Common Vulnerabilities and Exposures (CVE)

CVE-2026-41900

May 8, 2026 12:54:17 UTC

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbit...

CVE-2026-43940

May 8, 2026 12:52:47 UTC

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied widge...

CVE-2026-8069

May 8, 2026 12:51:41 UTC

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured...

CVE-2026-8149

May 8, 2026 12:51:03 UTC

A vulnerability in Legion of the Bouncy Castle Inc. BC-FJA BC-FIPS on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w. This issue affects BC-FJA: from 2.1.0 through 2.1.2.

CVE-2026-44916

May 8, 2026 12:50:35 UTC

In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.

CVE-2026-44927

May 8, 2026 12:49:45 UTC

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

CVE-2026-44928

May 8, 2026 12:49:01 UTC

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

CVE-2026-8076

May 8, 2026 12:48:22 UTC

Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with...

CVE-2026-8153

May 8, 2026 12:47:12 UTC

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.

CVE-2026-3318

May 8, 2026 12:46:32 UTC

Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter allows redirection because the web application accepts a URL as...

CVE-2026-7650

May 8, 2026 12:45:42 UTC

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-download` shortcode in all versions up to, and including, 1.32.17. This is due to insufficient ...

CVE-2026-6213

May 8, 2026 12:45:06 UTC

A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be expl...

CVE-2026-43283

May 8, 2026 12:41:46 UTC

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle dma_free_coherent() in error path takes priv->rx_buf.alloc_len as the dma handle. This would lead to improper un...

CVE-2026-43280

May 8, 2026 12:41:45 UTC

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise When user provides a bogus pat_index value through the madvise IOCTL, the xe_pat_index_get_coh...

CVE-2026-43279

May 8, 2026 12:41:44 UTC

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode before the actual playback, we blindly assume ...