Common Vulnerabilities and Exposures (CVE)

CVE-2026-44928

May 8, 2026 07:16:05 UTC

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

CVE-2026-44927

May 8, 2026 07:15:54 UTC

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

CVE-2026-44916

May 8, 2026 06:38:37 UTC

In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.

CVE-2026-44742

May 8, 2026 06:25:34 UTC

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

CVE-2023-46453

May 8, 2026 06:19:11 UTC

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, this affects version 4....

CVE-2025-69599

May 8, 2026 06:08:35 UTC

RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific...

CVE-2026-8149

May 8, 2026 06:01:40 UTC

A vulnerability in Legion of the Bouncy Castle Inc. BC-FJA BC-FIPS on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w. This issue affects BC-FJA: from 2.1.0 through 2.1.2.

CVE-2026-4935

May 8, 2026 06:00:04 UTC

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

CVE-2026-8069

May 8, 2026 05:57:22 UTC

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured...

CVE-2025-69690

May 8, 2026 05:56:44 UTC

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only avail...

CVE-2025-67888

May 8, 2026 05:52:30 UTC

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. Th...

CVE-2025-67887

May 8, 2026 05:52:28 UTC

1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier...

CVE-2025-67886

May 8, 2026 05:52:25 UTC

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier ...

CVE-2025-69691

May 8, 2026 05:51:51 UTC

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-55449

May 8, 2026 05:40:04 UTC

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.