Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 18 May 2026

RSS

609 vulnerabilities published on 18 May 2026

Severity:
Azure Local Disconnected Operations Privilege Escalation
CVE-2026-42822
An unauthorized attacker can gain elevated privileges over a network if they exploit a weakness in Azure Local Disconnected Operations. This means they could access sensitive information or make chang...
10.0
Root:npm vm2 Vulnerability: Uncontrolled Memory Access
ROOT-APP-NPM-CVE-2026-44006
The @rootio/vm2 package in Root:npm has a memory access issue that could be exploited by attackers. This could lead to unauthorized data access or system crashes. Update to a fixed version of @rootio/...
10.0
Root:npm vm2 Package Unpatched on Older Versions
ROOT-APP-NPM-CVE-2026-44005
If you're using Root's npm package and haven't updated vm2 recently, you may be at risk of a security issue. This issue has been fixed by Root in newer versions of vm2. We recommend updating to the la...
10.0
Root VM2 Software Allows Unauthorized Access
ROOT-APP-NPM-CVE-2026-43997
A security patch has been released for the Root VM2 software to prevent unauthorized access. This affects users of Root's npm package. To stay secure, update to a patched version of the software as so...
10.0
Dokploy versions 0.26.6 and below allow attackers to execute system commands.
CVE-2026-27130
Dokploy's free, self-hosted Platform as a Service is affected by a security issue. An authenticated attacker can inject malicious system commands by manipulating the application name. To fix this, upd...
9.9
Root:npm vm2: Unpatched Code Execution Risk
ROOT-APP-NPM-CVE-2026-43999
A patch has been released for the vm2 library in Root:npm to prevent malicious code from being executed. This library is used by Root, so it's essential to update to the latest version to ensure the s...
9.9
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-8836
An unauthenticated attacker can execute arbitrary code on Debian Linux systems. This is a significant security risk, as it allows an attacker to take control of the system without needing a password. ...
9.9
lwIP: Unauthenticated Remote Stack Overflow in SNMPv3 Handler
CVE-2026-8836
A remote attacker can cause a stack overflow in the lwIP SNMPv3 handler, potentially leading to a crash or malicious code execution. This affects all systems using lwIP versions up to 2.2.1. To fix th...
9.3
Microsoft Edge (Chromium-based) allows malicious code to run
CVE-2026-45495
A security issue in Microsoft Edge (Chromium-based) could allow hackers to run unauthorized code on a user's device. This could happen if a user visits a malicious website or opens a compromised file....
9.8
SGLangs Scheduler Exposes to Remote Code Execution
CVE-2026-7301 GHSA-gwv6-pq6m-p3rq
The SGLangs scheduler has a default setting that makes it accessible from the internet, allowing hackers to execute malicious code on your system. This can happen if you have the scheduler exposed to ...
9.8
SGLangs multimodal generation runtime allows unauthenticated remote code execution
CVE-2026-7304 GHSA-36m8-w8qf-g76p
A vulnerability in SGLangs allows attackers to run malicious code on a server without being authenticated. This is possible when a specific option is enabled. To stay safe, update SGLangs to the lates...
9.8
Apache Tomcat: Important Security Patch Released for Remote Code Execution
ROOT-APP-MAVEN-CVE-2025-24813
A patch has been released for the Apache Tomcat library that prevents attackers from potentially running unauthorized code on your server. This affects systems running outdated versions of the library...
9.8
Root:npm protobufjs Data Tampering Risk
ROOT-APP-NPM-CVE-2026-41242
The @rootio/protobufjs package in Root:npm has a data tampering risk. This means that an attacker could manipulate data to deceive users. Root has released a patch to fix this issue, and you should up...
9.8
Apache Tomcat AJP Connections Can Be Tricked into Returning Files
BIT-tomcat-2020-1938
When using the Apache JServ Protocol (AJP) with Apache Tomcat, attackers can trick the system into returning sensitive files if they can connect to it. This is a risk if the AJP port is accessible to ...
9.8 KEV
Root VM2 Software Allows Unauthorized Access
ROOT-APP-NPM-CVE-2026-44009
A security patch has been released for Root VM2 software, which fixes a vulnerability that could allow unauthorized access. This affects users who rely on Root VM2 for their operations. To stay secure...
9.8
Root VM2: Unauthenticated Access to Internal Services
ROOT-APP-NPM-CVE-2026-26332
The Root VM2 software had a security issue that allowed unauthorized access to internal services. This could have allowed attackers to access sensitive information or take control of the system. Root ...
9.8
Root VM2 Package Allows Unauthorized Access
ROOT-APP-NPM-CVE-2026-44008
A security patch has been released for Root's VM2 package. If not updated, attackers could potentially gain unauthorized access to Root systems. Update to the latest version of the package to ensure s...
9.8
Root:npm @rootio/vm2 Unpatched Virtual Machine Code Execution
ROOT-APP-NPM-CVE-2026-24781
A security patch has been released for the Root:npm @rootio/vm2 package. If left unpatched, this vulnerability could allow attackers to execute malicious code within virtual machines. Update to the la...
9.8
Root VM2 Package Security Patch
ROOT-APP-NPM-CVE-2026-24118
A security patch has been released for Root's VM2 package. This patch fixes a security issue that could have allowed unauthorized access to Root's systems. To stay secure, update to the latest version...
9.8
Malicious Code in Mistralai 2.4.6 on PyPI
GHSA-wx9m-wx4f-4cmg
A malicious version of the Mistralai software, version 2.4.6, has been uploaded to the PyPI package repository. This version contains code that can download and run a malicious script on Linux systems...
9.6
Dify versions 1.14.1 and prior allow attackers to access internal data
CVE-2026-41948
Dify versions 1.14.1 and prior have a security flaw that allows attackers to access internal data they shouldn't be able to see. This happens because the software doesn't properly check URLs, making i...
9.3
ChromaDB Python project: Unauthenticated code execution
CVE-2026-45829 GHSA-f4j7-r4q5-qw2c
The ChromaDB Python project, version 1.0.0 or later, is vulnerable to a security threat. An attacker can send malicious data to the database, allowing them to run any code on the server without needin...
9.3
Root Sanitize HTML Package Security Patch
ROOT-APP-NPM-CVE-2026-44990
A security patch has been released for the @rootio/sanitize-html package used by Root. This update addresses a security issue that could potentially allow malicious code to be executed. To ensure secu...
9.3
Unauthorized Access to Protected Features in Creartia's ICMS Software
CVE-2026-4320
Creartia's ICMS software has a security issue that could allow an attacker to access parts of the system they shouldn't be able to access. This could happen if someone manipulates the way the system r...
9.3
DumbAssets through 1.0.11 allows unauthenticated deletion of files
CVE-2026-45230
An attacker can delete any file on the server without needing a password, which could cause the server to stop working. This is a concern because it could allow an attacker to delete important files t...
8.8