Microsoft will turn on hotpatch security updates by default for all eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API, beginning with the May 2026 Windows security update. [...]
A vulnerability, which was classified as problematic, has been found in HCL Sametime 12.0.21 on Android. This affects an unknown part of the component Application Log Handler. This manipulation causes sensitive information in log files.
This vulnerability is registered as CVE-2026-21791. The attack needs to be launched locally. No exploit is available.
A vulnerability classified as problematic was found in NextScripts Plugin up to 4.4.6 on WordPress. Affected by this issue is the function nxs_fbembed of the component Shortcode Handler. The manipulation of the argument snapFB results in cross site scripting.
This vulnerability is cataloged as CVE-2026-3228. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Wpmet MetForm Pro Plugin up to 3.9.6 on WordPress. Affected by this vulnerability is an unknown functionality of the component Quiz Feature. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-1261. The attack may be initiated remotely. There is no available exploit.
A vulnerability described as problematic has been identified in unitecms Unlimited Elements for Elementor Plugin up to 2.0.5 on WordPress. Affected is an unknown function of the component Form Submission Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-2724. The attack can be launched remotely. No exploit exists.
A vulnerability marked as critical has been reported in ASSA ABLOY Visionline up to 1.32. This impacts an unknown function. Performing a manipulation results in incorrect default permissions.
This vulnerability is identified as CVE-2026-3315. The attack is only possible with local access. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Apache PDFBox up to 2.0.36/3.0.7. This affects the function PDComplexFileSpecification.getFilename of the component Example. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-23907. It is possible to launch the attack remotely. No exploit is available.