Skip to content
Threat Feed

May 2026 (30)

high threat

code-projects Project Management System SQL Injection Vulnerability (CVE-2026-9584)

A SQL injection vulnerability (CVE-2026-9584) exists in code-projects Project Management System 1.0 within the chk.php file of the Login component, allowing a remote attacker to execute arbitrary SQL commands.

Project Management System 1.0 sql-injection cve-2026-9584 web-application injection
2r 1t 1c
high advisory

CVE-2026-5260: libgnutls Heap Overread via Short Premaster Secret

A remote attacker can trigger a heap overread in libgnutls by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, potentially leading to information disclosure.

libgnutls heap-overread information-disclosure tls cve
2r 1c
high threat

CVE-2026-42013: gnutls Certificate Validation Bypass via Oversized SAN

A vulnerability in gnutls (CVE-2026-42013) allows a remote attacker to bypass certificate validation by providing an oversized Subject Alternative Name (SAN), causing the validation process to fall back to the Common Name (CN) field, potentially leading to spoofing or man-in-the-middle attacks.

gnutls certificate validation spoofing man-in-the-middle CVE-2026-42013
2r 1t 1c
medium threat

GnuTLS Certificate Spoofing Vulnerability (CVE-2026-42012)

CVE-2026-42012 describes a vulnerability in GnuTLS where a remote attacker can spoof legitimate services or intercept sensitive information by presenting a specially crafted certificate with URI or SRV SANs, causing the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN).

GnuTLS vulnerability certificate spoofing tls
2r 1t 1c
high advisory

Cryptojacking Campaign Abusing ScreenConnect and SEO Poisoning

An active cryptojacking campaign uses SEO poisoning, AI chatbot interactions, and ScreenConnect abuse to target high-performance PCs, aiming to maximize GPU mining yield and establish persistent remote access for potential data theft or ransomware attacks.

ScreenConnect cryptojacking seo-poisoning dll-sideloading
2r 1t 1i
medium advisory

JeecgBoot Improper Access Control Vulnerability (CVE-2026-9580)

JeecgBoot up to version 3.9.1 is vulnerable to improper access control in the LoginController.selectDepart function, allowing remote attackers to bypass intended restrictions.

JeecgBoot cve access control
1r 1t 1c
high advisory

XWiki Platform Livetable Vulnerability Allows Password Hash Reconstruction

A vulnerability in XWiki Platform allows an attacker to reconstruct password hashes using 768 requests through the `LiveTableResults` macro, impacting versions prior to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17.

XWiki Platform xwiki credential-access password-hash-disclosure cve-2026-48048
1r
high advisory

itsourcecode Student Transcript Processing System 1.0 SQL Injection Vulnerability (CVE-2026-9575)

A SQL injection vulnerability exists in itsourcecode Student Transcript Processing System 1.0 in the `/admin/modules/class/index.php?view=view` component; the vulnerability is triggered by manipulating the `ID` argument, potentially enabling remote attackers to execute arbitrary SQL commands.

Student Transcript Processing System 1.0 sql-injection cve web-application
2r 1t 1c
high threat

itsourcecode Student Transcript Processing System SQL Injection Vulnerability (CVE-2026-9574)

itsourcecode Student Transcript Processing System 1.0 is vulnerable to SQL injection via the studentId/cid parameter in the /admin/modules/student/trans.php file, allowing remote attackers to manipulate database queries.

exploited Student Transcript Processing System 1.0 sql-injection cve-2026-9574 itsourcecode web-application
2r 1t 1c
high advisory

itsourcecode Student Transcript Processing System SQL Injection Vulnerability (CVE-2026-9573)

CVE-2026-9573 is a SQL injection vulnerability in itsourcecode Student Transcript Processing System 1.0, allowing a remote attacker to execute arbitrary SQL commands by manipulating the studentId parameter in the /admin/modules/student/index.php?view=view file.

Student Transcript Processing System 1.0 sql injection cve-2026-9573 web application
2r 1t 1c
high advisory

code100x Mobile API Authentication Bypass Vulnerability (CVE-2026-8890)

code100x Mobile API contains an authentication bypass vulnerability (CVE-2026-8890) allowing unauthenticated attackers to impersonate arbitrary users by crafting a JSON payload in the 'g' HTTP header, skipping identity header validation and granting unauthorized access to course data.

code100x Mobile API authentication-bypass mobile-api cve-2026-8890 credential-access privilege-escalation
2r 2t
high advisory

CVE-2026-4051: IBM Engineering Lifecycle Management Remote Code Execution

IBM Engineering Lifecycle Management 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 through Interim Fix 001 could allow an attacker with administrative privileges to execute remote code due to an exposed method that is not properly restricted, potentially leading to complete system compromise.

Engineering Lifecycle Management 7.0.3 +2 cve rce ibm
2r 1t 1c
critical advisory

CVE-2026-3660: IBM Engineering Lifecycle Management Unauthenticated Remote Access

IBM Engineering Lifecycle Management versions 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 through Interim Fix 001 are vulnerable to an unauthenticated remote attacker who can update server property files, leading to unauthorized access to the application.

Engineering Lifecycle Management cve cve-2026-3660 ibm unauthenticated access property file modification
2r 1t 1c
medium advisory

CVE-2026-3603: IBM Engineering Lifecycle Management XXE Vulnerability

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 are vulnerable to XML external entity injection (XXE), allowing an authenticated attacker to expose sensitive information or consume memory resources.

Engineering Lifecycle Management 7.0.3 +2 cve xxe injection
2r 1t 1c
high advisory

CVE-2026-8834: IBM HTTP Server Buffer Overflow Vulnerability

IBM HTTP Server 8.5 and 9.0 are vulnerable to a heap-based buffer overflow, allowing a privileged, authenticated user to execute arbitrary code or cause a denial of service.

HTTP Server 8.5 +1 buffer overflow remote code execution denial of service
2r 3t 1c
high advisory

Autodesk 3ds Max Memory Corruption Vulnerability via Malformed WRL File (CVE-2026-7452)

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can trigger a memory corruption vulnerability (CVE-2026-7452) allowing arbitrary code execution in the context of the application.

3ds Max cve memory corruption autodesk rce
2r 1t 1c
high advisory

Dumping Account Hashes via Built-In Commands on macOS

This rule detects the execution of macOS built-in commands such as `defaults`, `mkpassdb`, and `dscl` used by adversaries to dump user account hashes for credential access and lateral movement.

Elastic Defend credential-access macos endpoint
3r 1t
high advisory

CVE-2026-9170: IBM WebSphere Application Server and Liberty Improper Input Validation Vulnerability

IBM WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 are vulnerable to denial of service and potential remote code execution due to improper input validation as described in CVE-2026-9170.

WebSphere Application Server +2 vulnerability websphere rce dos
2r 2t 1c
medium threat

CVE-2026-8856 - IBM HTTP Server Denial of Service Vulnerability

IBM HTTP Server 8.5 and 9.0 is vulnerable to a denial of service (DoS) in configurations where an attacker possesses write access to server configuration files, as tracked by CVE-2026-8856.

HTTP Server 8.5 +1 cve-2026-8856 dos ibm
2r 1t 1c
high threat

CVE-2026-8855: IBM HTTP Server RCE and DoS via TLS Mutual Authentication

IBM HTTP Server 8.5 and 9.0 are vulnerable to remote code execution and denial of service in configurations utilizing TLS mutual authentication (client authentication).

HTTP Server 8.5 +1 cve rce dos tls ibm
2r 2t 1c
medium advisory

CVE-2026-8854 - IBM HTTP Server mod_mem_cache Denial-of-Service

IBM HTTP Server 8.5 and 9.0 are vulnerable to a denial-of-service (DoS) attack due to a flaw in the optional `mod_mem_cache` module that can be triggered remotely.

HTTP Server 8.5 +1 cve dos denial-of-service
2r 1t 1c
medium advisory

CVE-2026-8835: IBM HTTP Server Invalid Pointer Dereference Vulnerability

IBM HTTP Server versions 8.5 and 9.0 are susceptible to an invalid pointer dereference, potentially allowing a privileged, authenticated user to expose sensitive information or cause a denial of service.

HTTP Server 8.5 +1 cve pointer dereference dos information disclosure
2r 1t 1c
medium threat

CVE-2026-8620: IBM WebSphere Application Server HTTP Request Smuggling Vulnerability

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 are vulnerable to HTTP request smuggling due to inconsistent interpretation of HTTP requests, potentially leading to unauthorized access and data manipulation.

WebSphere Application Server +3 http-request-smuggling websphere cve-2026-8620
2r 1t 1c
high advisory

CVE-2026-7454 - Autodesk 3ds Max Memory Corruption Vulnerability via Malicious WRL File

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can trigger CVE-2026-7454, a memory corruption vulnerability allowing arbitrary code execution in the context of the current process.

3ds Max cve memory corruption autodesk
2r 1t 1c
high advisory

CVE-2026-7451 - Autodesk 3ds Max Out-of-Bounds Write Vulnerability via Malicious TIF File

CVE-2026-7451 is an out-of-bounds write vulnerability in Autodesk 3ds Max that can be exploited via a maliciously crafted TIF file, potentially leading to a crash, data corruption, or arbitrary code execution.

3ds Max cve out-of-bounds write tif memory corruption
2r 1t 1c
critical advisory

CVE-2026-8633: IBM WebSphere Application Server RCE via Crafted Request

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request (CVE-2026-8633).

WebSphere Application Server +3 rce websphere cve-2026-8633
2r 1t 1c
high advisory

Typebot Stored XSS via Rating Block Custom Icon

Typebot is vulnerable to stored cross-site scripting (XSS) due to the rating block's custom icon feature, which accepts arbitrary HTML/SVG via the `customIcon.svg` field without sanitization. When a malicious typebot is imported or crafted by a workspace collaborator, the payload executes in the builder's DOM context, bypassing the `isUnsafe` Web Worker sandbox that protects Script blocks during preview, allowing session hijacking and privilege escalation within the builder application.

@typebot.io/js xss stored-xss web-application typebot
2r 4t 1c
high threat

Das Parking Management System 6.2.0 SQL Injection Vulnerability (CVE-2026-9552)

A SQL injection vulnerability (CVE-2026-9552) exists in Das Parking Management System 6.2.0 within the Search API Endpoint, allowing a remote attacker to execute arbitrary SQL commands by manipulating the 'Value' argument.

exploited Parking Management System 停车场管理系统 6.2.0 sql-injection cve-2026-9552 web-application
2r 1t 1c
high advisory

Das Parking Management System 停车场管理系统 SQL Injection Vulnerability (CVE-2026-9551)

A SQL injection vulnerability exists in Das Parking Management System 停车场管理系统 version 6.2.0 allowing a remote attacker to execute arbitrary SQL commands by manipulating the Value argument in the xp_cmdshell function of the ParkingRecord/ExportParkingRecords API endpoint.

Parking Management System 停车场管理系统 6.2.0 cve-2026-9551 sql-injection web-application
2r 2t 1c
high advisory

Acrel EEMS Enterprise Power Operation and Maintenance Cloud Platform Path Traversal Vulnerability (CVE-2026-9550)

A path traversal vulnerability (CVE-2026-9550) exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0, allowing remote attackers to access sensitive files by manipulating the path argument in the /SubstationWEBV2/app/..;/main/upfile component.

EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0 path-traversal web-application cve
2r 1t 1c