Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 20 May 2026

RSS

755 vulnerabilities published on 20 May 2026

Severity:
WP Swings Gift Cards For WooCommerce Pro allows uploading malicious files
CVE-2026-45444
An attacker can upload malicious files to a WooCommerce store using the WP Swings Gift Cards For WooCommerce Pro plugin. This could allow them to compromise the store's security or disrupt its operati...
10.0
Cisco Secure Workload Internal API Privilege Escalation
CVE-2026-20223
A vulnerability in Cisco Secure Workload's internal APIs could allow an unauthorized attacker to access sensitive resources and make changes with administrator privileges. This could happen if an atta...
10.0
Unbound DNS Server versions 1.25.0 and earlier: Cache Poisoning via DNS Spoofing
CVE-2026-42960
The Unbound DNS Server, up to version 1.25.0, can be tricked into caching fake DNS information by an attacker. This could lead to incorrect DNS results for users. To fix this, update to version 1.25.1...
5.7
Debian Linux: Unprivileged users can gain root access
DEBIAN-CVE-2026-42960
A security issue in Debian Linux allows unprivileged users to gain elevated privileges, potentially allowing them to access sensitive areas of the system or execute malicious code. This affects all De...
10.0
Twig Template Sandbox Bypass in Versions 2.16.x and 3.9.0 to 3.25.x
DEBIAN-CVE-2026-24425
Certain versions of Twig, a templating engine, allow attackers to bypass security restrictions and execute arbitrary code when rendering templates. This affects websites that use affected versions of ...
9.9
Twig Sandbox Bypass in Template Rendering
CVE-2026-24425
Twig templates, used in web applications, can be exploited by attackers to execute arbitrary code if a custom source policy is used. This can happen if an attacker can manipulate the template renderin...
8.7
HP Linux Printing Software Privilege Escalation Risk
DEBIAN-CVE-2026-8631
The HP Linux Printing Software has a potential weakness that could allow unauthorized users to gain extra permissions or run malicious code. This could happen if the software is sent a specially desig...
9.8
HP Linux Imaging and Printing Software Escalation of Privileges Risk
CVE-2026-8631
The HP Linux Imaging and Printing Software may be vulnerable to attacks that allow unauthorized access to sensitive data or system functions. This could happen if an attacker sends specially crafted p...
9.3
Taiko AG1000-01A SMS Alert Gateway Authentication Bypass
CVE-2026-9141
An attacker can access sensitive settings and disrupt the Taiko AG1000-01A SMS Alert Gateway's monitoring and control functions without a password. This is a concern because it could lead to unauthori...
9.3
Taiko AG1000-01A SMS Gateway Exposes Administrative Credentials
CVE-2026-9139
The Taiko AG1000-01A SMS Gateway versions 7.3 and 8 contain a security flaw where sensitive login information is hardcoded into the device's web interface. This makes it possible for unauthorized user...
9.3
NornicDB Bolt Server Listens on All Network Interfaces
GHSA-2hp7-65r3-wv54
A bug in NornicDB's Bolt server causes it to listen on all network interfaces instead of the specified address. This allows unauthorized access to the graph database on local networks. To fix, update ...
9.8
Nornicdb exposes database to network devices without a fix
CVE-2026-42072 GO-2026-4967
If you're using Nornicdb version 1.0.42 or earlier, your graph database is accessible to other devices on the same network. This is because the database is set to accept connections from any device, u...
9.8
Apache HTTP Server Unrestricted File Upload on Windows
BELL-CVE-2026-42258
A vulnerability in the Apache HTTP Server for Windows allows an attacker to upload malicious files, potentially leading to arbitrary code execution. This affects Apache HTTP Server installations on Wi...
9.8
BIND 9 DNS-over-HTTPS can crash or leak memory
CVE-2026-3593
A security issue in BIND 9's DNS-over-HTTPS feature can cause the software to crash or leak memory, potentially leading to a denial-of-service attack. This affects BIND 9 versions 9.20.0 through 9.20....
9.8
HCL BigFix SM uses outdated base images, increasing exploitation risk
CVE-2025-31973
The HCL BigFix Service Management application uses outdated or insecure base images, which can introduce known vulnerabilities. This makes the application environment more susceptible to exploitation....
9.8
Unbound DNSSEC Validator Denial of Service and Code Execution
DEBIAN-CVE-2026-33278
A bug in the DNSSEC validator of Unbound can cause the program to crash or run malicious code. This can happen if an attacker controls a signed DNS zone and sends a specially crafted query to a vulner...
9.8
Unbound DNSSEC Validator Allows Remote Code Execution
CVE-2026-33278
Unbound DNSSEC validation software has a vulnerability that could allow hackers to crash the system or execute malicious code. This is a serious issue because it could be exploited by anyone who contr...
9.1
Apache HTTP Server Cross-Site Scripting (XSS) in Error Pages
BELL-CVE-2026-43493
Apache HTTP Server versions 2.4.52 and earlier contain a vulnerability that allows attackers to inject malicious code into error pages, potentially allowing them to steal sensitive information or take...
9.8
Boost plugin for WordPress vulnerable to malicious cookie injection.
CVE-2026-7637
The Boost plugin for WordPress has a security flaw that could allow hackers to inject malicious code into your website if they can trick a user into accepting a certain cookie. This only happens if yo...
9.8
NVIDIA Triton Inference Server: Integer Overflow Risk in DALI Backend
CVE-2026-24214
The NVIDIA Triton Inference Server's DALI backend has a vulnerability that could allow an attacker to execute malicious code, manipulate data, or make the system unavailable. This affects systems usin...
9.8
NVIDIA Triton Inference Server DALI backend out-of-bounds read risk
CVE-2026-24213
An attacker could read sensitive data or execute malicious code on your server if they find this vulnerability. This affects the NVIDIA Triton Inference Server, which is used for machine learning task...
9.8
NVIDIA Triton Inference Server: Authentication Bypass Leads to Code Execution
CVE-2026-24207
An attacker can bypass authentication in NVIDIA Triton Inference Server, potentially allowing them to execute malicious code, access sensitive data, or disrupt the system. This affects any organizatio...
9.8
NVIDIA Triton Inference Server authentication bypass risk
CVE-2026-24206
The NVIDIA Triton Inference Server has a security weakness that could allow an attacker to bypass its normal security checks. This could lead to an attacker gaining more access or control than they sh...
9.8
NVIDIA TRT-LLM RPC Testing Allows Code Execution
CVE-2026-24163
NVIDIA's TRT-LLM software has a security issue in its RPC testing feature. An attacker could potentially take control of the system, disrupt its normal operation, or access sensitive data. NVIDIA shou...
9.8
NVIDIA TRT-LLM: Deserialization Vulnerability Allows Code Execution
CVE-2026-24142
NVIDIA's TRT-LLM software contains a vulnerability that could allow attackers to execute malicious code, tamper with data, and potentially access sensitive information. This could happen if a user ope...
9.8