Latest Security Vulnerabilities
Thursday April 23, 2026
Unclassified
CVE-2026-41988 UUID Buffer Write Vulnerability (v3/5/6) before 14.0.0 uuidjsCVE-2026-41179 Rclone RC ops/fsinfo Unauth CmdExec via WebDAV 1.48.0-1.73.5
CVE-2026-3361 WP Store Locator 2.2.261 Stored XSS via 'wpsl_address' Meta
CVE-2026-3007 Koollab LMS XSS in Courselet (v5.3.2) Enables Arbitrary JS
CVE-2026-1923 Stored XSS via id param in Social Rocket <=1.3.4.2 (WP)
CVE-2026-6878 Sandbox Escalation in ByteDance verl 0.7.0
CVE-2026-40529 SQLi in CMS ALAYA 7.4.1.4 or earlier via admin interface
CVE-2026-41211 Vite+ 0.1.17 Path Traversal via downloadPackageManager
CVE-2026-41679 CVE-2026-41679 Paperclip RCE via API chain pre-2026.416.0
And others...
Froxlor
CVE-2026-41228 Froxlor <2.3.6 API def_language Path Traversal ExecCVE-2026-41231 Froxlor <2.3.6: ExportCron chown RCE via Path Traversal
CVE-2026-41230 Froxlor DNS Injection via DomainZones::add() (pre-2.3.6)
CVE-2026-41229 Froxlor 2.3.6+ PHP code exec via unescaped privileged_user
CVE-2026-41232 Froxlor email alias validation flaw (before 2.3.6) allows domain spoofing
CVE-2026-41233 Froxlor <=2.3.5 Domain Attribution Bypass via adminid Validation
Wednesday April 22, 2026
Linux Kernel
CVE-2026-31462 Linux Kernel amdgpu PASID Reuse Interrupt PrivEscCVE-2026-31463 Linux Kernel: iomap folio access flaw from i_blkbits granularity mis-match
CVE-2026-31468 Linux Kernel vfio/pci Double-Free via DMA-BUF on Error Path
CVE-2026-31469 Linux Kernel: virtio_net UAF on dst_ops when IFF_XMIT_DST_RELEASE cleared
CVE-2026-31470 Linux Kernel TDX Guest Quote Buffer Length Validation Mitigates OOB Read
CVE-2026-31471 Linux Kernel IPTFS mode_data dangling ptr in clone_state allocation failure
CVE-2026-31478 Linux Kernel ksmbd SMB2 offset bug in response buffer
CVE-2026-31479 Linux Kernel: DRM/xe VM Rebind Unwind Tracking Vulnerability
CVE-2026-31483 Linux Kernel s390 Spectre: Unbounded Syscall Dispatch Table Access
And others...
GitLab
CVE-2026-3254 GitLab CE/EE 18.11: Auth User Load Unauth Content via Mermaid SandboxCVE-2026-5262 GitLab <=18.11.1 Storybook token disclosure to unauthenticated user
CVE-2025-0186 GitLab CE/EE DoS via crafted endpoint (v10.6-18.9.5/18.10-18.10.3/18.11-18.11.0)
CVE-2025-3922 GitLab CE/EE DoS via GraphQL API before 18.9.6, 18.10.4, 18.11.1
CVE-2026-1660 GitLab CE/EE DoS from Issue Import Input Validation up to 18.11.1
CVE-2026-5816 GitLab CE/EE XSS via Path Validation (18.10<18.10.4, 18.11<18.11.1)
CVE-2026-5377 GitLab <=18.11.1 Improper ACL in Issue Render
CVE-2026-6515 GitLab Virtual Registry Credential Escalation 18.218.11.1
CVE-2026-4922 GitLab unauth GraphQL CSRF (v < 18.9.6 / 18.10.4 / 18.11.1)
And others...
Powerdns Recursor
CVE-2026-33259 Use-After-Free in ISC BIND RPZ Recursor allowing RPZ data corruption or crashCVE-2026-33600 BIND RPZ Null Pointer Deref Causes DoS
CVE-2026-33258 Unbound NSEC3 Negative Cache DoS via Crafted Zone
CVE-2026-33261 DNSSEC NSECNSEC3 Zone Transition DOS in BIND
VMware Spring Framework
CVE-2026-22746 Spring Security 5.7-7.0 DAO Auth Timing Attack Bypass via Disabled/LockedCVE-2026-22747 Spring Security 7.0.0-7.0.4 SubjectX500PrincipalExtractor X.509 CN flaw impersonation
CVE-2026-22748 Spring Security 6/7 JWT Decoder Missing Token Validator (CVE-2026-22748)
CVE-2026-22753 Spring Security 7.0.0-7.0.4 Matcher Security Bypass
CVE-2026-22754 Spring Security 7.0.07.0.4: Auth ByPass via Servlet Path
Unclassified
CVE-2026-41988 UUID Buffer Write Vulnerability (v3/5/6) before 14.0.0 uuidjsCVE-2026-41179 Rclone RC ops/fsinfo Unauth CmdExec via WebDAV 1.48.0-1.73.5
CVE-2026-3361 WP Store Locator 2.2.261 Stored XSS via 'wpsl_address' Meta
CVE-2026-3007 Koollab LMS XSS in Courselet (v5.3.2) Enables Arbitrary JS
CVE-2026-1923 Stored XSS via id param in Social Rocket <=1.3.4.2 (WP)
CVE-2026-6878 Sandbox Escalation in ByteDance verl 0.7.0
CVE-2026-40529 SQLi in CMS ALAYA 7.4.1.4 or earlier via admin interface
CVE-2026-41211 Vite+ 0.1.17 Path Traversal via downloadPackageManager
CVE-2026-41679 CVE-2026-41679 Paperclip RCE via API chain pre-2026.416.0
And others...
Red Hat Enterprise Linux (RHEL)
CVE-2026-6846 Heap Buffer Overrun in binutils XCOFF linker leads to LPECVE-2026-6862 RedHat libefiboot local DoS via invalid device path node length
CVE-2026-6845 binutils readelf DoS via crafted ELF file
CVE-2026-6861 Emacs SVG CSS Memory Corruption CVE-2026-6861
Powerdns
CVE-2026-33254 DNSdist Memory Exhaustion DoS via DoQ/DoH3 ConnectionsCVE-2026-33593 DNSCrypt CRASH: Divide-by-0 via Crafted DNS Query
CVE-2026-33595 Excessive Memory Allocation via DoQ/DoH3 Error Responses in CoreDNS

