Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 4 May 2026
RSS415 vulnerabilities published on 4 May 2026
Severity:
GV-VMS V20 allows an attacker to crash the application and gain control
CVE-2026-42369
The GV-VMS V20 software has a bug that can cause it to crash and potentially be taken over by an attacker if the WebCam Server feature is enabled. This is because the software doesn't properly check t...
10.0
Apache Polaris issues broad temporary storage credentials
CVE-2026-42809
GHSA-8ggj-j522-h5qf
Apache Polaris can create temporary storage credentials that give an attacker too much access to data. This happens when creating a new table before checking where the data will be stored. To fix this...
9.4
Apache Polaris has an Improper Input Validation issue
CVE-2026-42811
GHSA-fc3h-c6h7-r83j
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across t...
9.4
Apache Polaris allows unauthorized access to S3 data
CVE-2026-42810
GHSA-vxgg-mqx2-3w59
Apache Polaris doesn't properly handle certain characters in table names, which can allow an attacker to access data from other tables on Amazon S3. This is a security risk because an attacker could p...
9.4
Apache Iceberg and Polaris metadata files can be written to wrong location
CVE-2026-42812
GHSA-w76p-3cgp-qfcm
Apache Iceberg and Polaris have a security issue where a user with the right permissions can make the system write metadata files to an unintended location. This could lead to incorrect data being loa...
9.4
Comet Backup: Tenant Admin Can Access Other Users' Accounts
CVE-2026-29200
This vulnerability affects all versions of Comet Backup from 20.11.0 to 26.1.1 and 26.2.1. If left unpatched, a malicious admin can access other users' accounts on the same server. Update to the lates...
9.9
GeoVision LPC2011/LPC2211 Web Interface Allows Unauthorized Privilege Escalation
CVE-2026-42368
A hacker can use a specially crafted web request to gain elevated access to the GeoVision LPC2011/LPC2211 system. This could allow them to perform actions they shouldn't be able to do. Update the syst...
9.9
Net-IMAP vulnerable to command injection via raw arguments
GHSA-hm49-wcqc-g2xg
CVE-2026-42257
The Net-IMAP library in certain situations sends user-controlled input directly to the server without checking for malicious code. This allows an attacker to inject and execute arbitrary commands. Aff...
5.8
Net::IMAP vulnerable to command injection via unvalidated inputs
GHSA-75xq-5h9v-w6px
CVE-2026-42258
Net::IMAP, a library for working with email servers, has a security issue that allows attackers to inject malicious commands. This is because the library does not properly validate certain types of in...
5.8
ArchiveBox Exposes Local File Access via Unvalidated Config
GHSA-3h23-7824-pj8r
CVE-2026-42601
A security issue in ArchiveBox allows an attacker to execute arbitrary commands on the system, potentially leading to unauthorized access to local files. This issue affects users who have enabled book...
9.3
Apache OpenNLP: Malicious Model Can Run Arbitrary Code
CVE-2026-42027
GHSA-cx4m-2p55-rw7j
A vulnerability in Apache OpenNLP allows an attacker to run arbitrary code by creating a malicious model archive. This can happen when users load models from untrusted sources, such as community model...
9.8
Arelle before 2.39.10 allows malicious code execution
CVE-2026-42796
An attacker can upload and run their own code on the Arelle server without permission, potentially gaining control of the system. This is a serious issue because it allows unauthorized access and coul...
9.2
Evolver before 1.69.3 allows attackers to run arbitrary server commands
CVE-2026-42076
Evolver, a tool used to create AI agents, is vulnerable to a security issue that allows hackers to execute commands on the server. This could lead to unauthorized access or data theft. Update to versi...
9.8
Apache OpenNLP: Malicious Model Can Run Any Class Code
DEBIAN-CVE-2026-42027
A security issue in older versions of Apache OpenNLP's ExtensionLoader allows an attacker to make any class on the computer run when a specially crafted model is loaded. This could potentially lead to...
9.8
VM2 Sandbox Escape: Host Code Execution
GHSA-grj5-jjm8-h35p
CVE-2026-24118
VM2's sandbox is vulnerable to a breach, allowing malicious code to execute on the host system. This means an attacker could potentially take control of your system. To protect yourself, update to the...
9.8
Assimp FBX Importer allows malicious files to cause crashes
CVE-2025-70067
A vulnerability in Assimp's FBX Importer, used in various 3D modeling software, could allow a malicious FBX file to crash the application. This issue affects Assimp versions up to 6.0.2. To protect yo...
9.8
Rootio Cryptography Package Exposes Data
ROOT-APP-PYPI-CVE-2026-39892
The rootio-cryptography package on Root's PyPI repository had a security weakness that could allow unauthorized access to sensitive data. This has been addressed by Root through a software update. Use...
9.8
Totolink N300RH Router Password Buffer Overflow Risk
CVE-2026-7747
A security flaw in the Totolink N300RH router's password system can be exploited by hackers to gain unauthorized access. This can happen if an attacker sends a malicious password to the router. To pro...
8.9
Tegsoft Online Support App: Malicious Code Injection Risk
CVE-2025-14320
A security flaw in the Tegsoft Online Support Application could allow hackers to inject malicious code into the application, potentially stealing sensitive information or taking control of user sessio...
9.8
Totolink WA300 Router: Remote Code Execution via Buffer Overflow
CVE-2026-7719
A vulnerability in the Totolink WA300 router's login function allows an attacker to potentially execute malicious code remotely, potentially allowing them to take control of the device. This could lea...
8.9
GeoVision GV-VMS V20 20.0.2 WebCam Server Login Allows Untrusted Input
CVE-2026-42370
An attacker can send a specially crafted HTTP request to the GeoVision GV-VMS V20 20.0.2 WebCam Server Login, potentially allowing them to execute malicious code on your system. This can happen withou...
9.8
OpenC3 COSMOS QuestDB Time-Series Database Data Disclosure and Deletion
GHSA-v529-vhwc-wfc5
A security issue exists in the QuestDB database used by OpenC3 COSMOS. If an attacker with certain permissions can exploit this issue, they may be able to access and delete sensitive telemetry data. T...
9.6
OpenC3 COSMOS SQL Injection in Time-Series Database
CVE-2026-42087
OpenC3 COSMOS has a security flaw in its Time-Series Database that could allow an attacker to delete data. This vulnerability exists in versions of OpenC3 COSMOS from 6.7.0 to before 7.0.0-rc3. Users ...
9.6
Notesnook Note Export Can Execute Malicious Code
CVE-2026-42090
Notesnook's note export feature had a security flaw that allowed attackers to execute malicious code on users' computers. This issue has been fixed in versions 3.3.15 and 3.3.20 of the desktop app and...
9.6
Siemens SIMATIC S7-1200 PLC Software Authentication Bypass
CVE-2026-25293
The Siemens SIMATIC S7-1200 PLC software has a flaw in its authentication system. This allows unauthorized access to the system, potentially leading to data tampering or system crashes. To protect you...
9.6