9.8

CVSS3.1

CVE-2026-7567 - Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before pro…

📅 Published: May 1, 2026, 9:26 a.m. 🔄 Last Modified: May 1, 2026, 9:26 a.m.

7.5

CVSS3.1

CVE-2026-42402 - Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts th…

📅 Published: May 1, 2026, 8:54 a.m. 🔄 Last Modified: May 1, 2026, 8:54 a.m.

7.5

CVSS3.1

CVE-2026-42403 - Apache Neethi: Circular Policy Reference Infinite Loop

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, l…

📅 Published: May 1, 2026, 8:38 a.m. 🔄 Last Modified: May 1, 2026, 8:38 a.m.

5.4

CVSS3.1

CVE-2026-40201 -

@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.

📅 Published: May 1, 2026, 8:36 a.m. 🔄 Last Modified: May 1, 2026, 8:40 a.m.

8.4

CVSS4.0

CVE-2026-7584 - Arbitrary Code Execution via Unsafe Deserialization in LabOne Q

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names from the serialized data without any validation of the target…

📅 Published: May 1, 2026, 7:21 a.m. 🔄 Last Modified: May 1, 2026, 7:21 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here