Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 7 May 2026
RSS807 vulnerabilities published on 7 May 2026
Severity:
Azure AI Foundry M365 Agents Privilege Elevation Risk
CVE-2026-35435
Unauthorized access to Azure AI Foundry M365 agents could allow attackers to gain elevated network privileges. This affects the security of your network and data. Update your agents to the latest vers...
10.0
Note Mark JWT Secret is Too Weak for Security
GHSA-q6mh-rqwh-g786
CVE-2026-44523
A weak secret in Note Mark makes it possible for attackers to steal user accounts. This happens when they crack the secret using a computer and then create fake login tokens for any user. To fix this,...
10.0
Open Notebook v1.8.3 allows malicious code execution
CVE-2026-33587
Open Notebook v1.8.3 does not properly check user input, which can lead to malicious code being executed on the server. This can result in unauthorized access to system resources. To fix this issue, u...
9.2
vm2: Attackers can modify fundamental JavaScript objects
GHSA-vwrp-x96c-mhwq
CVE-2026-44005
The vm2 software allows attackers to modify fundamental JavaScript objects like Object.prototype, Array.prototype, and Function.prototype. This could allow attackers to gain control of a system or ste...
10.0
vm2 Sandbox Escape Allows Malicious Code Execution
GHSA-47x8-96vw-5wg6
CVE-2026-43997
The vm2 JavaScript engine has a vulnerability that allows an attacker to escape the sandbox and execute malicious code on the host system. This could lead to unauthorized access and control of the sys...
10.0
vm2 Sandbox Escape Allows Remote Code Execution
GHSA-qcp4-v2jj-fjx8
CVE-2026-44006
The vm2 library has a security flaw that could allow an attacker to execute malicious code on a server. This could happen if a developer uses vm2 to run untrusted code. To protect against this, update...
10.0
Unauthorized Code Execution in Azure Managed Cassandra
CVE-2026-33109
An authorized user with access to Azure Managed Instance for Apache Cassandra can potentially execute malicious code over a network. This could allow the attacker to access sensitive data or disrupt t...
9.9
vm2 allows sandboxed code to load excluded builtins
GHSA-947f-4v7f-x2v8
CVE-2026-43999
A vulnerability in vm2 allows malicious code to escape the sandbox and load excluded builtins, potentially leading to remote code execution on the host system. This affects users who use vm2 to sandbo...
9.9
Fleet: Helm impersonation bypass exposes sensitive cluster-admin credentials
GHSA-765j-qfrp-hm3j
CVE-2026-41050
A vulnerability in Fleet's Helm deployer allows a tenant with access to a monitored repository to read secrets from any namespace on downstream clusters. This is a confidentiality risk, as leaked cred...
9.9
GitHub Enterprise Server notebook viewer exposes internal services to attackers
CVE-2026-8034
A security weakness in the GitHub Enterprise Server notebook viewer allows attackers to access internal services on the same network. This could lead to unauthorized access to sensitive data or system...
7.9
GitPython: Malicious Git Configs Can Be Applied During Clone
DEBIAN-CVE-2026-42284
GitPython, a Python library used to interact with Git repositories, had a security issue prior to version 3.1.47. An attacker could use a specially crafted command to apply malicious Git configuration...
9.8
Apache Log4j Unauthenticated Remote Code Execution
UBUNTU-CVE-2026-42284
Apache Log4j, a logging library used in many software applications, has a flaw that allows attackers to execute malicious code on a server without needing a password. This could lead to unauthorized a...
9.8
Query-Parser-String for NPM: Malicious Query Parameters Can Harm Your App
CVE-2025-63704
GHSA-587p-w43q-4hjx
The query-parser-string package for NPM doesn't properly check user input, which can cause unexpected behavior in your application. This can happen if you use user-supplied data in your application wi...
9.8
parse-ini npm package allows attackers to modify JavaScript objects
CVE-2025-63703
GHSA-x72j-hv9f-qqh4
The parse-ini npm package has a security issue that allows attackers to manipulate JavaScript objects, potentially leading to unexpected behavior in applications that use this package. This could allo...
9.8
Yarbo Firmware v2.3.9: Hardcoded Admin Credentials
CVE-2026-7414
A security flaw in Yarbo firmware v2.3.9 allows anyone with the correct credentials to access device management interfaces. This is a concern because the credentials are the same for all devices and c...
9.8
Yarbo Firmware v2.3.9 Has Hidden Backdoor Allowing Remote Access
CVE-2026-7413
A hidden backdoor was discovered in Yarbo firmware version 2.3.9, allowing unauthorized access to sensitive features. This poses a risk to security and data integrity. Update to a fixed version of the...
9.8
Ivanti EPMM versions 12.6.1 and earlier allow unauthorized access
CVE-2026-5788
A security issue in older Ivanti EPMM versions lets an attacker access sensitive features without permission. This could allow them to manipulate the system in unintended ways. Update to version 12.6....
9.8
Next NPM Version Vulnerable to Untrusted Input
CVE-2025-63706
GHSA-2xx6-qf7x-grqh
The Next NPM Version package is used in some projects to update NPM packages. If an attacker can inject malicious input, they may be able to execute arbitrary system commands, potentially allowing the...
9.8
ChestnutCMS SQL Injection in Admin Backend
CVE-2026-36458
An attacker can inject malicious SQL code into the ChestnutCMS admin backend, potentially allowing them to access or modify sensitive data. This vulnerability affects the admin backend of ChestnutCMS ...
9.8
Optoma CinemaX P2 Projector Exposes Remote Control API on Network
CVE-2026-30496
The Optoma CinemaX P2 projector has a remote control system that can be accessed by any device on the same network without a password. This means that anyone with a device connected to the same networ...
9.8
Firefox ESR: WebRTC Security Risk in Older Versions
CVE-2026-8094
Older versions of Firefox ESR may be at risk of a security issue in the WebRTC component. This means that an attacker could potentially exploit a weakness in the software to gain unauthorized access. ...
9.8
Debian Package Manager Allows Arbitrary File Execution
DEBIAN-CVE-2026-8094
A security issue in Debian's package manager could allow an attacker to execute any file on a system. This could happen if a user installs a malicious package or if an attacker gains access to the pac...
9.8
Debian OpenSSL Key Generation Flaw Allows Man-in-the-Middle Attacks
DEBIAN-CVE-2026-8091
A flaw in Debian's OpenSSL package allows attackers to intercept sensitive information, such as encrypted data and login credentials. This can happen when Debian systems generate or use OpenSSL keys. ...
9.8
Firefox: Audio/Video playback can crash or be exploited
CVE-2026-8091
A bug in Firefox's audio and video playback component can cause the browser to crash or be exploited by attackers. This issue affects users who have not updated to the latest Firefox ESR versions. To ...
9.8
Liderahenk 2.0.1 allows unauthorized access to restricted features
CVE-2026-6508
A security flaw in Liderahenk 2.0.1 allows users to access features that should be restricted. This could lead to unauthorized actions within the system. To fix this, update to version 2.0.2 or later.
9.8