Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 9 May 2026
RSS415 vulnerabilities published on 9 May 2026
Severity:
Ruby Net::IMAP allows malicious IMAP commands
DEBIAN-CVE-2026-42258
Net::IMAP, a Ruby library for accessing email, had a security issue that allowed attackers to inject malicious commands. This has been fixed in newer versions. If you're using an older version, update...
7.1
Net::IMAP in Ruby allows malicious IMAP command injection
DEBIAN-CVE-2026-42257
The Net::IMAP library in Ruby has a security issue. If a user enters malicious input, it could be used to execute unauthorized commands on the email server. This issue has been fixed in versions 0.4.2...
7.6
Apache HTTP Server Remote Code Execution in PHP
BELL-CVE-2026-43185
Apache HTTP Server's PHP module allows attackers to execute arbitrary code on the server, potentially leading to unauthorized data access or system compromise. This affects servers using the PHP modul...
9.8
Apache HTTP Server Denial of Service on Windows
BELL-CVE-2026-43465
Apache's HTTP Server on Windows can be crashed by a malicious request, causing the server to stop working. This affects servers running Apache on Windows and can be exploited by an attacker to make th...
9.8
WordPress Plugin 'Easy Social Sharing' Allows Malicious Code Execution
BELL-CVE-2026-43414
An issue in the 'Easy Social Sharing' plugin for WordPress allows attackers to inject malicious code. This could lead to unauthorized access to sensitive data or website takeover. Update the plugin to...
9.8
PgBouncer SCRAM overflow due to unchecked strlcat() return value
DEBIAN-CVE-2026-6665
A bug in PgBouncer's SCRAM code can cause a stack overflow if a malicious backend sends a long nonce. This can potentially allow an attacker to crash the PgBouncer service. To fix this, update to vers...
9.8
mcp-server Domain Lookup Module at Risk of Command Execution
GHSA-v6wj-c83f-v46x
The domain_lookup module in mcp-server allows unauthenticated attackers to execute arbitrary system commands. This could lead to unauthorized access, data theft, or disruption of service. Update the m...
9.8
mcp-server vulnerable to command execution through domain lookup
GHSA-v6wj-c83f-v46x
The mcp-server's domain lookup module allows an unauthenticated attacker to execute arbitrary system commands. This could lead to unauthorized access to system resources, data theft, or system comprom...
9.8
Apache HTTP Server Denial of Service Vulnerability
BELL-CVE-2026-43117
Apache HTTP Server versions 2.4.53 and earlier may crash or become unresponsive when processing certain HTTP requests. This could lead to service downtime or allow an attacker to disrupt website funct...
9.1
Linkwarden: Unvalidated HTTP Requests Can Expose Internal Services
CVE-2026-44313
Linkwarden, a self-hosted bookmark manager, had a security flaw that allowed authenticated users to make unauthorized requests to internal services. This could have allowed them to access sensitive in...
9.1
Gibbon versions before v30.0.01 allow hackers to access server files
CVE-2026-8208
Old versions of Gibbon software are at risk of being hacked by a malicious user with Teacher or higher privileges. If exploited, this could allow the hacker to access and control the server hosting Gi...
8.9
Wavlink NU516U1 M16U1_V240425 allows remote attackers to inject commands.
CVE-2026-8192
A security flaw in the Wavlink NU516U1 M16U1_V240425 allows hackers to remotely execute commands on the device. This could potentially allow them to access sensitive information or take control of the...
2.1
Wavlink NU516U1 M16U1_V240425 WiFi Settings Manipulation Risk
CVE-2026-8191
A vulnerability in Wavlink's NU516U1 M16U1_V240425 allows an attacker to manipulate WiFi settings remotely. This could potentially allow an attacker to execute system commands, which could lead to una...
2.1
Wavlink NU516U1 WAN Configuration Injection
CVE-2026-8190
An attacker can remotely inject malicious commands into a Wavlink NU516U1 router's WAN configuration. This could allow an attacker to gain unauthorized access to the router or disrupt internet connect...
2.1
Wavlink NU516U1 M16U1_V240425 - Remote Command Injection via Web Interface
CVE-2026-8189
A vulnerability in the web interface of Wavlink NU516U1 M16U1_V240425 allows an attacker to execute arbitrary system commands remotely. This could potentially be used to take control of the device or ...
2.1
Wavlink Router: Unsecured WiFi Password Change Exposes System
CVE-2026-8188
A security flaw in the Wavlink NU516U1 router's WiFi password change function allows hackers to execute malicious commands on the system. This means that an attacker can remotely access and control th...
2.1
Apache HTTP Server Denial of Service Vulnerability
BELL-CVE-2026-43283
Apache HTTP Server versions 2.4.52 and earlier may be vulnerable to a denial of service attack. This could allow an attacker to crash the server, disrupting access to websites and online services. We ...
8.8
Apache HTTP Server: Remote Code Execution via Malicious HTTP Request
BELL-CVE-2026-43249
Apache HTTP Server versions 2.4.52 and earlier may allow an attacker to execute arbitrary code on the server if they can send a specially crafted HTTP request. This could potentially allow the attacke...
8.8
Apache HTTP Server Remote Code Execution in Logs
BELL-CVE-2026-43232
Apache HTTP Server versions 2.4.51 and earlier have a vulnerability in their log file handling. This could allow an attacker to execute malicious code on a server by manipulating log entries. To prote...
8.8
Linkwarden versions 2.14.0 and prior: Unsanitized JavaScript in archive upload
CVE-2026-42455
A self-hosted bookmark manager, Linkwarden, has a security issue in older versions. If an attacker uploads malicious HTML files, they can run code on your server when users access the archive. To prot...
8.8
Bubblewrap setuid mode allows unauthorized access
CVE-2026-41163
Bubblewrap, a tool for sandboxing applications, has a security issue when installed in a special mode that allows certain users to gain more access than they should. This could potentially allow attac...
8.7
Spring AI: Unsanitized Document IDs Allow Data Deletion
CVE-2026-41705
GHSA-v632-2m87-7469
An attacker can delete data in Spring AI's database by manipulating document IDs. This is a security risk because sensitive information can be removed. To fix this, upgrade to version 1.0.7 or later f...
8.6
Java Library Allows Untrusted Code Execution in Firefox
BELL-CVE-2026-43274
A vulnerability in a Java library used by Firefox allows attackers to execute malicious code. This could potentially allow hackers to take control of a user's browser. Firefox users should update thei...
8.4
Plainpad self-hosted note taking app admin access escalation
CVE-2026-42562
A user with limited access to Plainpad can gain full admin rights by submitting a specific request. This could allow them to access and modify sensitive data. Update to version 1.1.1 to fix this issue...
8.3
Debian Linux: Unpatched System Files Can Be Overwritten
DEBIAN-CVE-2026-41163
Certain Debian Linux systems are missing a security update, which allows an attacker to overwrite system files. This could lead to unauthorized access and data tampering. Update your Debian Linux syst...
8.3