Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 10 May 2026

RSS

995 vulnerabilities published on 10 May 2026

Severity:
WordPress Download From Files Plugin Uploads Malicious Files
CVE-2021-47940
The WordPress Download From Files plugin, versions 1.48 and earlier, allows attackers to upload malicious files without a password. This means that unauthorized users can upload files that could harm ...
9.3
OpenCATS 0.9.4 allows attackers to run malicious code remotely
CVE-2021-47936
An attacker can upload a malicious file to OpenCATS, pretending it's a resume, and then execute system commands without needing a password. This could allow an attacker to access sensitive information...
9.3
WordPress MStore API allows malicious file uploads
CVE-2021-47933
The WordPress MStore API has a security issue that allows hackers to upload malicious files to your server without needing a password. This could let them take control of your server. To fix this, upd...
9.3
TheCartPress: Attackers Can Create Administrator Accounts
CVE-2021-47932
An attacker can create an administrator account on a TheCartPress site without needing a password, allowing them to make changes to the site. This is a serious security risk because an attacker could ...
9.3
OpenCart 3.0.3.8: Hijacked User Sessions via Malicious Cookie
CVE-2021-47923
OpenCart's session management is affected, allowing attackers to take control of user sessions. This can lead to unauthorized access to user accounts. To protect your store, update to the latest versi...
9.3
Debian Linux: Unauthenticated Remote Code Execution via Samba
DEBIAN-CVE-2026-7261
A vulnerability in the Samba file sharing service on Debian Linux allows attackers to execute malicious code on affected systems without being authenticated. This means that hackers can potentially ta...
8.4
PHP SoapServer persistence can cause memory corruption or crashes
CVE-2026-7261
PHP versions 8.2 to 8.5 have a bug that can cause memory corruption or crashes when handling SOAP requests. This can lead to sensitive information being leaked or the system becoming unstable. To fix ...
6.3
Debian Linux: Unprivileged users can read sensitive files
DEBIAN-CVE-2026-6722
A security issue in Debian Linux allows unprivileged users to access sensitive files on the system. This could potentially allow an attacker to gain more access to the system. To fix this issue, updat...
9.4
PHP SOAP Extension Remote Code Execution in Certain Versions
CVE-2026-6722
A vulnerability in PHP's SOAP extension affects certain versions. It allows an attacker to execute malicious code on a server by manipulating SOAP requests. To fix this, update to a supported version ...
9.5
Debian Linux: Unprivileged access to sensitive system files
DEBIAN-CVE-2025-14179
A vulnerability in Debian Linux allows unprivileged users to access sensitive system files. This could potentially allow an attacker to gain elevated privileges and take control of the system. Debian ...
9.9
PHP PDO Firebird driver SQL injection risk in certain versions
CVE-2025-14179
Certain PHP versions with the PDO Firebird driver are at risk of SQL injection attacks. This occurs when an attacker injects malicious code into SQL queries by exploiting the driver's improper handlin...
7.4
PHP PDO Firebird driver SQL injection risk with NUL bytes
UBUNTU-CVE-2025-14179
The PHP PDO Firebird driver can be exploited by attackers to inject malicious SQL code if certain values are not properly handled. This affects PHP versions 8.2 to 8.5 and can lead to unauthorized dat...
9.9
PHP SoapServer Persistence Allows Memory Corruption
UBUNTU-CVE-2026-7261
A bug in PHP's SoapServer allows a malicious SOAP request to potentially cause memory corruption, information disclosure, or crashes in affected systems. This affects PHP versions 8.2 through 8.5, and...
8.4
PHP SOAP Extension Pointer Leak in PHP Versions 8.2 to 8.5
UBUNTU-CVE-2026-6722
The PHP SOAP extension has a bug that can allow an attacker to execute malicious code on your server. This is a serious issue because it can be exploited remotely, without requiring direct access to y...
9.4
rootio-linux: Unauthenticated Root Access on Linux Devices
ROOT-OS-DEBIAN-11-CVE-2026-23112
A security patch has been released for rootio-linux to prevent unauthorized access to Linux devices. This affects users of rootio-linux on Debian 11. To protect your system, update to the latest versi...
9.8
Debian Linux: Unauthenticated Remote Code Execution in libssh2
DEBIAN-CVE-2026-6104
A vulnerability in the libssh2 library used by Debian Linux allows an attacker to execute malicious code on a server without needing a password. This could happen if a server is accessed over the inte...
8.1
PHP mbstring Functions Can Crash or Leak Memory
CVE-2026-6104
PHP versions 8.4 and 8.5 are affected. If a malicious encoding name is passed to certain functions, it can cause a crash or memory leak, potentially exposing sensitive information. Update to the lates...
6.3
PHP: Malicious Encoding Can Cause Crash or Data Exposure
UBUNTU-CVE-2026-6104
PHP versions 8.4 and 8.5 have a bug that can cause a crash or allow an attacker to access sensitive information if a malicious encoding is used. This issue affects websites and applications using PHP,...
8.1
Aero CMS allows attackers to run malicious code
CVE-2022-50944
Aero CMS has a security flaw that lets attackers with a login run their own code on the server. This could lead to unauthorized changes or data theft. To fix this, update Aero CMS to the latest versio...
8.7
CyberPanel 2.1 allows attackers to read files and execute code
CVE-2021-47949
CyberPanel, a web hosting control panel, has a security flaw that lets attackers with a login access to sensitive information and run malicious code on the server. This could lead to unauthorized acce...
8.7
TextPattern CMS 4.8.7 allows attackers to run malicious code
CVE-2021-47943
Authenticated attackers can upload malicious files to TextPattern CMS, allowing them to run arbitrary commands on the server. This is a serious security risk because it could give attackers full contr...
8.7
Evolution CMS allows authenticated users to execute system commands
CVE-2021-47939
Authenticated users with module creation permissions in Evolution CMS can inject malicious code to execute system commands. This could allow an attacker to gain unauthorized access or disrupt the syst...
8.7
ImpressCMS Autotasks Interface Allows Malicious PHP Code Execution
CVE-2021-47938
ImpressCMS's administrative interface has a security flaw that lets attackers who have logged in execute their own PHP code on the site. This can be done by submitting a special request with malicious...
8.7
e107 CMS Allows Malicious Theme Files to Execute System Commands
CVE-2021-47937
Authenticated users with theme installation permissions on e107 CMS can upload malicious theme files, which can then execute system commands. This allows attackers to take control of the website. To f...
8.7
Sentry 8.2.0 allows superusers to execute malicious code
CVE-2021-47935
Authenticated superusers in Sentry 8.2.0 can execute malicious code if an attacker sends a specific type of request to the audit log endpoint. This means that if an attacker gains access to a superuse...
8.7