Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 May 2026
RSS630 vulnerabilities published on 19 May 2026
Severity:
CtrlPanel installer allows hackers to run server commands
CVE-2026-34234
CtrlPanel's web installer in versions 1.1.1 and earlier can be exploited by attackers to run arbitrary commands on the server. This vulnerability is critical for hosting providers using CtrlPanel, as ...
10.0
Malicious Code in @beproduct/nestjs-auth (0.1.2-0.1.19) Can Steal Secrets
GHSA-6xwp-cp5h-q856
CVE-2026-46412
Between May 11 and May 22, 2026, malicious versions of the @beproduct/nestjs-auth package were published on npm. These versions contained code that could steal sensitive information like login tokens,...
10.0
9router: Unauthenticated Remote Code Execution via Unprotected Routes
GHSA-fhh6-4qxv-rpqj
CVE-2026-46339
The 9router software exposes unauthenticated API endpoints that can be used to execute arbitrary OS commands without any prerequisites or credentials. This vulnerability exists because the authenticat...
10.0
HestiaCP Web Terminal Session Format Mismatch Allows Root Access
CVE-2026-43633
HestiaCP versions 1.9.0 to 1.9.4 have a security weakness in the web terminal. Attackers can exploit this weakness to gain full control over a system with the web terminal feature enabled. To protect ...
9.5
Kitty Terminal: Unchecked Arithmetic Allows Remote Code Execution
CVE-2026-33642
A security issue affects Kitty Terminal versions 0.46.2 and below. An attacker can send malicious commands to a Kitty Terminal, potentially allowing them to execute code remotely. To fix this, update ...
9.9
rok Python ProxyShare allows attackers to access internal servers
GHSA-jh67-hwqw-m5r7
CVE-2026-45568
The ProxyShare feature in rok Python allows attackers to bypass security settings and access internal servers by manipulating URL paths. This could lead to unauthorized access to sensitive data or sys...
9.9
Drupal Module Exposes iCal Feeds to Unauthorized Users
DRUPAL-CONTRIB-2026-037
CVE-2026-8495
A module in Drupal allows anyone to access sensitive date fields without permission. This could allow unauthorized users to view or manipulate sensitive information. Update the module to ensure it pro...
9.8
Turborepo allows malicious code execution in untrusted repositories
CVE-2026-45772
GHSA-3qcw-2rhx-2726
Turborepo's build system can run malicious code if you use it in a project from an unknown or untrusted source. This can happen if the project's configuration contains malicious code. To stay safe, up...
7.5
Kopia: Unauthenticated Access via SSH Command Injection
GHSA-2q4c-3mrw-63c3
CVE-2026-45695
GO-2026-5009
Kopia's HTTP server allows unauthenticated access when started without a username or password. An attacker can inject malicious commands into the SSH connection, potentially executing arbitrary code a...
9.8
Kitty Terminal: Malicious Input Can Cause Data Corruption
DEBIAN-CVE-2026-33642
Versions of Kitty terminal below 0.46.2 are vulnerable to data corruption when displaying malicious input. This can happen if an attacker is able to send specific commands to a Kitty terminal, such as...
9.8
Kitty terminal: Malicious code can read or write memory
UBUNTU-CVE-2026-33642
A security issue affects Kitty terminal versions 0.46.2 and below. An attacker can write malicious code to a Kitty terminal to access memory it shouldn't have, potentially leading to security breaches...
9.8
ScadaBR 1.2.0: Hard-Coded Admin Credentials
CVE-2026-8605
ScadaBR's admin credentials are hardcoded, allowing unauthorized access to the SCADA system. This is a serious risk because an attacker can gain full control of the system. Update to a fixed version o...
5.1
ScadaBR 1.2.0: Unauthenticated root access via OS command injection
CVE-2026-8603
An attacker can execute system commands with root privileges on the SCADA system. This could allow unauthorized access and control of the system. Update to the latest version of ScadaBR to fix this vu...
8.7
Panabit PAP-XM320 HTTP Server Authentication Bypass Risk
CVE-2026-36829
The Panabit PAP-XM320's built-in web server has a weakness that could let attackers access it without needing a password. This is because the server checks a password-related cookie in a way that an a...
9.8
hitarth-gg Zenshin URL Command Injection Risk
CVE-2026-37281
The hitarth-gg Zenshin application has a security flaw that could allow an attacker to execute unauthorized system commands. This could potentially lead to data theft, system compromise, or other mali...
9.8
APScheduler JSON and CBOR Deserialization RCE
CVE-2026-31072
APScheduler's JSON and CBOR deserialization features allow attackers to execute malicious code remotely. This can happen if an attacker submits a specially crafted payload to an application using thes...
9.8
LalanaChami Pharmacy Management System: Unauthorized Role Assignment
CVE-2026-31070
The LalanaChami Pharmacy Management System has a security issue that allows anyone to give themselves extra privileges. This could allow unauthorized users to access sensitive information or make chan...
9.8
Scalar Astro v0.1.13 exposes sensitive data to attackers
CVE-2026-30118
The Scalar Astro proxy endpoint can be tricked into sending requests to malicious URLs, potentially exposing sensitive information like authentication cookies. This could allow unauthorized access to ...
9.8
Scalar Proxy allows attackers to execute arbitrary code
CVE-2026-30117
An attacker can upload a malicious file, potentially executing code on your server. This is a serious issue, especially if you're hosting user-uploaded content. Update to the latest version of Scalar ...
9.8
Tyler Identity Local uses default, unchanged admin credentials
CVE-2026-44159
Tyler Identity Local's default admin credentials are not changed before deployment, which means an attacker could gain full access to the system if they know these credentials. This is a concern becau...
9.3
Debian Linux: Unrestricted File Access
DEBIAN-CVE-2026-8956
A security flaw in Debian Linux can allow unauthorized users to access and modify sensitive files. This affects Debian Linux systems and can compromise system integrity. To protect your system, ensure...
9.8
Firefox Integer Overflow in Networking: JAR
CVE-2026-8956
A vulnerability in the Firefox Networking: JAR component can cause the browser to crash or behave unexpectedly. This issue affects Firefox versions prior to 151 and Firefox ESR versions prior to 140.1...
9.8
Apache Camel: Unauthenticated Header Injection via Missing Filtering
CVE-2026-47323
Apache Camel versions 3.18.0 to 4.18.2 have a security issue that allows attackers to inject malicious headers into messages. This can lead to unauthorized code execution or file access. To fix this, ...
9.8
Piotnet Forms for WordPress allows attackers to upload any file type
CVE-2026-4883
The Piotnet Forms plugin for WordPress doesn't properly check the type of files being uploaded, which means an attacker can upload any type of file. This could allow an attacker to execute malicious c...
9.8
Linux Kernel: MAY_BACKLOG Requests Can Cause Busy Errors
CVE-2026-43493
A bug in the Linux kernel's crypto module (pcrypt) could cause a busy error when handling certain requests. This could lead to system instability or crashes. Linux kernel developers have fixed this is...
9.8