2026-05-07
2026-05-07 22:16Z
CRIT

CVE-2026-33823 — Microsoft: Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33823

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 285VNDMicrosoftTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-07
2026-05-07 22:16Z
CRIT

CVE-2026-33109 — Azure: Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDAzureTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-07
2026-05-07 22:16Z
HIGH

CVE-2026-32207 — Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 21:16Z
HIGH

CVE-2026-42449 — MCP: Response bodies are returned to the caller (non-blind SSRF), and the n8nApiKey is forwarded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42449

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstanceContext()), the synchronous URL validator in SSRFProtection.validateUrlSync() had no IPv6 checks. IPv4-mapped IPv6 addresses such as http://[::ffff:169.254.169.254] bypassed the cloud-metadata, localhost, and private-IP range ch CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDMcpTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-07
2026-05-07 21:16Z
HIGH

CVE-2026-42047 — Inngest: Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42047

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serve() HTTP handler. The serve() handler implements GET, POST, and PUT methods. Requests using PATCH, OPTIONS, or DELETE fall through to a generic handler that returns diagnostic info CVSSv3.1 8.6 (HIGH)

CWECWE 200CWECWE 497VNDInngestTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-07
2026-05-07 20:16Z
HIGH

CVE-2026-42239 — Budibase: This means every XSS becomes a full account takeover — the attacker steals the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42239

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full account takeover — the attacker steals the JWT and has persistent access to the victim's account. The cookie also lacks secure: true (sent over plaintext HTTP) and sameSite attribute. CVSSv3.1 8.1 (HIGH)

CWECWE 1004VNDBudibaseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-07
2026-05-07 19:47Z
INFO

v3.4.0.58

Mythic releases·github.com

Mythic v3.4.0.58 released with a bug fix for lazyQuery on the single task view page. This is a minor patch release addressing UI/UX functionality in the command & control framework.

SWMythicTYPTool
15
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-07
2026-05-07 19:16Z
HIGH

CVE-2026-42284 — GitPython: Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split("

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42284

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in vers CVSSv3.1 8.1 (HIGH)

CWECWE 88VNDGitpythonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-07
2026-05-07 19:16Z
HIGH

CVE-2026-42215 — GitPython: From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42215

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_o CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDGitpythonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 19:16Z
CRIT

CVE-2026-41902 — FreeScout: Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41902

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until consumed. Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on the setup page, server-side log exposure, abandoned invite email CVSSv3.1 9.1 (CRITICAL)

CWECWE 613VNDFreescoutTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-07
2026-05-07 18:44Z
HIGH

CVE-2022-0847-Container-Escape — CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

GitHub · container escape·github.comGITHUB POCCVE-2022-0847

A GitHub repository demonstrates a practical container escape exploit leveraging CVE-2022-0847 (Dirty Pipe) combined with the CAP_DAC_READ_SEARCH capability to overwrite arbitrary read-only files on the host filesystem from within a container. The exploit uses splice() and open_by_handle_at() syscalls to bypass file permission checks and modify host files, with a working proof-of-concept in C.

SRFOsTACTA0004TACTA0005TYPResearchTYPExploitSTGDefense EvasionSTGPrivescEXPPrivilege Escalation
72
Edit Score
2026-05-07
2026-05-07 18:16Z
CRIT

CVE-2026-37709 — Permissions: Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 17:15Z
CRIT

CVE-2026-7415 — MQTT: The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7415

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDMqttTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 17:15Z
CRIT

CVE-2026-7414 — Yarbo: These credentials are identical across all devices running this firmware and cannot be changed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7414

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDYarboTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 16:16Z
HIGH

CVE-2026-6973 — Ivanti Endpoint_manager_mobile: A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6973in the wild

A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to inject arbitrary Apache directives, leading to remote code execution. CVSSv3.1 7.2 (HIGH) · EPSS 90th percentile

CWECWE 15VNDIvantiTYPVulnerabilitySTAitw exploited
7.2
CVSS v3.1
88
Edit Score
2026-05-07
2026-05-07 16:16Z
HIGH

CVE-2026-5787 — Certificate: An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5787

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. CVSSv3.1 8.9 (HIGH)

CWECWE 295TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-05-07
2026-05-07 16:16Z
HIGH

CVE-2026-5786 — Access: An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5786

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDAccessTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 16:16Z
CRIT

CVE-2025-63704 — NPM: package query-parser-string 1.0.0 is vulnerable to Prototype Pollution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63704

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1321TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 16:16Z
CRIT

CVE-2025-63703 — npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63703

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). CVSSv3.1 9.8 (CRITICAL)

CWECWE 1321TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 16:00Z
HIGH

Shift Happens – Uncovering Two Built-in Command Injections in Windows Context Menus

SpecterOps·specterops.io

SpecterOps researcher Remi Gascou disclosed two command injection vulnerabilities in Windows Explorer's built-in "Open PowerShell window here" context menu. By crafting folder names with special characters (e.g., "folder; calc"), attackers can achieve arbitrary PowerShell command execution when users Shift+Right-Click and select the menu option. One variant affects Windows 11 Canary builds; the other existed since Windows 10 1703 (2017) and was fixed after responsible disclosure to MSRC.

SRFOsTACTA0002OSWindowsTYPResearchSTGExecutionTECT1059.001EXPCommand InjectionSTApatched
78
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2026-41654 — Weblate Weblate: http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41654

Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.object CVSSv3.1 8.1 (HIGH)

CWECWE 918CWECWE 20VNDWeblateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2026-41505 — RELATE: Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41505

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16. CVSSv3.1 8.7 (HIGH)

CWECWE 338CWECWE 330VNDRelateTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2026-41422 — Daptin: Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41422

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed authenticated users with any valid session to inject arbitrary SQL expressions. This issue has been patched in version 0.11.4. CVSSv3.1 8.3 (HIGH)

CWECWE 89VNDDaptinTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-07
2026-05-07 15:16Z
CRIT

CVE-2026-36458 — ChestnutCMS: v1.5.10 has a SQL injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36458

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDChestnutcmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 15:16Z
CRIT

CVE-2025-63706 — NPM: package next-npm-version1.0.1 is vulnerable to Command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63706

NPM package next-npm-version1.0.1 is vulnerable to Command injection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score