Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 13 May 2026
RSS925 vulnerabilities published on 13 May 2026
Severity:
ERPNext: Unauthorized Data Modification Before 16.9.1
CVE-2026-44442
ERPNext users with certain roles may be able to access and modify data they shouldn't. This could lead to incorrect or unauthorized changes to your business data. Update to ERPNext version 16.9.1 or l...
9.9
JupyterLab: Malicious buttons can execute code on user click
DEBIAN-CVE-2026-42557
JupyterLab, a popular interactive computing environment, had a security issue that allowed malicious buttons to execute code on a user's computer without their knowledge. This has been fixed in versio...
9.9
Traefik: Unauthorized access to REST provider handler
GHSA-96qj-4jj5-wcjc
CVE-2026-44774
Traefik's REST provider can be exposed by a low-privileged user in a shared deployment, allowing them to reconfigure routers and services. This is possible because Traefik accepts any backend referenc...
6.4
Web::Passwd for Perl allows unauthorized command execution.
CVE-2026-8500
The Web::Passwd Perl module has a security flaw that allows hackers to execute unauthorized commands on a server. This can lead to unauthorized access to sensitive data or the takeover of the server. ...
9.8
Netty: Malformed HTTP Requests Can Cause Message Disagreement
DEBIAN-CVE-2026-42581
Netty, a network framework, has a security issue that can allow attackers to manipulate HTTP requests in a way that can cause issues for downstream servers. This can happen when a request contains con...
9.8
Ecommerce Systempay 1.0 payment key can be guessed
CVE-2020-37168
A weak key in Ecommerce Systempay 1.0 makes it easy for hackers to guess a secret key used to verify payments. This allows them to fake payment signatures and change transaction amounts. You should up...
9.3
Goobi viewer - Unauthenticated access to Solr data
GHSA-2rgp-f66f-4499
CVE-2026-45083
An outdated Goobi viewer API endpoint allowed unauthorized access to its entire Solr index. This meant an attacker could read, modify, or delete sensitive data, including protected documents. To fix t...
9.8
ELECOM Wireless Access Points: Unauthorized OS Command Execution
CVE-2026-42062
ELECOM wireless LAN access points are vulnerable to an attack that can execute any system command without a password. This means an attacker could potentially take control of the device or disrupt its...
9.3
ELECOM Wireless LAN Access Point Authentication Bypass
CVE-2026-40621
Some ELECOM wireless LAN access points do not require a password to access certain settings. This means that anyone with access to the device can make changes without needing a password. You should up...
9.3
Patched: rootio pgx/v5 database connection security risk
ROOT-APP-GOBINARY-CVE-2026-33816
A security issue in the pgx/v5 package for Root:Go has been fixed by Root. This affects how the database connects to your application. Update to a fixed version to prevent potential security risks.
9.8
GUARDIANWALL MailSuite and Mail Security Cloud SaaS - Remote Code Execution Risk
CVE-2026-32661
The GUARDIANWALL MailSuite and Mail Security Cloud SaaS may allow a remote attacker to execute malicious code on the system if they send a specially crafted request to the product's web service. This ...
9.3
Apache HTTP Server Unauthenticated Remote Code Execution
BELL-CVE-2026-42257
The Apache HTTP Server is affected by a vulnerability that allows attackers to execute arbitrary code on a server without needing a password. This could allow unauthorized access to sensitive data or ...
9.8
Obot allows unauthorized access to MCP servers
GHSA-vw82-7fv8-r6gp
Any authenticated Obot user can connect to and use MCP servers they shouldn't have access to, potentially allowing them to make changes or view sensitive data. This is a critical issue that requires i...
9.6
NGINX Software Can Crash or Be Hacked with Malicious Requests
ALPINE-CVE-2026-42945
NGINX software has a weakness that can be exploited by sending specially crafted HTTP requests. This could cause the software to crash or, in some cases, allow an attacker to take control of the syste...
9.4
Debian Linux: Unrestricted Access to Sensitive System Files
DEBIAN-CVE-2026-42945
A vulnerability in Debian Linux allows unauthorized access to sensitive system files. This could be exploited by an attacker to gain elevated privileges, potentially leading to data breaches or system...
9.4
Garmin WDU Cross-Site Attack Allows Full Control
CVE-2025-27851
The Garmin WDU's web interface on some versions can be hacked remotely by tricking the user into visiting a malicious website. This allows the hacker to take full control of the device. To stay safe, ...
9.3
OPNsense Firewall Allows Remote Code Execution as Root
CVE-2026-45158
If you're using an OPNsense firewall version prior to 26.1.8, an attacker could potentially execute malicious code on your system. This is a serious issue because it could give an attacker complete co...
9.1
OPNsense: Unauthenticated Users Can Run System Commands as Root
CVE-2026-44194
OPNsense users with certain privileges can run system commands with root access, which could allow an attacker to gain control of the system. This is a serious issue because it allows an attacker to m...
9.1
OPNsense Firewall Allows Remote Attackers to Run Malicious Code
CVE-2026-44193
A security issue in older versions of OPNsense's firewall and routing platform allows attackers to run malicious code on the system. This is a serious risk because it could be used to take control of ...
9.1
CubeCart Ecommerce Software: Admins Can Execute Server Commands
CVE-2026-45714
An unpatched security issue in CubeCart's email templates, invoices, documents, and contact forms allows any administrator to run commands on the server, potentially leading to data loss or system com...
9.1
CubeCart 6.6.9 and earlier: Authenticated File Upload Risk
CVE-2026-45053
CubeCart's file upload feature allows authorized users to upload malicious files that can be executed by the web server, potentially leading to unauthorized access and control of the website. To prote...
9.1
CubeCart Ecommerce Software: Authenticated Code Execution Risk
CVE-2026-44377
A security issue exists in older versions of CubeCart's email and document features. An attacker with admin access could potentially read sensitive files or create malicious code, which could lead to ...
9.1
Netty: Inbound data mixed with wrong outbound request
DEBIAN-CVE-2026-42584
A bug in the Netty framework could cause incorrect data to be read from a response. This happens when a server sends multiple responses in a specific order. Affected versions of Netty are fixed in 4.2...
9.1
Netty DNS Handler Fails to Validate Domain Names
DEBIAN-CVE-2026-42579
Netty's DNS handler in older versions does not properly check domain names, which can allow attackers to send malicious data. This could lead to security issues if an attacker is able to control the d...
9.1
iControl REST Manager Role Privilege Escalation
CVE-2026-41225
A highly privileged attacker with a Manager role in iControl REST can create configuration objects to run arbitrary commands. This could lead to unauthorized access to sensitive data or system comprom...
8.6