863 – There is a memory corruption vulnerability due to an out-of-bounds read in sentr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32863</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32863</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32862 – There is a memory corruption vulnerability due to an out-of-bounds write in ResF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32862</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32862</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32861 – There is a memory corruption vulnerability due to an out-of-bounds write when lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32861</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32861</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvclass file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32860 – There is a memory corruption vulnerability due to an out-of-bounds write when lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32860</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32860</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvlib file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5627 – A path traversal vulnerability exists in mintplex-labs/anything-llm versions up ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5627</guid>
    <pubDate>Tue, 07 Apr 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5627</strong></p>
  <p>A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper handling of user input in the `loadFlow` and `deleteFlow` methods in `server/utils/agentFlows/index.js`. Specifically, the combination of `path.join` and `normalizePath` allows attackers to bypass directory restrictions a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35185 – HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35185</guid>
    <pubDate>Mon, 06 Apr 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35185</strong></p>
  <p>HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1233 – The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1233</guid>
    <pubDate>Sat, 04 Apr 2026 12:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1233</strong></p>
  <p>The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry` class. This makes it possible for unauthenticated attackers to extract and deco…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-10148 – Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-10148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-10148</guid>
    <pubDate>Fri, 03 Apr 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-10148</strong></p>
  <p>Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-in-the-middle attacks, impersonate devices, and expose sensitive information by leveraging the share…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-10148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34785 – Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34785</guid>
    <pubDate>Thu, 02 Apr 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34785</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, fi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-187</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3872 – A flaw was found in Keycloak. This issue allows an attacker, who controls anothe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3872</guid>
    <pubDate>Thu, 02 Apr 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3872</strong></p>
  <p>A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5032 – The W3 Total Cache plugin for WordPress is vulnerable to information exposure in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5032</guid>
    <pubDate>Thu, 02 Apr 2026 08:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5032</strong></p>
  <p>The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic fragment HTML comments — including the W3TC_DYNAMIC_SECURITY security token — to be re…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32929 – V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32929</guid>
    <pubDate>Wed, 01 Apr 2026 23:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32929</strong></p>
  <p>V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32927 – V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32927</guid>
    <pubDate>Wed, 01 Apr 2026 23:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32927</strong></p>
  <p>V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32926 – V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32926</guid>
    <pubDate>Wed, 01 Apr 2026 23:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32926</strong></p>
  <p>V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34543 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34543</guid>
    <pubDate>Wed, 01 Apr 2026 21:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34543</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30292 – An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30292</guid>
    <pubDate>Wed, 01 Apr 2026 15:22:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30292</strong></p>
  <p>An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30291 – An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader &amp; Edi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30291</guid>
    <pubDate>Wed, 01 Apr 2026 15:22:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30291</strong></p>
  <p>An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30289 – An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30289</guid>
    <pubDate>Wed, 01 Apr 2026 14:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30289</strong></p>
  <p>An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30287 – An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30287</guid>
    <pubDate>Wed, 01 Apr 2026 14:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30287</strong></p>
  <p>An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30290 – An arbitrary file overwrite vulnerability in InTouch Contacts &amp; Caller ID APP v6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30290</guid>
    <pubDate>Tue, 31 Mar 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30290</strong></p>
  <p>An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30285 – An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30285</guid>
    <pubDate>Tue, 31 Mar 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30285</strong></p>
  <p>An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30286 – An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30286</guid>
    <pubDate>Tue, 31 Mar 2026 18:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30286</strong></p>
  <p>An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30283 – An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30283</guid>
    <pubDate>Tue, 31 Mar 2026 18:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30283</strong></p>
  <p>An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30282 – An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30282</guid>
    <pubDate>Tue, 31 Mar 2026 18:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30282</strong></p>
  <p>An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30279 – An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30279</guid>
    <pubDate>Tue, 31 Mar 2026 18:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30279</strong></p>
  <p>An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30279">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
