Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 8 May 2026
RSS972 vulnerabilities published on 8 May 2026
Severity:
free5GC's NEF nnef-pfdmanagement API is unauthenticated; attackers can read data and create subscriptions
GHSA-rwww-x45w-p52w
CVE-2026-44330
The free5GC's NEF nnef-pfdmanagement API does not require a valid login token, allowing an attacker to read sensitive data and create or delete subscriptions. This is a security issue that affects the...
10.0
free5GC's SMF UPI interface lacks authentication protection
GHSA-3258-qmv8-frp3
CVE-2026-44329
GO-2026-4995
The free5GC's SMF (Service Management Function) has a security issue in its UPI (Unified Policy Interface) management interface. This means that an attacker can access and modify sensitive data withou...
10.0
free5GC's NEF OAM Route Group is Unauthenticated
GHSA-cmpj-2x3g-m7g3
CVE-2026-44327
A security issue exists in free5GC's NEF software. The OAM route group is not protected by a login check, allowing unauthorized access to sensitive operations. This issue can be exploited by an attack...
10.0
Emlog versions before 2.6.11 allow SQL attacks on database
CVE-2026-42287
Emlog, a website building system, had a security weakness that allowed hackers to access and manipulate its database. This could lead to the theft of sensitive information or even destroy the system. ...
10.0
Data Space Portal: Unauthorized Access to New Accounts
CVE-2026-42160
Data Space Portal versions 2.1.1 to 7.3.1 are at risk of unauthorized access to new user accounts. This could allow an attacker to gain access to sensitive data. Update to version 7.3.2 or later to fi...
10.0
OpenVPN with OAuth2 plugin allows unauthorized access
DEBIAN-CVE-2026-41070
OpenVPN servers with an OAuth2 plugin in experimental mode may let unauthorized users connect. This happens when they use a client that doesn't support single sign-on. The fix is included in version 1...
10.0
Remote Spark SparkView before build 1122 allows code execution as root
CVE-2026-6213
An older version of Remote Spark SparkView software on a server can be exploited by an attacker to gain full control of the server, potentially leading to data theft or system damage. This vulnerabili...
10.0
OpenLearnX Can Run Malicious Code on Its Servers
GHSA-8h25-q488-4hxw
CVE-2026-41900
OpenLearnX's code execution environment has a critical flaw that could allow an attacker to run malicious code on the server, potentially leading to unauthorized access or data breaches. This issue ha...
10.0
Termix versions before 2.1.0 allow remote code execution
CVE-2026-42454
Termix, a web-based server management platform, had a security issue that allowed an attacker to execute commands on managed servers. This happened when an attacker entered a special container ID. The...
9.9
NVIDIA Garak AI Scanner Remote Code Execution Vulnerability
CVE-2026-41512
The NVIDIA Garak AI Scanner has a security issue that allows attackers to inject malicious code into the browser. This could potentially allow them to take control of the system. Users should update t...
9.9
pfSense XMLRPC API allows malicious code execution by admins
CVE-2025-69691
A security issue exists in pfSense CE 2.8.0 that allows administrators to execute unauthorized code through the XMLRPC API. This could potentially allow an attacker to gain control of the system if an...
9.9
FastGPT versions 4.14.10 to 4.14.12: Unauthenticated access to AI Agent
CVE-2026-42302
FastGPT's AI Agent building platform has a security issue from version 4.14.10 to 4.14.12. This means that anyone with access to the network can potentially take control of the AI Agent without needin...
9.8
Postiz Docker Image Build Allows Unauthenticated Code Execution
CVE-2026-42298
An attacker can create a malicious Docker image that executes code without needing a password. This could allow them to access sensitive information. To protect against this, ensure that you have the ...
9.8
Snipe-IT Insecure Permissions Allows Remote Code Execution
CVE-2026-37709
GHSA-xg82-2hrv-hf64
A security issue in Snipe-IT versions 8.4.0 and earlier could allow an attacker to execute malicious code remotely. This affects users who have not updated to a fixed version. To protect your system, ...
9.8
MailEnable Enterprise Premium: Unauthorized Access to Admin Tools
CVE-2026-44400
MailEnable's Enterprise Premium version 10.55 and earlier has a security issue that lets attackers gain access to administrative tools without permission. This is because the system doesn't properly c...
8.7
Electerm Prior to 3.7.16 Allows Malicious File Execution
CVE-2026-43940
GHSA-f77v-9vpc-6pjm
Electerm's terminal client has a security issue that allows an attacker to run malicious code on a user's computer if they can trick the client into loading a malicious file. This is fixed in version ...
9.8
NornicDB's Bolt Server Allows Remote Access on LAN
GHSA-2hp7-65r3-wv54
A vulnerability in NornicDB's Bolt server allows unauthorized remote access to the graph database on a local area network, exposing sensitive data and credentials. This occurs because the Bolt server ...
9.8
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query,...
GHSA-j88v-2chj-qfwx
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, th...
2.3
SQL Injection in pgx PostgreSQL Driver for Go
CVE-2026-41889
The pgx PostgreSQL driver for Go has a security issue that allows attackers to inject malicious SQL code. This can happen when using a non-standard PostgreSQL protocol and a specific type of SQL query...
2.3
fohrloop dash-uploader allows remote code execution
CVE-2026-38360
The fohrloop dash-uploader, used to upload files, has a security flaw that lets an attacker run unauthorized code on a server. This could allow an attacker to access sensitive data or disrupt the serv...
9.8
Go PostgreSQL Driver pgx Allows SQL Injection
UBUNTU-CVE-2026-41889
The Go PostgreSQL driver pgx has a security issue that allows attackers to inject malicious SQL code. This can happen when using a non-standard protocol and a specific type of SQL query. To fix this, ...
6.8
vm2 Sandbox Breakout Allows Remote Code Execution
GHSA-9vg3-4rfj-wgcm
CVE-2026-44009
A vulnerability in vm2 allows attackers to break out of a sandbox and execute arbitrary commands on the host system. This could allow attackers to run malicious code and access sensitive data. To prot...
9.8
vm2 Sandbox Breakout via `neutralizeArraySpeciesBatch`
GHSA-9qj6-qjgg-37qq
CVE-2026-44008
A vulnerability in vm2 allows attackers to break out of the sandbox and execute arbitrary commands on the host system. This could happen if an attacker can manipulate the vm2 environment. To protect y...
9.8
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-43465
An attacker can run malicious code on a Debian Linux server without needing a password. This is a serious security issue because an attacker could access sensitive data or take control of the server. ...
9.8
Linux Kernel: Incorrect Fragment Counting in mlx5 Driver
CVE-2026-43465
A vulnerability in the Linux kernel's mlx5 driver could cause incorrect fragment counting, potentially leading to a negative reference counting error. This issue has been resolved in a recent update. ...
9.8