VulDB Updates Updates
- CVE-2026-10066 | Shibby Tomato up to 1.28 UPS Service tomatoups.cgi sub_9068 stack-based overflow (EUVD-2026-33341)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability, which was classified as critical, has been found in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer. This vulnerability is documented as CVE-2026-10066. The attack can be initiated remotely. There is not any exploit available. This project is superseded by FreshTomato.
- CVE-2026-43917 | dokploy up to 0.19.0 authorization (GHSA-f8wj-5c4w-frhg / EUVD-2026-33361)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability, which was classified as critical, has been found in dokploy up to 0.19.0. This issue affects some unknown processing. Performing a manipulation results in authorization bypass. This vulnerability is known as CVE-2026-43917. Remote exploitation of the attack is possible. No exploit is available.
- CVE-2026-9090 | Casdoor up to 2.362.0 x.509 Certificate buildSpCertificateStore signature verification (EUVD-2026-32941)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability classified as problematic was found in Casdoor up to 2.362.0. This affects the function buildSpCertificateStore of the component x.509 Certificate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The identification of this vulnerability is CVE-2026-9090. The attack may be launched remotely. There is no exploit available.
- CVE-2026-45660 | Statamic CMS up to 5.73.21/6.18.0 URL Validation server-side request forgery (GHSA-pf9c-ch8r-2958 / EUVD-2026-33365)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability identified as critical has been detected in Statamic CMS up to 5.73.21/6.18.0. Affected by this issue is some unknown functionality of the component URL Validation Handler. The manipulation leads to server-side request forgery. This vulnerability is listed as CVE-2026-45660. The attack may be initiated remotely. There is no available exploit. You should upgrade the affected component.
- CVE-2026-6824 | CP Plus CP-UNR-108F1 Hardware 1.0 Device Backend cross site scripting (EUVD-2026-33363)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability classified as problematic has been found in CP Plus CP-UNR-108F1 Hardware, CP-UNR-108F1 Web and CP-UNR-108F1 System 1.0. Affected by this vulnerability is an unknown functionality of the component Device Backend. This manipulation causes cross site scripting. This vulnerability is registered as CVE-2026-6824. Remote exploitation of the attack is possible. No exploit is available.
- CVE-2026-47274 | mcdope pam_usb up to 0.8.x on Linux Environment Variable src/tmux.c uncontrolled search path (GHSA-pp29-w28g-r9h9 / EUVD-2026-32651)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability, which was classified as problematic, has been found in mcdope pam_usb up to 0.8.x on Linux. Affected by this issue is some unknown functionality of the file src/tmux.c of the component Environment Variable Handler. The manipulation leads to uncontrolled search path. This vulnerability is documented as CVE-2026-47274. The attack needs to be performed locally. There is not any exploit available. It is advisable to upgrade the affected component.
- CVE-2026-44660 | UltraJSON up to 5.12.0 ujson.dump memory leak (GHSA-c38f-wx89-p2xg / EUVD-2026-32663)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability classified as problematic was found in UltraJSON up to 5.12.0. This vulnerability affects the function ujson.dump. The manipulation results in memory leak. This vulnerability is cataloged as CVE-2026-44660. The attack may be launched remotely. There is no exploit available. Upgrading the affected component is advised.
- CVE-2026-44713 | mcdope pam_usb up to 0.8.6 on Linux socket-path src/tmux.c popen TMUX os command injection (GHSA-822m-whrh-vrj8 / EUVD-2026-32657)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability categorized as critical has been discovered in mcdope pam_usb up to 0.8.6 on Linux. This vulnerability affects the function popen of the file src/tmux.c of the component socket-path. Executing a manipulation of the argument TMUX can lead to os command injection. This vulnerability is handled as CVE-2026-44713. It is possible to launch the attack on the local host. There is not any exploit available. It is advisable to upgrade the affected component.
- CVE-2026-42941 | Danelec MacGregor Voyage Data Recorder G4e up to 5.249 Password Change default credentials (EUVD-2026-33395)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability identified as critical has been detected in Danelec MacGregor Voyage Data Recorder G4e up to 5.249. The impacted element is an unknown function of the component Password Change Handler. Performing a manipulation results in use of default credentials. This vulnerability is identified as CVE-2026-42941. The attack can only be performed from the local network. There is not any exploit available. You should upgrade the affected component.
- CVE-2026-44247 | volcano-sh volcano up to 1.12.3/1.13.2/1.14.1 Webhook Endpoint resource consumption (GHSA-8wxp-xxp2-rcgx / EUVD-2026-32666)by vuldb.com on May 30, 2026 at 5:00 am
A vulnerability, which was classified as problematic, was found in volcano-sh volcano up to 1.12.3/1.13.2/1.14.1. Impacted is an unknown function of the component Webhook Endpoint. Such manipulation leads to resource consumption. This vulnerability is documented as CVE-2026-44247. The attack requires being on the local network. There is not any exploit available. You should upgrade the affected component.
- CVE-2026-46402 | Microsoft UFO 3.0.1-4-ge2626659 logs/ task_name path traversal (GHSA-whcg-fgpx-76f2 / EUVD-2026-32674)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability marked as critical has been reported in Microsoft UFO 3.0.1-4-ge2626659. This vulnerability affects unknown code of the file logs/. The manipulation of the argument task_name leads to path traversal. This vulnerability is referenced as CVE-2026-46402. Remote exploitation of the attack is possible. No exploit is available.
- CVE-2026-9793 | Keycloak on Red Hat signature verification (EUVD-2026-32707)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability was found in Keycloak on Red Hat. It has been classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in improper verification of cryptographic signature. This vulnerability is reported as CVE-2026-9793. The attack is possible to be carried out remotely. No exploit exists.
- CVE-2026-9804 | KubeVirt virt-exportserver link following (EUVD-2026-32748)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability, which was classified as critical, was found in KubeVirt. The affected element is an unknown function of the component virt-exportserver. Such manipulation leads to link following. This vulnerability is documented as CVE-2026-9804. The attack can be executed remotely. There is not any exploit available.
- CVE-2026-44358 | Espressif shared-github-dangerjs up to 1.0.0 entrypoint.sh pull_request_target uncontrolled search path (GHSA-wm3p-pv54-6w73 / EUVD-2026-32908)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability categorized as problematic has been discovered in Espressif shared-github-dangerjs up to 1.0.0. The impacted element is the function pull_request_target of the file entrypoint.sh. The manipulation results in uncontrolled search path. This vulnerability is known as CVE-2026-44358. Attacking locally is a requirement. No exploit is available. It is advisable to upgrade the affected component.
- CVE-2026-47759 | TinyMCE up to 5.11.0/6.8.6/7.9.2/8.5.0 data-mce-href/data-mce-src/data-mce-style cross site scripting (GHSA-q742-qvgc-gc2f / EUVD-2026-32921)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability marked as problematic has been reported in TinyMCE up to 5.11.0/6.8.6/7.9.2/8.5.0. Affected is an unknown function. Performing a manipulation of the argument data-mce-href/data-mce-src/data-mce-style results in cross site scripting. This vulnerability was named CVE-2026-47759. The attack may be initiated remotely. There is no available exploit. It is suggested to upgrade the affected component.
- CVE-2026-35671 | thorsten phpMyFAQ up to 4.1.2 userId privileges assignment (GHSA-xvp4-phqj-cjr3 / EUVD-2026-32902)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability labeled as critical has been found in thorsten phpMyFAQ up to 4.1.2. The affected element is an unknown function. The manipulation of the argument userId results in incorrect privilege assignment. This vulnerability was named CVE-2026-35671. The attack may be performed from remote. There is no available exploit. The affected component should be upgraded.
- CVE-2026-44796 | nautobot up to 2.4.32/3.1.1 /dcim/interfaces/rename/ use_regex find resource consumption (EUVD-2026-32975)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability has been found in nautobot up to 2.4.32/3.1.1 and classified as problematic. This vulnerability affects the function use_regex of the file /dcim/interfaces/rename/. Performing a manipulation of the argument find results in resource consumption. This vulnerability is identified as CVE-2026-44796. The attack can be initiated remotely. There is not any exploit available. The affected component should be upgraded.
- CVE-2026-44543 | rancher local-path-provisioner up to 0.0.35 privileges management (GHSA-7fxv-8wr2-mfc4 / EUVD-2026-32954)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability was found in rancher local-path-provisioner up to 0.0.35. It has been classified as critical. Affected is an unknown function. This manipulation causes improper privilege management. This vulnerability is registered as CVE-2026-44543. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component is recommended.
- CVE-2026-47673 | honojs hono up to 4.12.20 improper authorization (GHSA-f577-qrjj-4474 / EUVD-2026-32927)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability labeled as critical has been found in honojs hono up to 4.12.20. This issue affects some unknown processing. The manipulation results in improper authorization. This vulnerability is known as CVE-2026-47673. It is possible to launch the attack remotely. No exploit is available. The affected component should be upgraded.
- CVE-2026-45296 | OpenReplay up to 1.25.x Authenticated API app_apikey access control (EUVD-2026-32971)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability described as critical has been identified in OpenReplay up to 1.25.x. This impacts the function app_apikey of the component Authenticated API. Executing a manipulation can lead to improper access controls. This vulnerability is handled as CVE-2026-45296. The attack can be executed remotely. There is not any exploit available. Upgrading the affected component is recommended.
- CVE-2026-44794 | Nautobot up to 2.4.32/3.1.1 authorization (EUVD-2026-32955)by vuldb.com on May 30, 2026 at 4:46 am
A vulnerability, which was classified as critical, was found in Nautobot up to 2.4.32/3.1.1. This affects an unknown part. Such manipulation leads to missing authorization. This vulnerability is referenced as CVE-2026-44794. It is possible to launch the attack remotely. No exploit is available. You should upgrade the affected component.
- CVE-2020-17103 | Microsoft Windows up to Server 2019 Cloud Files Mini Filter Driver GreenPlasma/MiniPlasma privileges management (Nessus ID 316497)by vuldb.com on May 30, 2026 at 4:36 am
A vulnerability classified as critical has been found in Microsoft Windows. Impacted is an unknown function of the component Cloud Files Mini Filter Driver. The manipulation leads to improper privilege management. This vulnerability is documented as CVE-2020-17103. The attack needs to be performed locally. There is not any exploit available. To fix this issue, it is recommended to deploy a patch.
- CVE-2026-45498 | Microsoft Defender Antimalware Platform UnDefend denial of service (EUVD-2026-31102 / Nessus ID 316484)by vuldb.com on May 30, 2026 at 4:35 am
A vulnerability categorized as problematic has been discovered in Microsoft Defender Antimalware Platform. The affected element is an unknown function. Executing a manipulation can lead to denial of service. This vulnerability is handled as CVE-2026-45498. It is possible to launch the attack on the local host. Additionally, an exploit exists.
- CVE-2026-41091 | Microsoft Malware Protection Engine RedSun link following (EUVD-2026-31101 / Nessus ID 316462)by vuldb.com on May 30, 2026 at 4:34 am
A vulnerability classified as critical was found in Microsoft Malware Protection Engine. This impacts an unknown function. Such manipulation leads to link following. This vulnerability is listed as CVE-2026-41091. The attack must be carried out locally. In addition, an exploit is available.
- CVE-2026-33825 | Microsoft Defender Antimalware Platform prior 4.18.26030.3011 BlueHammer insufficient granularity of access control (Nessus ID 306740)by vuldb.com on May 30, 2026 at 4:33 am
A vulnerability classified as critical has been found in Microsoft Defender Antimalware Platform. Affected by this issue is some unknown functionality. The manipulation leads to insufficient granularity of access control. This vulnerability is referenced as CVE-2026-33825. The attack can only be performed from a local environment. Furthermore, an exploit is available. It is recommended to upgrade the affected component.
- CVE-2026-42951 | Danelec MacGregor Voyage Data Recorder G4e up to 5.249 Password Hash Handler insufficiently protected credentials (EUVD-2026-33396)by vuldb.com on May 30, 2026 at 3:48 am
A vulnerability, which was classified as problematic, has been found in Danelec MacGregor Voyage Data Recorder G4e up to 5.249. This affects an unknown part of the component Password Hash Handler Handler. Performing a manipulation results in insufficiently protected credentials. This vulnerability is reported as CVE-2026-42951. The attacker must have access to the local network to execute the attack. No exploit exists. It is advisable to upgrade the affected component.
- CVE-2026-46372 | SillyTavern up to 1.17.x User Interface /api/search/searxng server-side request forgery (EUVD-2026-33397)by vuldb.com on May 30, 2026 at 3:48 am
A vulnerability was found in SillyTavern up to 1.17.x. It has been rated as critical. Impacted is an unknown function of the file /api/search/searxng of the component User Interface. This manipulation causes server-side request forgery. The identification of this vulnerability is CVE-2026-46372. It is possible to initiate the attack remotely. There is no exploit available. Upgrading the affected component is advised.
- CVE-2026-44611 | Danelec MacGregor Voyage Data Recorder G4e up to 5.249 Password Length weak password hash (EUVD-2026-33398)by vuldb.com on May 30, 2026 at 3:48 am
A vulnerability categorized as problematic has been discovered in Danelec MacGregor Voyage Data Recorder G4e up to 5.249. The affected element is an unknown function of the component Password Length Handler. Such manipulation leads to password hash with insufficient computational effort. This vulnerability is referenced as CVE-2026-44611. The attack needs to be initiated within the local network. No exploit is available. It is advisable to upgrade the affected component.
- CVE-2026-42929 | Danelec MacGregor Voyage Data Recorder G4e up to 5.249 hard-coded credentials (EUVD-2026-33400)by vuldb.com on May 30, 2026 at 3:48 am
A vulnerability classified as critical was found in Danelec MacGregor Voyage Data Recorder G4e up to 5.249. Affected by this issue is some unknown functionality. Such manipulation leads to hard-coded credentials. This vulnerability is documented as CVE-2026-42929. The attack requires being on the local network. There is not any exploit available. Upgrading the affected component is advised.
- CVE-2026-40425 | Danelec MacGregor Voyage Data Recorder G4e up to 5.249 file access (EUVD-2026-33403)by vuldb.com on May 30, 2026 at 3:48 am
A vulnerability was found in Danelec MacGregor Voyage Data Recorder G4e up to 5.249. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to files or directories accessible. The identification of this vulnerability is CVE-2026-40425. The attack needs to be done within the local network. There is no exploit available. It is recommended to upgrade the affected component.




