Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 23 May 2026

RSS

132 vulnerabilities published on 23 May 2026

Severity:
Nezha Monitoring: RoleMember can run shell on all monitored servers
GHSA-99gv-2m7h-3hh9 CVE-2026-46716
A Nezha Monitoring user with a 'RoleMember' role can create a scheduled task that runs on all monitored servers, including those in other tenants. This allows an attacker to execute arbitrary commands...
9.9
Dolibarr ERP CRM 7.0.3 allows unauthenticated code execution
CVE-2018-25357
An attacker can send a request to Dolibarr ERP CRM 7.0.3 with malicious code, which can then be executed without needing a password. This means an attacker could potentially access and control the sys...
9.3
userSpice 4.3.24: Unauthenticated Attackers Can Discover Valid Usernames
CVE-2018-25350
UserSpice, a user management system, has a security weakness that lets attackers find valid usernames without logging in. This could be used to guess or find existing accounts. To fix this, update to ...
9.3
Redaxo CMS Mediapool Addon: Authenticated Users Can Upload Malicious Files
CVE-2018-25353
The Mediapool Addon in Redaxo CMS is affected by a security flaw that allows authorized users to upload files with hidden malicious extensions. This could allow attackers to upload and execute harmful...
8.7
Linux Kernel: Fragment Marker Not Propagated Correctly
CVE-2026-43503
A Linux kernel vulnerability has been fixed, which could allow an attacker to write to a read-only file. This issue was found in the way the kernel handled fragment markers in network packets. It has ...
8.8
Edimax BR-6428NS 1.10: Remote Wireless Settings Hack
CVE-2026-9295
A security flaw in the Edimax BR-6428NS 1.10 router allows hackers to remotely access and manipulate the wireless settings. This could lead to unauthorized access to your network and compromise of sen...
7.4
Edimax BR-6428NS Router Buffer Overflow Risk
CVE-2026-9294
A security issue affects Edimax BR-6428NS routers running version 1.10. An attacker could potentially send malicious data to the router, causing it to crash or behave unexpectedly. We recommend updati...
7.4
Firefox and Thunderbird Security Updates Needed
RLSA-2026:19588
Firefox and Thunderbird users need to update their software to fix security issues that could allow hackers to steal data or take control of their computers. These updates are available now, and it's ...
8.8
Wishlist Member plugin for WordPress: Unauthorized Data Modification
CVE-2026-6898
The Wishlist Member plugin for WordPress, used in websites, has a security flaw that could allow attackers with limited access to make changes to sensitive data. This could potentially lead to a compl...
8.8
Wishlist Member Plugin for WordPress Exposes Site to Unauthorized Access
CVE-2026-6897
The Wishlist Member plugin for WordPress, used for membership management, has a security flaw that allows attackers with basic access to make changes to the site. This could lead to a complete takeove...
8.8
WishList Member plugin for WordPress exposes sensitive data and allows site takeover
CVE-2026-6895
The WishList Member plugin for WordPress, used to manage memberships, contains a security flaw that could allow an attacker to access sensitive information and take control of the entire website. This...
8.8
WishList Member plugin for WordPress exposes sensitive data
CVE-2026-6419
Authenticated attackers with Subscriber-level access can steal the plugin's secret key, create administrator accounts, and take over the entire website. Affected users should update the WishList Membe...
8.8
Parse Server: Denial of Service via Client Header Backtracking
GHSA-38m6-82c8-4xfm CVE-2026-47138
An attacker can send a specially crafted request that causes Parse Server to use up a lot of CPU, making it slow or unresponsive. This affects Parse Server deployments that use the default configurati...
8.7
Nezha Monitoring: RoleMember can access internal HTTP responses
GHSA-w4g9-mxgg-j532 CVE-2026-46717
A low-privilege user can read internal HTTP response bodies, potentially accessing sensitive information. This affects the Nezha Monitoring dashboard, which allows a user with the 'RoleMember' role to...
8.5
SIPp 3.6 and earlier crashes or runs malicious code due to oversized input
CVE-2018-25356
SIPp versions 3.6 and earlier have a security flaw that can be exploited by a local attacker to crash the application or run unauthorized code. This can happen when an attacker supplies too much infor...
8.6
Audiograbber 1.83: Malicious Input Can Execute Code
CVE-2018-25355
Audiograbber, a software used to record and rip audio CDs, has a security flaw that allows attackers to execute malicious code on a local computer. This could potentially lead to unauthorized access o...
8.6
10-Strike Network Scanner 3.0 allows malicious code execution
CVE-2018-25345
The 10-Strike Network Scanner 3.0 has a security flaw that can be exploited by attackers. This allows them to run unauthorized code on a computer, potentially causing harm. To protect yourself, update...
8.6
10-Strike Network Inventory Explorer 8.54: Malicious Registration Key Code Execution
CVE-2018-25344
The 10-Strike Network Inventory Explorer software has a security flaw that allows a local attacker to run malicious code with administrator privileges. This can happen if an attacker creates a fake re...
8.6
Joomla! EkRishta 2.10: Unauthenticated SQL Injection Attack
CVE-2018-25351
A security flaw in Joomla! EkRishta 2.10 allows hackers to access sensitive information without needing a login. This is a serious issue because it could allow attackers to steal user passwords and le...
8.8
Joomla! Ek Rishta 2.10 allows attackers to access database info
CVE-2018-25348
An attacker can send a special request to Joomla! Ek Rishta 2.10, allowing them to access sensitive database information. This is a risk because it could give an attacker confidential information abou...
8.8
Smartshop 1 allows attackers to steal sensitive data
CVE-2018-25342
Smartshop 1 has a security flaw that lets attackers access sensitive information without a password. This means they can potentially steal product details and other system data. To protect your data, ...
8.8
Smartshop 1 allows attackers to steal database info
CVE-2018-25341
An attacker can access sensitive information from Smartshop 1's database by sending a special request to the product.php page. This is a serious issue because it could allow unauthorized access to con...
8.8
Smartshop 1 allows attackers to steal user data
CVE-2018-25340
An attacker can use a specific type of malicious input to extract sensitive user data from Smartshop 1, including usernames. This can happen without needing a password. To protect your data, update Sm...
8.8
WooCommerce PayPal Payments plugin for WordPress allows unauthorized order changes
CVE-2026-9284
The WooCommerce PayPal Payments plugin for WordPress has a security issue that allows attackers to manipulate other customers' orders and steal sensitive information. This affects all versions up to 4...
8.2
Linux Kernel: Coalescing Fragments Can Cause Data Corruption
CVE-2026-46300
This issue affects the Linux kernel's networking component. If not fixed, it could allow unauthorized access to encrypted data. To address this, update your Linux kernel to the latest version.
7.8