Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 5 May 2026
RSS546 vulnerabilities published on 5 May 2026
Severity:
Eclipse BaSyx Java Server SDK: Unauthenticated File Writing
CVE-2026-7411
GHSA-8gpm-h2mh-36qc
The Eclipse BaSyx Java Server SDK, used in certain applications, has a security flaw that allows an attacker to write files anywhere on the computer. This could potentially let an attacker take contro...
10.0
Django-S3File allows attackers to load files from anywhere
GHSA-67qg-7284-2277
CVE-2026-42196
An attacker can trick Django-S3File into loading files from unintended locations, potentially exposing sensitive data or corrupting files. To fix this, update Django-S3File to version 7.0.2 or later.
9.9
Gitix submodule name validation bypass and trust inheritance flaw
GHSA-p3hw-mv63-rf9w
A flaw in Gitix allows attackers to access and read sensitive information from arbitrary Git repositories. This is due to a combination of a submodule name validation bypass and a trust inheritance fl...
9.9
FireFighter's Jira Bot Endpoint Allows Unauthorized Access to AWS Credentials
GHSA-fqvv-jvhr-g5jc
CVE-2026-42864
An attacker can exploit a security weakness in FireFighter's Jira bot feature to steal sensitive AWS credentials. This can happen if an unauthenticated user can access the FireFighter server. To prote...
9.9
Apache HTTP Server mod_proxy_ajp crashes with malicious server response
DEBIAN-CVE-2026-28780
A malicious server can send a message that causes the Apache HTTP Server's mod_proxy_ajp module to crash. This happens when mod_proxy_ajp connects to a server that sends a specially crafted message. T...
9.8
D-Link DI-8100 Buffer Overflow Risk via POST Request
CVE-2026-7854
A D-Link DI-8100 router's ability to handle POST requests can be exploited, allowing an attacker to potentially cause the router to crash or become unstable. This can happen if a malicious request is ...
8.9
Kestra v1.3.3 and before allows hackers to manipulate database queries
CVE-2026-38428
Kestra versions 1.3.3 and earlier are at risk because hackers can inject malicious code into database queries. This can lead to unauthorized access to sensitive information. To stay safe, update to th...
9.8
OpenCTI versions 6.6.0 to 6.9.12 allow unauthenticated access to admin API
CVE-2026-27960
OpenCTI's API is accessible to anyone without a login, allowing them to view and potentially manipulate data. This is a serious issue because it gives attackers control over the platform. To fix this,...
9.8
D-Link DI-8100 allows remote code execution via buffer overflow
CVE-2026-7853
The D-Link DI-8100's HTTP Handler has a weakness that can allow hackers to execute malicious code remotely. This can be done by sending a specially crafted message to the device. We recommend updating...
8.9
CodeChecker: Unauthorized Access to User Permissions
CVE-2026-25660
GHSA-4v9x-cqc5-j645
CodeChecker, a tool used to analyze code, allows an attacker to gain access to any user's permissions by crafting a specific URL. This could allow an attacker to view or modify sensitive information. ...
9.3
ERPNext Email Templates Can Execute Malicious Code
CVE-2026-38431
ERPNext versions before 15.103.1 have a security flaw in their email template system. An attacker with permission to create or edit email templates can potentially inject malicious code that can be ex...
9.8
vm2 Sandbox Escape Allows Arbitrary Code Execution
CVE-2026-26956
GHSA-ffh4-j6h5-pg66
A vulnerability in vm2 version 3.10.4 allows an attacker to escape the sandbox and run any code on the host machine. This means an attacker could potentially take control of your system. Update to ver...
9.8
vm2 Sandbox Escape in Node.js Versions Prior to 3.11.0
CVE-2026-26332
GHSA-55hx-c926-fr95
A security issue in older versions of vm2 for Node.js allows attackers to break out of a secure environment and run their own code. This is a serious risk, especially for servers hosting untrusted cod...
9.8
Node.js vm2 Sandbox Breakout through Inspect Function
CVE-2026-24781
GHSA-v37h-5mfm-c47c
A vulnerability in Node.js' vm2 sandbox allows attackers to escape the sandbox and execute arbitrary commands on the host system. This affects versions prior to 3.11.0. Update to version 3.11.0 or lat...
9.8
vm2 Sandbox Escape in Node.js Versions Prior to 3.10.5
CVE-2026-24120
GHSA-qvjj-29qf-hp7p
An outdated version of the vm2 sandbox for Node.js can be tricked into allowing malicious code to break free and run commands on the host computer. This is fixed in version 3.10.5. Update to the lates...
9.8
Linux Kernel: ext4 File Allocation Error
CVE-2026-43067
A Linux kernel bug affected ext4 file system allocation. It could have led to incorrect block allocation for certain files. This has been fixed by adding a safety check to prevent this issue.
9.8
Debian Linux: Unprivileged user can gain elevated privileges
DEBIAN-CVE-2026-43067
A vulnerability in Debian Linux allows an attacker with normal user privileges to gain elevated access to the system. This could potentially allow the attacker to install malicious software or make ch...
9.8
rootio-mbedtls: Malicious Certificate Can Bypass Security Checks
ROOT-OS-DEBIAN-12-CVE-2025-47917
A security patch has been released for the rootio-mbedtls package in Root:Debian:12. This patch addresses a vulnerability that could allow a malicious certificate to bypass security checks. Root users...
9.8
ipTIME NAS1dual: Remote Attack Possible via Web Interface
CVE-2026-7834
An attacker can exploit a weakness in the web interface of ipTIME NAS1dual devices running version 1.5.24, potentially allowing them to execute unauthorized code. This could lead to unauthorized acces...
8.9
OpenClaw versions 2026.4.7 to 2026.4.13 have a security flaw that lets attackers gain extra access
CVE-2026-43566
OpenClaw versions 2026.4.7 to 2026.4.13 are affected. This means attackers can send fake messages that trick the system into giving them more access than they should have. To stay safe, update to vers...
9.1
OpenClaw before 2026.4.10 lets attackers escalate input
CVE-2026-43534
OpenClaw, a system management tool, has a security flaw that allows attackers to make it do more than intended. This could lead to unauthorized actions on the system. To stay safe, update to the lates...
9.3
Eclipse Equinox OSGi Remote Code Execution
CVE-2023-54344
Eclipse Equinox OSGi versions 3.7.2 and earlier have a security flaw that allows hackers to run unauthorized commands on your system. This can happen if an attacker connects to a specific port and sen...
9.3
Eclipse Equinox OSGi Versions 3.8-3.18: Unauthenticated Remote Code Execution
CVE-2023-54342
The Eclipse Equinox OSGi console interface has a security flaw that allows attackers to execute malicious code on your system without a password. This can happen if an attacker can connect to your sys...
9.3
Eclipse Equinox OSGi versions 3.8 to 3.18 allow remote code execution
UBUNTU-CVE-2023-54342
Versions 3.8 to 3.18 of Eclipse Equinox OSGi are vulnerable to a remote code execution attack. This means an attacker could potentially run malicious code on your system without your permission. To pr...
9.9
Eclipse Equinox OSGi Remote Code Execution Vulnerability
UBUNTU-CVE-2023-54344
Using Eclipse Equinox OSGi may allow attackers to execute code on your server. This is a serious issue because it can lead to unauthorized access and data breaches. Update Eclipse Equinox OSGi to the ...
9.9