<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Information Disclosure</title>
  <link>https://cvedaily.com/pages/tags/info-leak.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/info-leak.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Information Disclosure</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-26825 – A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26825</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-26825</strong></p>
  <p>A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-26824 – libxls through version 1.6.3 contains a use of uninitialized memory vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26824</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-26824</strong></p>
  <p>libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application crashes or potential information disclosure when processing a crafted XLS file</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-50052 – In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-50052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50052</guid>
    <pubDate>Wed, 03 Jun 2026 06:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-50052</strong></p>
  <p>In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40713 – Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40713</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40713</strong></p>
  <p>Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24237 – NVIDIA NVTabular contains a vulnerability where an attacker could cause improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24237</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24237</strong></p>
  <p>NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24221 – NVIDIA NVTabular contains a vulnerability where an attacker could cause improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24221</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24221</strong></p>
  <p>NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25717 – Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an informati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25717</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25717</strong></p>
  <p>Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3198 – MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3198</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3198</strong></p>
  <p>MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGatewayEndpoints`, and `ListGatewayModelDefinitions`. This allows any authenticated user, regardless of their as…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9048 – The Slider Revolution plugin for WordPress is vulnerable to Sensitive Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9048</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9048</strong></p>
  <p>The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59609 – Information Disclosure when processing advertisement frames with malformed MBSSI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59609</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59609</strong></p>
  <p>Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59601 – Information Disclosure when resetting device to factory default settings through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59601</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59601</strong></p>
  <p>Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-28586 – In multiple functions of AppOpsService.java, there is a possible missing permiss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28586</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-28586</strong></p>
  <p>In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0056 – In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0056</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0056</strong></p>
  <p>In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0050 – In handleBondStateChanged of AdapterService.java, there is a possible sensitive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0050</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0050</strong></p>
  <p>In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0016 – In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0016</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0016</strong></p>
  <p>In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-48616 – In multiple functions of KeyguardViewMediator.java , there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48616</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-48616</strong></p>
  <p>In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5419 – A flaw was found in gnutls. The PKCS#7 padding check, performed during decryptio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5419</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5419</strong></p>
  <p>A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10118 – A flaw was found in Poppler's Splash backend. A remote attacker could exploit th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10118</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10118</strong></p>
  <p>A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10254 – A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10254</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10254</strong></p>
  <p>A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9051 – There is an authentication bypass vulnerability in the NI SystemLink Enterprise ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9051</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9051</strong></p>
  <p>There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  Successful exploitation requires an attacker to send a specially crafted HTTP request.  This vulnerability affects NI SystemLink Enterprise 2026-04 and p…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-49370 – In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49370</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-49370</strong></p>
  <p>In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49369 – In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49369</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49369</strong></p>
  <p>In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10078 – A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10078</guid>
    <pubDate>Fri, 29 May 2026 11:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10078</strong></p>
  <p>A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to the GitLab endpoint. This insecure transmission can lead to the disclosure of these credentials in various system logs, such as server access logs, reverse proxy…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-598</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8995 – The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8995</guid>
    <pubDate>Fri, 29 May 2026 04:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8995</strong></p>
  <p>The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This is due to insufficient access controls on the 'ays_poll_get_user_information' AJAX action, which serializes and returns the complete WP_User object — including the user_pass (bcrypt password hash), user_email, user_login, user…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33463 – Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33463</guid>
    <pubDate>Thu, 28 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33463</strong></p>
  <p>Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enabling an unauthenticated actor in possession of the token to retrieve the associated content after expiration.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-672</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47332 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47332</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47332</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45044 – RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45044</guid>
    <pubDate>Thu, 28 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45044</strong></p>
  <p>RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e.g., glibc), the handler invokes a fixed 60-second CPU profiling operation (dump_cpu_pprof_for(Dura…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9804 – A flaw was found in KubeVirt's virt-exportserver component. An attacker with spe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9804</guid>
    <pubDate>Thu, 28 May 2026 09:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9804</strong></p>
  <p>A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's files…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7526 – The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7526</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7526</strong></p>
  <p>The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-on is also installed and has saved a key; on Lite-only installatio…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9802 – A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9802</guid>
    <pubDate>Thu, 28 May 2026 06:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9802</strong></p>
  <p>A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim's account, potenti…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9794 – A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9794</guid>
    <pubDate>Thu, 28 May 2026 05:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9794</strong></p>
  <p>A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9792 – A flaw was found in Keycloak's Client Policies, specifically within the `org.key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9792</guid>
    <pubDate>Thu, 28 May 2026 05:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9792</strong></p>
  <p>A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42878 – FacturaScripts is an open source accounting and invoicing software. Prior to v20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42878</guid>
    <pubDate>Wed, 27 May 2026 19:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42878</strong></p>
  <p>FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information disclosure vulnerability in the Installer controller allows any remote attacker to trigger phpinfo() on a fresh FacturaScripts deployment by requesting /?phpinfo=TRUE, exposing full PHP configuration, server environment variables (including any database credentials, API keys, or appl…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68712 – SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68712</guid>
    <pubDate>Wed, 27 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68712</strong></p>
  <p>SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating cascading interface flows - insecure navigation through exposed routes facilitat…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5260 – A flaw was found in libgnutls. A remote attacker, by sending an extremely short ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5260</guid>
    <pubDate>Tue, 26 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5260</strong></p>
  <p>A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9583 – A weakness has been identified in SourceCodester CET Automated Grading System wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9583</guid>
    <pubDate>Tue, 26 May 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9583</strong></p>
  <p>A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68711 – AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68711</guid>
    <pubDate>Tue, 26 May 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68711</strong></p>
  <p>AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E]…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68708 – SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68708</guid>
    <pubDate>Tue, 26 May 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68708</strong></p>
  <p>SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intent…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68710 – Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68710</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68710</strong></p>
  <p>Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3603 – IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3603</guid>
    <pubDate>Tue, 26 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3603</strong></p>
  <p>IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8835 – IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8835</guid>
    <pubDate>Tue, 26 May 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8835</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24201 – NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24201</guid>
    <pubDate>Tue, 26 May 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24201</strong></p>
  <p>NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24200 – NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24200</guid>
    <pubDate>Tue, 26 May 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24200</strong></p>
  <p>NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24198 – NVIDIA GPU Display Driver for Linux  contains a vulnerability where an advanced ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24198</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24198</strong></p>
  <p>NVIDIA GPU Display Driver for Linux  contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24196 – NVIDIA Display Driver for Linux contains a vulnerability where a user could caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24196</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24196</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24194 – NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24194</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24194</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24193 – NVIDIA Display Driver for Windows and Linux contains a vulnerability where an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24193</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24193</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24192 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24192</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24192</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24191 – NVIDIA Display Driver for Windows contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24191</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24191</strong></p>
  <p>NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24190 – NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24190</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24190</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24187 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24187</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24187</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48864 – A flaw was found in libsolv. This heap buffer overflow occurs during the decompr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48864</guid>
    <pubDate>Tue, 26 May 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48864</strong></p>
  <p>A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of progr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24212 – NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24212</guid>
    <pubDate>Tue, 26 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24212</strong></p>
  <p>NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24162 – NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24162</guid>
    <pubDate>Tue, 26 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24162</strong></p>
  <p>NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48846 – In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote imag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48846</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48846</strong></p>
  <p>In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48845 – In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48845</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48845</strong></p>
  <p>In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48843 – Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48843</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48843</strong></p>
  <p>Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9352 – A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9352</guid>
    <pubDate>Sun, 24 May 2026 05:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9352</strong></p>
  <p>A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of the component Messaging Gateway Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor wa…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9349 – A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9349</guid>
    <pubDate>Sun, 24 May 2026 04:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9349</strong></p>
  <p>A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx of the component Generic React API. This manipulation of the argument cancelledBy/rescheduledBy causes information disclosure. The attack can be initiated remotely. The exploit has been publi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9284 – The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9284</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9284</strong></p>
  <p>The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order o…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6895 – The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6895</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6895</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32749 – Dell PowerFlex Manager, version(s) &lt;=4.6.2, contain(s) an Exposure of Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32749</guid>
    <pubDate>Fri, 22 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32749</strong></p>
  <p>Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7636 – The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7636</guid>
    <pubDate>Fri, 22 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7636</strong></p>
  <p>The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider metadata including unpublished media URLs, captions, and slider configuration author…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44409 – There is an an information disclosure vulnerability in ZTE MU5250. Due to improp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44409</guid>
    <pubDate>Fri, 22 May 2026 05:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44409</strong></p>
  <p>There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2734 – In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2734</guid>
    <pubDate>Thu, 21 May 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2734</strong></p>
  <p>In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all registered models, regardless of their permission level. The issue arises due to the absence of `SearchMode…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40102 – Plane is an open-source project management tool. In versions 1.3.0 and below, Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40102</guid>
    <pubDate>Wed, 20 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40102</strong></p>
  <p>Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-ana…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39850 – Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39850</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39850</strong></p>
  <p>Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled _file_ key in the $params array overwrites the internal local variable specifyin…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24218 – NVIDIA DGX OS contains a vulnerability in the factory provisioning process, wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24218</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24218</strong></p>
  <p>NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where  the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution,…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24217 – NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24217</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24217</strong></p>
  <p>NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24216 – NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a des...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24216</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24216</strong></p>
  <p>NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32750 – Dell PowerFlex Manager, version(s) &lt;=4.6.2, contain(s) an Exposure of Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32750</guid>
    <pubDate>Wed, 20 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32750</strong></p>
  <p>Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-548</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6728 – The Slider Revolution plugin for WordPress is vulnerable to Sensitive Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6728</guid>
    <pubDate>Wed, 20 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6728</strong></p>
  <p>The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5075 – The All in One SEO plugin for WordPress is vulnerable to Sensitive Information E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5075</guid>
    <pubDate>Wed, 20 May 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5075</strong></p>
  <p>The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post editor contexts without effective masking for low-privilege users. This makes it possible for authenticated attackers, with contributor-level ac…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24213 – NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24213</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24213</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24207 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24207</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24207</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24206 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24206</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24206</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24163 – NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24163</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24163</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could  cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24142 – NVIDIA TRT-LLM for any platform contains a deserialization vulnerability   and u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24142</guid>
    <pubDate>Wed, 20 May 2026 04:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24142</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a deserialization vulnerability   and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33255 – NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33255</guid>
    <pubDate>Wed, 20 May 2026 04:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33255</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8967 – Information disclosure in the Graphics: WebGPU component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8967</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8967</strong></p>
  <p>Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8966 – Information disclosure in the IP Protection component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8966</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8966</strong></p>
  <p>Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8965 – Information disclosure in the DOM: Security component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8965</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8965</strong></p>
  <p>Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8958 – Information disclosure, sandbox escape in the Security: Process Sandboxing compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8958</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8958</strong></p>
  <p>Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-40904 – A Stored HTML Injection vulnerability was discovered in the Smart Polling functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40904</guid>
    <pubDate>Tue, 19 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-40904</strong></p>
  <p>A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote strategy in the Smart Polling functionality, the injected HTML renders in their browser, enabling p…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-40903 – A Stored HTML Injection vulnerability was discovered in the Schedule Restore Arc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40903</guid>
    <pubDate>Tue, 19 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-40903</strong></p>
  <p>A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected schedule, the injected HTML renders in their browser, enabling phishing and possibly open redirect att…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-40902 – A Stored HTML Injection vulnerability was discovered in the Users functionality ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40902</guid>
    <pubDate>Tue, 19 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-40902</strong></p>
  <p>A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user, the injected HTML renders in their browser, enabling phishing and possibly open re…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-40901 – A Stored HTML Injection vulnerability was discovered in the Credentials Manager ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40901</guid>
    <pubDate>Tue, 19 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-40901</strong></p>
  <p>A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected identity, the injected HTML renders in their browser, enabling phishing and possibly open redirect att…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-40900 – An Angular template injection vulnerability was discovered in the Reports functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40900</guid>
    <pubDate>Tue, 19 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-40900</strong></p>
  <p>An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious report template. When the victim views or imports the report, the Angular template ex…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-7860 – A possible information disclosure vulnerability exists in the Vaadin Maven plugi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7860</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-7860</strong></p>
  <p>A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build can expose those secrets in clear text in CI logs and archiv…</p>
  <p><strong>CVSS:</strong> 1.6 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7571 – A flaw was found in Keycloak. A low-privilege user, with knowledge of user crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7571</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7571</strong></p>
  <p>A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4630 – A flaw was found in Keycloak. An authenticated client could exploit an Insecure ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4630</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4630</strong></p>
  <p>A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET,…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-37981 – A flaw was found in Keycloak. A broken access control vulnerability in the Accou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37981</guid>
    <pubDate>Tue, 19 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-37981</strong></p>
  <p>A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29962 – HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29962</guid>
    <pubDate>Mon, 18 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29962</strong></p>
  <p>HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arb…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8766 – A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8766</guid>
    <pubDate>Sun, 17 May 2026 23:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8766</strong></p>
  <p>A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was c…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8750 – A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8750</guid>
    <pubDate>Sun, 17 May 2026 11:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8750</strong></p>
  <p>A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosur…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46366 – phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46366</guid>
    <pubDate>Fri, 15 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46366</strong></p>
  <p>phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially iterate solution IDs to discover all FAQs including those restricted to specific users or groups,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41181 – Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41181</guid>
    <pubDate>Fri, 15 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41181</strong></p>
  <p>Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information disclosure vulnerability in Traefik's errors (custom error pages) middleware. When the backend returns a response matching the configured status range, the middleware forwards the original request's complete header set, including Authorization, Cookie, and other authentication mat…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28761 – Cross-site request forgery vulnerability exists in Musetheque V4 Information Dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28761</guid>
    <pubDate>Fri, 15 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28761</strong></p>
  <p>Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24662 – Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24662</guid>
    <pubDate>Fri, 15 May 2026 06:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24662</strong></p>
  <p>Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48520 – An improper input validation vulnerability within the AMD Platform Management Fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48520</guid>
    <pubDate>Fri, 15 May 2026 02:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48520</strong></p>
  <p>An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48520">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
