Common Vulnerabilities and Exposures (CVE)

CVE-2026-33007

May 4, 2026 17:32:48 UTC

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to versi...

CVE-2026-33006

May 4, 2026 17:32:47 UTC

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVE-2026-31431

May 4, 2026 17:32:46 UTC

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in opera...

CVE-2026-29169

May 4, 2026 17:32:38 UTC

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case fo...

CVE-2026-24072

May 4, 2026 17:32:36 UTC

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this is...

CVE-2026-23918

May 4, 2026 17:32:35 UTC

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2025-47405

May 4, 2026 17:32:25 UTC

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

CVE-2026-42092

May 4, 2026 17:30:46 UTC

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configu...

CVE-2026-42091

May 4, 2026 17:24:47 UTC

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unco...

CVE-2026-42088

May 4, 2026 17:21:27 UTC

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the o...

CVE-2026-42796

May 4, 2026 17:19:43 UTC

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization....

CVE-2025-47404

May 4, 2026 17:18:50 UTC

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

CVE-2026-42087

May 4, 2026 17:18:02 UTC

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) ...

CVE-2025-47403

May 4, 2026 17:17:18 UTC

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

CVE-2026-42086

May 4, 2026 17:15:59 UTC

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which all...