Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 14 May 2026
RSS942 vulnerabilities published on 14 May 2026
Severity:
utcp-cli Allows Malicious Commands to Run on Server
CVE-2026-45369
GHSA-33p6-5jxp-p3x4
A security issue in utcp-cli allows an attacker to execute any command on the server. This could allow them to access or modify sensitive data. To protect against this, make sure you're running the la...
10.0
Cisco SD-WAN Controller allows unauthorized access
CVE-2026-20182
A security issue in Cisco's SD-WAN Controller lets attackers access the system without a password. This means they could potentially take control of the system and make changes to the network. To fix ...
10.0
KEV
vm2 Node.js Sandbox Escape Vulnerability
CVE-2026-45411
GHSA-248r-7h7q-cr24
A vulnerability in the vm2 sandbox allows attackers to execute arbitrary commands on the host system. This affects all versions of vm2 prior to 3.11.3. To protect your system, update to version 3.11.3...
9.8
Fleet software installer vulnerable to malicious package execution
GHSA-9vcr-g537-3w5v
CVE-2026-26191
Fleet's software installer pipeline is affected, which could allow a malicious software package to run arbitrary commands on managed endpoints. This is a risk because a hacker could upload a package t...
6.0
Akilli Commerce E-Commerce Website Session Hijacking Risk
CVE-2026-2347
A security weakness in Akilli Commerce's E-Commerce Website allows an attacker to access a customer's session, potentially allowing them to make unauthorized purchases or changes. This affects version...
9.8
Akilli Commerce Website: Blind SQL Injection via Malformed SQL
CVE-2025-11024
Akilli Commerce's E-commerce website has a security flaw that allows attackers to manipulate database queries. This could lead to sensitive information being stolen or altered. Update to version 4.5.0...
9.8
InfusedWoo Pro plugin for WordPress: Unauthorized Access to Admin Accounts
CVE-2026-6510
The InfusedWoo Pro plugin for WordPress is vulnerable to unauthorized access to admin accounts. This means that an attacker can gain access to any account, including the administrator account, without...
9.8
Career Section plugin for WordPress allows attackers to upload malicious files
CVE-2026-6271
The Career Section plugin for WordPress, in versions up to 1.7, allows unauthenticated attackers to upload files that could potentially contain malicious code. This could allow attackers to execute co...
9.8
Burst Statistics plugin for WordPress allows unauthorized access
CVE-2026-8181
An attacker can use a known administrator username to pretend to be that administrator and gain access to the WordPress site. This can lead to unauthorized changes or actions on the site. Website admi...
9.8
Google Chrome Use After Free Sandbox Escape
CVE-2026-8580
A vulnerability in Google Chrome allowed a malicious website to potentially escape the security sandbox, potentially leading to unauthorized access to your computer. This issue has been fixed in versi...
9.6
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-8580
Debian Linux systems are at risk of being hacked by malicious users who can execute unauthorized code on the system. This could allow an attacker to gain full control of the system. To protect your sy...
9.6
Debian Linux: Unpatched System Updates Leave Systems Open to Attack
DEBIAN-CVE-2026-8511
Debian Linux users are at risk if they haven't applied recent system updates. This means that attackers can exploit known security weaknesses. To stay secure, ensure that all system updates have been ...
9.6
Google Chrome UI Sandbox Escape via Malicious Web Page
CVE-2026-8511
Google Chrome versions prior to 148.0.7778.168 have a security issue that could allow an attacker to escape the browser's security sandbox. This could potentially allow the attacker to access sensitiv...
9.6
SoundCloud Client allows malicious track titles to run code locally
CVE-2026-44482
A security issue was found in the SoundCloud Client software. If a user plays a SoundCloud track with a malicious title, it could potentially run code on the user's computer. This has been fixed in ve...
9.6
Gradient 1.1.0: Unauthorized Access to Continuous Integration System
CVE-2026-44592
The Gradient continuous integration system allows anyone to register as a worker without a password, giving them access to all jobs and the ability to upload arbitrary files. This is a security risk b...
9.4
FlowiseAI Evaluator Allows Cross-Workspace Data Access
GHSA-wxrr-jp8m-qq7f
A security issue in FlowiseAI's Evaluator feature allows unauthorized access to data across different workspaces. This could lead to sensitive information being compromised. To protect your data, upda...
9.4
FlowiseAI: Malicious Evaluator Can Take Over Other Workspaces
GHSA-wxrr-jp8m-qq7f
CVE-2026-46480
A security flaw in FlowiseAI allows an attacker with permission to create or update an Evaluator to take control of Evaluators in other workspaces. This can happen when an attacker creates or updates ...
9.4
FlowiseAI: Malicious Data Can Access Other Workspaces
GHSA-mq53-pc65-wjc4
A vulnerability in FlowiseAI allows attackers to access and manipulate data from other workspaces. This can happen when an attacker sends malicious data to the system, potentially leading to unauthori...
9.4
FlowiseAI: Cross-Workspace Evaluation Data Exposure
GHSA-mq53-pc65-wjc4
CVE-2026-46479
A security issue in FlowiseAI allows unauthorized access to data from other workspaces. This can happen when creating or updating an evaluation. To fix this, FlowiseAI developers should ensure that on...
9.4
FlowiseAI: DatasetRow data can be taken from other workspaces
GHSA-7j65-65cr-6644
CVE-2026-46478
A bug in the FlowiseAI software allows an attacker to access and modify data from other workspaces. This could lead to unauthorized access to sensitive information. To fix this issue, FlowiseAI develo...
9.4
FlowiseAI: DatasetRow data can be stolen from other workspaces
GHSA-7j65-65cr-6644
A bug in FlowiseAI's DatasetRow feature allows an attacker to access and modify data from other workspaces. This could happen if a user with access to one workspace is tricked into updating a DatasetR...
9.4
FlowiseAI: Malicious Data Can Be Added Across Workspaces
GHSA-5h9v-837x-m97r
A security issue exists in the FlowiseAI dataset feature, where an attacker can create or update datasets in any workspace, not just their own. This allows unauthorized access to sensitive data. To fi...
9.4
FlowiseAI: Dataset create+update allows cross-workspace data takeover
GHSA-5h9v-837x-m97r
CVE-2026-46477
FlowiseAI's dataset feature allows unauthorized access to datasets across different workspaces. This means an attacker could access sensitive data they shouldn't have access to. To fix this, update th...
9.4
FlowiseAI: Custom Template Data Can Be Stolen Between Workspaces
GHSA-728h-4mwj-f2p4
CVE-2026-46476
FlowiseAI's Custom Template feature has a security issue. This means that data from one workspace can be accessed and stolen by users from other workspaces. To fix this, FlowiseAI's developers need to...
9.4
FlowiseAI: CustomTemplate data takeover from unauthorized workspace
GHSA-728h-4mwj-f2p4
An issue has been found in the CustomTemplate feature of FlowiseAI that allows an attacker to access and modify data from other workspaces. This is a security risk because it could allow unauthorized ...
9.4