Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 12 May 2026
RSS754 vulnerabilities published on 12 May 2026
Severity:
ChurchCRM Setup Wizard Password Risk
CVE-2026-42288
ChurchCRM's setup wizard password is not properly secured, allowing attackers to potentially run malicious code. This risk affects older versions of ChurchCRM and has been fixed in version 7.3.2. Upda...
10.0
Dalfox Server Mode: Unauthenticated Remote Code Execution via `found-action`
GHSA-v25v-m36w-jp4h
CVE-2026-45087
When running Dalfox in server mode, an attacker can send a malicious request to execute arbitrary commands on the host system without authentication. This is a critical issue because it allows an atta...
10.0
Nginx UI allows attackers to access internal services
CVE-2026-44015
A user with a valid login to Nginx UI can potentially access internal services and data by exploiting a weakness in the way the system handles requests. This could allow unauthorized access to sensiti...
9.9
Microsoft Dynamics 365 On-Premises Code Execution Risk
CVE-2026-42898
An authorized user with Microsoft Dynamics 365 on-premises access can execute unauthorized code over a network, potentially allowing an attacker to gain more access than they should have. This is a co...
9.9
Azure Logic Apps Privilege Elevation Over Network
CVE-2026-42823
Azure Logic Apps has a security issue that allows authorized users to gain more access than they should over a network. This means that an attacker who is already authorized could potentially do more ...
9.9
Microsoft Dynamics 365 Customer Insights Privilege Escalation
CVE-2026-33821
An attacker with authorized access to Microsoft Dynamics 365 Customer Insights can potentially gain higher-level access to the system, allowing them to view or modify sensitive data. This is a concern...
9.9
Arduino ESP32 Web Server Crashes from Malicious Data
CVE-2026-42854
A bug in the Arduino ESP32's web server can cause it to crash if it receives a large amount of data from a website. This could potentially allow an attacker to take control of the device. Update to th...
9.8
Exim before 4.99.3 - Unauthenticated code execution via malicious email
CVE-2026-45185
Exim, a popular email server software, has a security flaw that allows an attacker to execute malicious code without needing a password. This can happen if an attacker sends a specific type of email t...
9.8
Debian Linux: Unprivileged user can escalate privileges
DEBIAN-CVE-2026-45185
A Debian Linux security issue allows an attacker with normal user privileges to gain full system control. This could happen if a malicious user exploits a weakness in the Debian package management sys...
9.8
Mamba Language Model Framework through 2.2.6 Allows Malicious Model Execution
CVE-2026-31239
GHSA-pq2f-x424-6fjm
The Mamba language model framework allows attackers to execute arbitrary code on a victim's system when loading pre-trained models from HuggingFace Hub. This is a security risk because it can be used ...
9.8
Ludwig framework model server exposes systems to code execution
CVE-2026-31238
GHSA-xp5q-5q7g-q26r
The Ludwig framework's model server is at risk if an attacker provides a malicious model file. This could allow the attacker to run any code they want on the system hosting the model server. To fix th...
9.8
imgaug library (0.4.0 and earlier) allows code execution via malicious data
CVE-2026-31235
GHSA-g82g-j283-hj97
The imgaug library has a security flaw that allows an attacker to run malicious code on your system if they can influence the data used by the library. This is particularly concerning if you're using ...
9.8
Ludwig framework predict() method deserializes malicious data
CVE-2026-31237
GHSA-wcr3-gm9f-f87q
The Ludwig framework's predict() method can load and execute malicious code from a pickle file, allowing an attacker to run arbitrary code on the system. This can happen if a user provides a malicious...
9.8
LLM CLI Tool Through 0.27.1 Allows Malicious Code Execution
CVE-2026-31236
GHSA-g76p-4vg5-f4qh
The LLM CLI tool is affected if you use the --functions option to run custom Python code. This is a serious security risk because an attacker could trick you into running malicious code, giving them c...
9.8
Guardrails AI through 0.6.7 allows remote code execution via Hub package installation
CVE-2026-31233
GHSA-r6hf-g5x6-7pv9
Guardrails AI has a security flaw in its package installation process. An attacker can publish malicious packages, which can then be installed by a victim and execute arbitrary code on their system. T...
9.8
Horovod 0.28.1 KVStore HTTP Server Allows Remote Code Execution
CVE-2026-31234
GHSA-mf8f-x4r3-jm8c
Horovod's distributed task coordination system has a security flaw that lets attackers run code on your computers. This happens because the system doesn't check who is sending data, and it can execute...
9.8
Apache Tomcat allows unauthorized access due to input mistakes
CVE-2026-41293
BIT-tomcat-2026-41293
GHSA-r29c-68gh-xp6x
Apache Tomcat versions from 9 to 11 have a security flaw that could let attackers access data they shouldn't. This matters because it could expose sensitive information. To fix it, update to the lates...
9.8
PySyft: Remote Code Execution via User-Submitted Code
CVE-2026-31220
GHSA-cfpg-c974-jfhq
PySyft versions 0.9.5 and earlier allow attackers to run malicious code on the server, potentially taking control of the server environment. This is a serious risk because it could allow an attacker t...
9.8
Apache Tomcat Digest Authentication Bypass Risk
CVE-2026-43512
BIT-tomcat-2026-43512
GHSA-h6fc-48rj-7qqh
Apache Tomcat versions 7 through 11 have a security issue that allows unauthorized access. This could happen if an attacker finds a way to bypass the authentication process, which is used to verify us...
9.8
WGDashboard on WireGuard VPN allows unauthorized access to host files
CVE-2026-44343
If you use WGDashboard with WireGuard VPN, update to version 4.3.2 or later to prevent unauthorized access to your host file system. This is a serious security issue that can be exploited by malicious...
9.3
Fortinet FortiAuthenticator: Unauthorized Code Execution
CVE-2026-44277
Fortinet's FortiAuthenticator software has a security issue that could allow an attacker to run unauthorized code or commands on the system. This could potentially allow the attacker to access or modi...
9.8
Microsoft Windows DNS Allows Unauthorized Code Execution
CVE-2026-41096
A security flaw in Microsoft Windows DNS could allow an attacker to run malicious code on a targeted system over the network. This could happen if an attacker sends a specially crafted request to the ...
9.8
Windows Netlogon Buffer Overflow Risk
CVE-2026-41089
An attacker can remotely execute malicious code on a Windows system by exploiting a weakness in the Netlogon service. This could allow the attacker to take control of the system and potentially spread...
9.8
LLM CLI Tool Through 0.27.1 Allows Malicious Code Execution
DEBIAN-CVE-2026-31236
The LLM CLI tool has a critical security issue that allows attackers to run malicious code on a victim's system. This happens when a user is tricked into running a specially crafted command with custo...
9.8
Cognee thru v0.4.0: Remote Code Execution via Notebook Cell
CVE-2026-31231
An attacker can execute malicious code on the Cognee server by sending a specially crafted request. This could lead to the complete compromise of the system. Update Cognee to a version after v0.4.0 to...
9.8