<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Oracle JDK</title>
  <link>https://cvedaily.com/pages/tags/oracle-jdk.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oracle-jdk.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Oracle JDK</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:30 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-47065 – ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47065</guid>
    <pubDate>Wed, 03 Jun 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-47065</strong></p>
  <p>ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy   Assessment: Fully addressed.   When the serialised stream contains a TC_PROXYCLASSDESC (the marker  for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc()  is dispatched. JDK then calls the default  ObjectInputStream.resolveProxyClass(interfaces) implementation, which  perfor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35482 – alf.io is an open source ticket reservation system for conferences, trade shows,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35482</guid>
    <pubDate>Tue, 02 Jun 2026 23:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35482</strong></p>
  <p>alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the server. The extension system is intended to execute restricted JavaScript in a sandboxed Rhino environm…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64390 – A privilege escalation vulnerability exists in PlayStation 4 firmware versions 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64390</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64390</strong></p>
  <p>A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be escaped through a malformed JAR file.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45683 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45683</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45683</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can therefore point OBI at kernel memory and cause that memory to be copied into telemetry. This issue has been patched in versio…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-127</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45682 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45682</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45682</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap me…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10567 – A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10567</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10567</strong></p>
  <p>A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10550 – A weakness has been identified in elunez eladmin up to 2.7. This vulnerability a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10550</guid>
    <pubDate>Tue, 02 Jun 2026 02:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10550</strong></p>
  <p>A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manipulation of the argument uploadPath causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10529 – A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10529</guid>
    <pubDate>Tue, 02 Jun 2026 02:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10529</strong></p>
  <p>A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/module/web/system/ScheduleJobController.java of the component Task Scheduling Management Module. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10514 – A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10514</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10514</strong></p>
  <p>A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.0 mitigates this issue. Th…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-28586 – In multiple functions of AppOpsService.java, there is a possible missing permiss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28586</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-28586</strong></p>
  <p>In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28581 – In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28581</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28581</strong></p>
  <p>In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local  with null execution privileges needed. User interaction is null for exploitation.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28578 – In multiple functions of DevicePolicyManagerService.java, there is a possible de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28578</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28578</strong></p>
  <p>In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28577 – In addWindow of WindowManagerService.java, there is a possible tapjacking issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28577</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28577</strong></p>
  <p>In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0099 – In onNullBinding of HostEmulationManager.java, there is a possible way to launch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0099</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0099</strong></p>
  <p>In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-273</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0098 – In getCallingPackageName of Shared.java, there is a possible way to bypass activ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0098</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0098</strong></p>
  <p>In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0096 – In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0096</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0096</strong></p>
  <p>In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0094 – In getApplicationLabel of KeyChainActivity.java, there is a possible way to tric...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0094</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0094</strong></p>
  <p>In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0089 – In multiple functions of PackageInstallerService.java, there is a possible way t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0089</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0089</strong></p>
  <p>In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0088 – In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0088</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0088</strong></p>
  <p>In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0087 – In approvalLevelForDomainInternal of DomainVerificationService.java, there is a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0087</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0087</strong></p>
  <p>In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0085 – In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0085</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0085</strong></p>
  <p>In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0078 – In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0078</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0078</strong></p>
  <p>In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0077 – In resumeConfigurationDispatch of ActivityRecord.java, there is a possible backg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0077</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0077</strong></p>
  <p>In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0070 – In multiple functions of DevicePolicyManagerService.java, there is a possible wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0070</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0070</strong></p>
  <p>In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0069 – In verifySignature of ApkChecksums.java, there is a possible way to cause a cras...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0069</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0069</strong></p>
  <p>In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0061 – In multiple functions of WindowState.java, there is a possible way to trick a us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0061</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0061</strong></p>
  <p>In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0060 – In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0060</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0060</strong></p>
  <p>In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0055 – In createSessionInternal of PackageInstallerService.java, there is a possible to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0055</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0055</strong></p>
  <p>In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0050 – In handleBondStateChanged of AdapterService.java, there is a possible sensitive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0050</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0050</strong></p>
  <p>In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0048 – In hide of WindowState.java, there is a possible way to trick the user into appr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0048</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0048</strong></p>
  <p>In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0046 – In InputInterceptor of Letterbox.java, there is a possible way to trick a user i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0046</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0046</strong></p>
  <p>In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0036 – In startAnimation of StageCoordinator.java, there is a possible tapjacking issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0036</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0036</strong></p>
  <p>In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0018 – In multiple functions of AccessibilityManagerService.java, there is a possible p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0018</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0018</strong></p>
  <p>In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0016 – In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0016</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0016</strong></p>
  <p>In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48648 – In isSameApp of NotificationManagerService.java, there is a possible persistent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48648</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48648</strong></p>
  <p>In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-48616 – In multiple functions of KeyguardViewMediator.java , there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48616</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-48616</strong></p>
  <p>In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48570 – In multiple functions of PipTaskOrganizer.java, there is a possible way to launc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48570</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48570</strong></p>
  <p>In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26418 – In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a poss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26418</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26418</strong></p>
  <p>In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22426 – In many functions of ComputerEngine.java, there is a possible way to access URIs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22426</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22426</strong></p>
  <p>In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10204 – A weakness has been identified in OFCMS 1.1.3. The affected element is the funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10204</guid>
    <pubDate>Mon, 01 Jun 2026 00:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10204</strong></p>
  <p>A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The projec…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10203 – A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Que...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10203</guid>
    <pubDate>Mon, 01 Jun 2026 00:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10203</strong></p>
  <p>A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemParamController.java of the component JSON Query Interface. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was inf…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10202 – A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Q...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10202</guid>
    <pubDate>Mon, 01 Jun 2026 00:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10202</strong></p>
  <p>A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10193 – A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10193</guid>
    <pubDate>Sun, 31 May 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10193</strong></p>
  <p>A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10153 – A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c355...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10153</guid>
    <pubDate>Sat, 30 May 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10153</strong></p>
  <p>A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release app…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10152 – A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10152</guid>
    <pubDate>Sat, 30 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10152</strong></p>
  <p>A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45292 – opentelemetry-java is the Java implementation of the OpenTelemetry API for recor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45292</guid>
    <pubDate>Thu, 28 May 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45292</strong></p>
  <p>opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is au…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9828 – Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9828</guid>
    <pubDate>Thu, 28 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9828</strong></p>
  <p>Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.  More precisely, an attacker able to influence serialized data sent to  SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from  classes in the java.lang and java.util packages that are not explic…</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37579 – An issue in SMSGate sms-core&lt;=2.1.13.6 allows a remote attacker to execute arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37579</guid>
    <pubDate>Thu, 28 May 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37579</strong></p>
  <p>An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9801 – A flaw was found in Keycloak. A remote attacker with high privileges, such as a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9801</guid>
    <pubDate>Thu, 28 May 2026 06:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9801</strong></p>
  <p>A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryEr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-38808 – SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38808</guid>
    <pubDate>Wed, 27 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-38808</strong></p>
  <p>SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38807 – Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38807</guid>
    <pubDate>Wed, 27 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38807</strong></p>
  <p>Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38945 – Command injection in Raynet rvia version 12.6 Update 8 and previous versions all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38945</guid>
    <pubDate>Wed, 27 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38945</strong></p>
  <p>Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45574 – epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45574</guid>
    <pubDate>Tue, 26 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45574</strong></p>
  <p>epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44900 – epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44900</guid>
    <pubDate>Tue, 26 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44900</strong></p>
  <p>epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in  SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm setup, but never checks whether the signature actually m…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47672 – epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47672</guid>
    <pubDate>Tue, 26 May 2026 21:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47672</strong></p>
  <p>epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45575 – epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45575</guid>
    <pubDate>Tue, 26 May 2026 21:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45575</strong></p>
  <p>epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge respo…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42785 – OpenKM 6.3.12 contains a remote code execution vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42785</guid>
    <pubDate>Tue, 26 May 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42785</strong></p>
  <p>OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9370 – A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9370</guid>
    <pubDate>Sun, 24 May 2026 10:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9370</strong></p>
  <p>A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The a…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-759</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6009 – Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6009</guid>
    <pubDate>Tue, 19 May 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6009</strong></p>
  <p>Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7504 – A flaw was found in Keycloak's URL validation logic during redirect operations. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7504</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7504</strong></p>
  <p>A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability specifically affects Keycloak clients configured with a wildcard (*) in the "Va…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8773 – A security vulnerability has been detected in linlinjava litemall up to 1.8.0. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8773</guid>
    <pubDate>Mon, 18 May 2026 00:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8773</strong></p>
  <p>A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to argument injection. The attack is possible to be carried out remotely. The exploit…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8771 – A security flaw has been discovered in linlinjava litemall up to 1.8.0. This imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8771</guid>
    <pubDate>Mon, 18 May 2026 00:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8771</strong></p>
  <p>A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used fo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8759 – A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8759</guid>
    <pubDate>Sun, 17 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8759</strong></p>
  <p>A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special elements used in an expression language statement. Remote exploitation of the attack is possible. Th…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8752 – A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8752</guid>
    <pubDate>Sun, 17 May 2026 12:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8752</strong></p>
  <p>A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to improper access controls. The attack may be performed from remote. The exploit has been made available to the public and…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8751 – A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8751</guid>
    <pubDate>Sun, 17 May 2026 12:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8751</strong></p>
  <p>A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early abo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8750 – A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8750</guid>
    <pubDate>Sun, 17 May 2026 11:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8750</strong></p>
  <p>A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosur…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8740 – A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8740</guid>
    <pubDate>Sun, 17 May 2026 09:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8740</strong></p>
  <p>A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes improper neutralization of special elements used in a template engine. The attack is possible to be…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-791</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8739 – A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected eleme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8739</guid>
    <pubDate>Sun, 17 May 2026 08:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8739</strong></p>
  <p>A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptographic key . The attack can be executed remotely. The exploit is now public and may be used. The ve…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8738 – A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8738</guid>
    <pubDate>Sun, 17 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8738</strong></p>
  <p>A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component Trade Payment Flow. The manipulation leads to business logic errors. Remote exploitation of the at…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-840</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8737 – A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8737</guid>
    <pubDate>Sun, 17 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8737</strong></p>
  <p>A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument userId/id can lead to missing authentication. The attack may be launched remotely. The exploit has…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8736 – A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8736</guid>
    <pubDate>Sun, 17 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8736</strong></p>
  <p>A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Performing a manipulation of the argument uniqueFileName results in path traversal. The attack may be carried out on the physical device. The exploit has been released to the public and may be used for atta…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8735 – A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8735</guid>
    <pubDate>Sun, 17 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8735</strong></p>
  <p>A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8724 – A security flaw has been discovered in Dataease 2.10.20. Impacted is the functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8724</guid>
    <pubDate>Sun, 17 May 2026 02:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8724</strong></p>
  <p>A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44714 – The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44714</guid>
    <pubDate>Fri, 15 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44714</strong></p>
  <p>The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends() contains two fast-path verification bugs for standard P2PKH and native P2WPKH spends in core/src/main/java/org/bitcoinj/script/ScriptExecution.java. In both branches, bitcoinj verifies an attacker-controlled signature/public-key pair but fails to verify that the public key is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41258 – OpenMRS is an open source electronic medical record system platform. From 2.7.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41258</guid>
    <pubDate>Fri, 15 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41258</strong></p>
  <p>OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The VelocityEngine is initialized with only logging properties and noSecureUberspector, leaving the default Ub…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35194 – Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35194</guid>
    <pubDate>Fri, 15 May 2026 16:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35194</strong></p>
  <p>Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Jav…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42555 – Valtimo is an open-source business process automation platform. com.ritense.valt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42555</guid>
    <pubDate>Thu, 14 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42555</strong></p>
  <p>Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions from user-supplied input using StandardEvaluationContext, which provides unrestricted access to Java…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44503 – The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:micr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44503</guid>
    <pubDate>Thu, 14 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44503</strong></p>
  <p>The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44501 – DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub front...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44501</guid>
    <pubDate>Thu, 14 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44501</strong></p>
  <p>DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data vulnerability (CWE-502) affecting the GET /callback/oidc endpoint. Successful ex…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46419 – Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46419</guid>
    <pubDate>Thu, 14 May 2026 02:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46419</strong></p>
  <p>Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-253</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37430 – An arbitrary file upload vulnerability in the ShopOrderImportController.java com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37430</guid>
    <pubDate>Wed, 13 May 2026 14:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37430</strong></p>
  <p>An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41901 – Thymeleaf is a server-side Java template engine for web and standalone environme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41901</guid>
    <pubDate>Tue, 12 May 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41901</strong></p>
  <p>Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constr…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44242 – Micronaut Framework is a JVM-based full stack Java framework designed for buildi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44242</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44242</strong></p>
  <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a ResourceBundleMessageSource bean and serve HTML error responses, an unauthenticated attacker can ex…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44241 – Micronaut Framework is a JVM-based full stack Java framework designed for buildi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44241</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44241</strong></p>
  <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33117 – The Java Key Vault Keys library in the Azure SDK for Java contains an issue in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33117</guid>
    <pubDate>Tue, 12 May 2026 18:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33117</strong></p>
  <p>The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected.…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45091 – sealed-env is a cross-stack, zero-trust secret management library for Node.js an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45091</guid>
    <pubDate>Tue, 12 May 2026 14:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45091</strong></p>
  <p>sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps,…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-42188 – Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Editio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42188</guid>
    <pubDate>Mon, 11 May 2026 22:22:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-42188</strong></p>
  <p>Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head texture data. By supplying a crafted Base64-encoded skin texture URL via the /give command, an attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to attacker-controlled or…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8320 – A security vulnerability has been detected in jishenghua jshERP up to 3.6. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8320</guid>
    <pubDate>Mon, 11 May 2026 20:25:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8320</strong></p>
  <p>A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of the component updatePlatformConfigByKey Endpoint. Such manipulation of the argument weixinUrl leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8216 – A vulnerability was identified in Industrial Application Software IAS Canias ERP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8216</guid>
    <pubDate>Sun, 10 May 2026 01:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8216</strong></p>
  <p>A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Java RMI Session Management. Such manipulation leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8211 – A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8211</guid>
    <pubDate>Sat, 09 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8211</strong></p>
  <p>A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java of the component JSP File Handler. The manipulation of the argument content results in code injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early a…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8196 – A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8196</guid>
    <pubDate>Sat, 09 May 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8196</strong></p>
  <p>A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the component mLogin Endpoint. This manipulation causes authorization bypass. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploit…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8195 – A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8195</guid>
    <pubDate>Sat, 09 May 2026 20:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8195</strong></p>
  <p>A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java of the component SVG File Handler. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8127 – A vulnerability has been found in eladmin up to 2.7. Impacted is the function ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8127</guid>
    <pubDate>Fri, 08 May 2026 03:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8127</strong></p>
  <p>A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users API Endpoint. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not r…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41586 – Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framew...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41586</guid>
    <pubDate>Thu, 07 May 2026 06:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41586</strong></p>
  <p>Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39852 – Quarkus is a Java framework for building cloud-native applications. In versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39852</guid>
    <pubDate>Tue, 05 May 2026 21:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39852</strong></p>
  <p>Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Quarkus's security layer performs authorization checks on the raw U…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7412 – In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Opera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7412</guid>
    <pubDate>Tue, 05 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7412</strong></p>
  <p>In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or external targets. This allows an attacker to bypass network segmentation and pivot…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7411 – In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7411</guid>
    <pubDate>Tue, 05 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7411</strong></p>
  <p>In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host file…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-54342 – Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54342</guid>
    <pubDate>Tue, 05 May 2026 12:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-54342</strong></p>
  <p>Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7710 – A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7710</guid>
    <pubDate>Mon, 04 May 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7710</strong></p>
  <p>A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7699 – A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7699</guid>
    <pubDate>Sun, 03 May 2026 15:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7699</strong></p>
  <p>A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argument filtersfields results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early a…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7699">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
