Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 17 May 2026
RSS395 vulnerabilities published on 17 May 2026
Severity:
Debian Linux: Remote Code Execution in Samba
DEBIAN-CVE-2026-8721
Debian Linux users who use Samba for file sharing may be at risk of remote code execution attacks. This means an attacker could potentially take control of a vulnerable system. Users should update the...
9.8
Perl Crypt::OpenSSL::PKCS12 truncates passwords with embedded NULLs
CVE-2026-8721
Perl's Crypt::OpenSSL::PKCS12 module, used for secure password handling, incorrectly truncates passwords that contain NULL characters. This can lead to reduced security for passwords that include spec...
9.8
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-8507
Debian Linux systems are affected. An attacker can remotely execute code on a vulnerable system without needing a password. This can lead to unauthorized access and data theft. Users should update the...
9.8
Perl Crypt::OpenSSL::PKCS12: Large File Parsing Risk
CVE-2026-8507
Perl's Crypt::OpenSSL::PKCS12 module is vulnerable to a security risk when parsing large files. This could allow an attacker to potentially execute malicious code on your system. Update to the latest ...
9.8
Peugeot Music 1.0 allows attackers to upload malicious files
CVE-2018-25335
The Peugeot Music WordPress plugin is vulnerable to a file upload issue. This means attackers can upload malicious files without needing a password, which could lead to security problems. To stay safe...
9.3
GitBucket 4.23.1 allows attackers to execute arbitrary system commands
CVE-2018-25332
GitBucket users are at risk of unauthorized code execution. Attackers can use weak secret tokens and upload malicious files to execute system commands. Update to a patched version to prevent this risk...
9.3
ACL Analytics versions 11.x - 13.0.0.579 allow attackers to run malicious commands
CVE-2018-25320
Some versions of ACL Analytics have a security weakness that could allow attackers to run their own commands on the system, potentially gaining control. This means that sensitive data could be accesse...
9.3
h2o-3 JAR Handler Import Vulnerability to Remote Deserialization
CVE-2026-8751
An attacker can remotely exploit a security flaw in h2o-3's JAR Handler, allowing them to potentially take control of your system. This affects versions up to 7402. We recommend updating to the latest...
5.5
Adenhq Hive 0.11.0 Path Traversal Vulnerability
CVE-2026-8757
Adenhq Hive versions up to 0.11.0 contain a vulnerability that allows attackers to access unauthorized files on the server. This could potentially lead to sensitive data being compromised. Update to t...
5.5
WordPress AI Engine Plugin allows unauthorized admin access
CVE-2026-8719
The WordPress AI Engine plugin has a security flaw that lets attackers with lower-level accounts gain full administrator access. This is a concern because it allows unauthorized users to make changes ...
8.8
VX Search 10.6.18: Malicious Input Can Crash the Application
CVE-2018-25328
A vulnerability in VX Search 10.6.18 allows attackers to crash the application by sending a specially crafted input file. This could potentially allow an attacker to execute malicious code, but only i...
8.6
Allok AVI Converter 2.6.1217: Local Code Execution through Text File
CVE-2018-25323
A security flaw in Allok AVI Converter 2.6.1217 allows an attacker with access to the computer to run malicious code by pasting a specially crafted text file into the software. This can lead to unauth...
8.6
Allok Fast AVI MPEG Splitter 1.2 can run malicious code when given a special license name
CVE-2018-25322
A security issue in Allok Fast AVI MPEG Splitter 1.2 allows an attacker to run unauthorized code on a local computer. This could potentially be used to access or modify sensitive data. Update to the l...
8.6
Net::Statsd::Tiny for Perl allows malicious metric injection
CVE-2026-46720
If you're using an old version of Net::Statsd::Tiny for Perl, an attacker could inject malicious data into your metrics. This could lead to incorrect or misleading data. Update to version 0.3.8 or lat...
8.2
Zechat 1.5 allows unauthenticated database information extraction
CVE-2018-25339
Zechat 1.5 has a security weakness that lets attackers get sensitive database information without needing a password. This could happen if someone enters a specific type of input into the chat softwar...
8.8
Zechat 1.5 Hashtag Parameter SQL Injection Risk
CVE-2018-25338
Zechat 1.5 is affected. Attackers can extract database information without logging in. Update to a secure version of Zechat to fix this issue.
8.8
Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 allows unauthorized database access
CVE-2018-25333
An attacker can access sensitive information and bypass security checks without a password by submitting malicious data through the login form. This affects the Nordex N149/4.0-4.5 Wind Turbine Web Se...
8.8
EkRishta Joomla Extension Allows Malicious Code Injection
CVE-2018-25330
The EkRishta extension for Joomla has security flaws that allow hackers to inject malicious code into user profiles and manipulate database queries. This can lead to unauthorized access to sensitive i...
8.8
rootio-linux: Unpatched Systems at Risk of Root Access
ROOT-OS-DEBIAN-12-CVE-2026-46300
The rootio-linux package for Root:Debian:12 was left unpatched, leaving systems open to unauthorized access. This could allow an attacker to gain control of your system, potentially leading to data th...
7.8
rootio-linux: Unauthorized access to sensitive system data
ROOT-OS-DEBIAN-11-CVE-2026-46333
A security patch has been released for rootio-linux, a software package used by Root. This patch fixes a vulnerability that could allow unauthorized access to sensitive system data. Root users should ...
7.8
qs.stringify with 'comma' and 'encodeValuesOnly' throws error on null or undefined
DEBIAN-CVE-2026-8723
When using 'qs.stringify' with 'arrayFormat: 'comma'' and 'encodeValuesOnly: true', it may throw an error if the array contains null or undefined values. This can happen when trying to serialize data ...
7.8
Vercel AI up to 3.0.97: Remote OS Command Injection Risk
CVE-2026-8767
A vulnerability in Vercel AI's automation feature allows attackers to execute malicious system commands remotely. This could potentially lead to unauthorized access or data modification. Vercel users ...
1.3
WordPress Plugin WP with Spritz 1.0 allows unauthorized access to files
CVE-2018-25329
A security flaw in the WordPress Plugin WP with Spritz 1.0 allows anyone to access sensitive files on your website without needing a password. This could potentially expose important information like ...
8.7
Google Drive for WordPress allows unauthorized access to sensitive files
CVE-2018-25326
An attacker can access sensitive files, such as configuration files, without authentication by exploiting a weakness in the way Google Drive for WordPress handles file requests. This could potentially...
8.7
Woocommerce CSV Importer Deletes Sensitive Files
CVE-2018-25325
A security issue in Woocommerce CSV Importer allows any registered user to delete files on your website. This can happen if an attacker tricks a registered user into submitting a special filename. To ...
8.7