| | CVE-2026-42833 | Microsoft | critical | 9.1 | 0.1%
| | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) al… | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-42838 | Microsoft | medium | 5.4 | 0.0%
| | Improper neutralization of special elements in output used by a downstream component ('injection') i… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-42891 | Microsoft | medium | 6.5 | 0.0%
| | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-42893 | Microsoft | high | 7.4 | 0.0%
| | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot … | May 12, 2026 | May 13, 2026 |
| | CVE-2026-42898 | Microsoft | critical | 9.9 | 0.1%
| | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) al… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-42899 | Microsoft | high | 7.5 | 2.4%
| | Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attack… | May 12, 2026 | Jul 15, 2026 |
| | CVE-2026-44277 | Fortinet | critical | 9.8 | 0.1%
| | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0… | May 12, 2026 | May 28, 2026 |
| | CVE-2026-44278 | Fortinet | low | 2.3 | 0.0%
| | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4… | May 12, 2026 | May 16, 2026 |
| | CVE-2026-44279 | Fortinet | medium | 5.5 | 0.1%
| | An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2… | May 12, 2026 | Jun 26, 2026 |
| | CVE-2026-23820 | HPE | high | 7.2 | — | | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant coul… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-23821 | HPE | high | 7.2 | — | | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-23823 | HPE | high | 7.2 | — | | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authent… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-44867 | HPE | high | 7.2 | 0.2%
| | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Op… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-44868 | HPE | high | 7.2 | 0.2%
| | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Op… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-44869 | HPE | high | 7.2 | 0.2%
| | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Op… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-44872 | HPE | high | 7.2 | 0.3%
| | A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 O… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-44871 | HPE | high | 7.2 | 0.1%
| | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the … | May 12, 2026 | May 14, 2026 |
| | CVE-2026-8449 | Red Hat | medium | — | — | | No description is available for this CVE. | May 12, 2026 | May 12, 2026 |
| | CVE-2026-42268 | Red Hat | medium | 4.9 | 0.1%
| | A flaw was found in ModSecurity, an open-source web application firewall (WAF). This vulnerability o… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-43476 | Red Hat | medium | — | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
iio: chemical: sps30_i2c: fix bu… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43486 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel. The `contpte_ptep_set_access_flags()` function, responsible fo… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43479 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's USB network device driver (lan78xx). A redundant function cal… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43489 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's liveupdate mechanism. When a `retrieve()` operation fails, th… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43487 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's `libata-core` module. This vulnerability arises from issues w… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43477 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel. Incorrectly configuring Variable Refresh Rate (VRR) timings be… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43485 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's nouveau/gsp module. This issue involved the frequent triggeri… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43488 | Red Hat | low | 5.5 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
usb: xhci: Prevent interrupt sto… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43484 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's MultiMediaCard (MMC) core. Concurrent updates to bitfield fla… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43482 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's sched_ext component. If a task is preempted between the scx_c… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43483 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem, specifically wi… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43480 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel, specifically within the ASoC AMD audio driver. This vulnerabil… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43478 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's ASoC rt1011 codec component. An incorrect helper function use… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-43481 | Red Hat | medium | 6.4 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
net-shapers: don't free reply sk… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-2725 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in Gerrit. An authenticated attacker with force push permissions on a secondary bra… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-7168 | Red Hat | medium | 5.3 | 0.1%
| ✓ Fix | A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authent… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-46300 | Red Hat | high | 7.8 | 0.0%
| ✓ Fix | In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: preserve shared-fra… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-41957 | F5 | high | 8.8 | — | | An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-I… | May 13, 2026 | May 14, 2026 |
| | CVE-2026-42919 | F5 | medium | 6.7 | — | | A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrativ… | May 13, 2026 | May 14, 2026 |
| | CVE-2026-42924 | F5 | high | 8.7 | — | | An authenticated attacker with the Resource Administrator or Administrator role can create SNMP conf… | May 13, 2026 | May 14, 2026 |
| | CVE-2026-42058 | F5 | medium | 4.3 | — | | An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information … | May 13, 2026 | May 14, 2026 |
| | CVE-2026-42406 | F5 | high | 8.7 | — | | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke… | May 13, 2026 | May 14, 2026 |
| | CVE-2026-42930 | F5 | high | 8.7 | — | | When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be a… | May 13, 2026 | May 14, 2026 |
| | CVE-2026-40701 | Red Hat | medium | 4.8 | 0.0%
| | A flaw was found in the ngx_http_ssl_module module of NGINX. When the ssl_verify_client directive is… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-42934 | Red Hat | medium | 4.8 | 0.0%
| | A flaw was found in the ngx_http_charset_module module of NGINX. When charset, source_charset, chars… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-44432 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | A flaw was found in urllib3, an HTTP client library for Python. This vulnerability allows a remote a… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-44431 | Red Hat | medium | 5.9 | 0.0%
| | A flaw was found in urllib3, an HTTP client library for Python. When using the low-level API via `Pr… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-44665 | Red Hat | medium | 6.1 | 0.0%
| | A flaw was found in fast-xml-builder, a software component used to create XML documents from JSON da… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-44664 | Red Hat | medium | 6.1 | 0.0%
| | A flaw was found in fast-xml-builder. The software, which builds XML from JSON, incorrectly sanitize… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-44572 | Red Hat | medium | 5.9 | 0.0%
| | A flaw was found in Next.js. An external client could exploit this vulnerability by sending a x-next… | May 13, 2026 | May 13, 2026 |
| | CVE-2026-20916 | F5 | high | 8.1 | 0.4%
| | An authenticated iControl REST user with low privileges can create or modify arbitrary files through… | May 13, 2026 | Jun 29, 2026 |