Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 May 2026
RSS709 vulnerabilities published on 21 May 2026
Severity:
BoxLite: Malicious Code Can Modify Protected Files
GHSA-g6ww-w5j2-r7x3
CVE-2026-46695
BoxLite's protection against unauthorized file modifications is weakened, allowing malicious code to alter sensitive data. This can lead to code execution on the host, compromising user credentials an...
10.0
Altium 365 SearchService: Unauthenticated Access to Search Data
CVE-2026-9152
A security issue exists in Altium 365's SearchService, allowing an attacker to access and modify search results without needing a login. This could reveal sensitive information and affect search resul...
10.0
Windows-MCP: Unauthenticated PowerShell Access via HTTP
GHSA-vrxg-gm77-7q5g
The Windows-MCP server exposes PowerShell to unauthenticated users via HTTP. This allows an attacker to execute commands as the Windows user running Windows-MCP. To fix this, update to the latest vers...
9.9
Mattermost: Malicious Auth Token Exposure
CVE-2026-4858
Mattermost versions 11.6.x, 11.5.x, and 10.11.x are vulnerable to a security issue that allows an authenticated user to access sensitive information. This issue affects users who have system admin pri...
9.9
Netatalk CNID Daemon Remote Code Execution
CVE-2026-44050
The CNID daemon in Netatalk versions 2.0.0 through 4.4.2 has a security flaw that allows a remote attacker to gain elevated access to the system or crash it. This affects users who run Netatalk, a fil...
9.9
Debian Linux: Unprivileged users can gain elevated privileges
DEBIAN-CVE-2026-44050
A vulnerability in Debian Linux allows an attacker with normal user privileges to gain full control over the system. This could be exploited by a malicious user to install malware, delete or modify fi...
9.9
BookingPress Pro plugin allows malicious file uploads on WordPress sites
CVE-2026-6960
The BookingPress Pro plugin for WordPress is vulnerable to malicious file uploads, which could allow an attacker to potentially execute code remotely. This issue affects all versions up to 5.6. To pro...
9.8
Fission router exposes internal functions to public access
GHSA-3g33-6vg6-27m8
CVE-2026-46614
The Fission router has a security issue that allows anyone who can reach it to call any function, even if it's not meant to be accessed publicly. This could allow unauthorized access to sensitive func...
9.8
Apache Fory: Untrusted Data Can Be Used to Attack the System
CVE-2026-48207
Apache Fory is a tool that can deserialize data, which is the process of taking data and converting it back into its original form. If an attacker can control the data being deserialized, they may be ...
9.8
Cockpit: Unauthenticated remote code execution via web browser
RLSA-2026:7383
Cockpit, a web-based server administration tool, allows attackers to run malicious code on a server without a password. This can happen if a user with malicious intentions visits a specially crafted w...
9.8
Cockpit: Unauthenticated remote code execution via web browser
RLSA-2026:7384
Cockpit, a web-based server administration tool, allows unauthorized users to execute malicious code on a server via the web browser. This could lead to server compromise and data loss. Update Cockpit...
9.8
Trend Micro Apex One Management Console Malicious Code Upload Risk
CVE-2025-71211
A vulnerability in the Trend Micro Apex One management console could allow a malicious attacker to upload and run code on affected installations. This is a concern for customers who expose their conso...
9.8
Trend Micro Apex One Management Console Allows Remote Code Upload
CVE-2025-71210
A security weakness in the Trend Micro Apex One management console lets hackers upload and run malicious code on affected systems. If your console's IP address is exposed to the internet, consider lim...
9.8
Divi Form Builder plugin allows attackers to create admin accounts
CVE-2026-5118
The Divi Form Builder plugin for WordPress has a security issue that allows unauthenticated attackers to create administrator accounts. This is a concern because an attacker with an admin account can ...
9.8
Linux kernel: IPv6 packet handling security risk
CVE-2026-43501
A security issue in the Linux kernel's IPv6 packet handling code could allow an attacker to write outside the intended memory area, potentially leading to a system crash or data corruption. This issue...
9.8
Apache HTTP Server Remote Code Execution Vulnerability
BELL-CVE-2026-7210
Apache HTTP Server versions 2.4.52 and earlier have a vulnerability that could allow an attacker to execute arbitrary code on a server. This is a serious risk because an attacker could take control of...
9.8
Adobe Flash Player allows arbitrary code execution
Adobe Flash Player has a vulnerability that can allow hackers to run malicious code on your computer. This could lead to your system being compromised, and your data being stolen or altered. Update Ad...
9.8
Apache HTTP Server Remote Code Execution in Windows
BELL-CVE-2026-3593
A vulnerability in the Apache HTTP Server software for Windows allows attackers to execute malicious code on affected servers. This could happen if a user visits a specially crafted website or clicks ...
9.8
Adobe Acrobat PDF Parsing Code Execution Vulnerability
BELL-CVE-2025-14179
Adobe Acrobat users may be at risk of having malicious code executed on their computers if they open a specially crafted PDF file. This could allow an attacker to take control of the user's system. Ad...
9.8
Avada Builder plugin for WordPress allows attackers to run code remotely
CVE-2026-6279
The Avada Builder plugin for WordPress allows attackers to run code on a website without needing a password. This is a serious security risk because attackers can do anything they want with the websit...
9.8
Boxlite: Malicious Images Can Write to Host Files
GHSA-f396-4rp4-7v2j
CVE-2026-46703
A vulnerability in Boxlite allows attackers to create malicious images that can write arbitrary content to any path on the host. This could lead to further attacks, such as remote code execution on th...
9.6
Twig: PHP Code Injection via Malformed Template Names
GHSA-7p85-w9px-jpjp
CVE-2026-46633
A security flaw in Twig allows attackers to inject malicious PHP code into templates. This can lead to unauthorized access to sensitive data and potentially allow attackers to execute code on the serv...
9.3
Hulumi Policies: GitHub OIDC Trust Policy Bypass via AWS Condition Operators
GHSA-q2f7-m237-v562
Versions of Hulumi Policies before 1.3.2 did not properly check some AWS IAM condition operators, which could allow an attacker to bypass security checks. This vulnerability has been fixed in version ...
9.3
WP Directory Kit SQL Injection Risk: Data Exposure
CVE-2026-39531
WP Directory Kit versions 1.5.0 and earlier are vulnerable to a SQL injection attack, which could allow an attacker to access sensitive data. This is a serious issue because it could lead to unauthori...
9.3
Hulumi Policies: GitHub OIDC Trust Policy Bypass via AWS Conditions
GHSA-q2f7-m237-v562
Versions of Hulumi Policies before 1.3.2 may allow attackers to bypass security checks. This affects users who rely on Hulumi Policies for GitHub Actions security. To fix this, update Hulumi Policies ...
9.1