5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25736 — LabF: nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25736

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe or other arbitrary commands. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDLabfTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25735 — AllPlayer: 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25735

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execution to run arbitrary commands with user privileges. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDAllplayerTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25733 — NetShareWatcher: 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25733

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigger code execution when the Find function is invoked. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDNetsharewatcherTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25732 — PHP: EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25732

PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to extract sensitive database information including usernames, passwords, and version details. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25730 — Listing: Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25730

Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to extract database credentials, usernames, and version information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDListingTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-06-04 14:16Z
CRIT

CVE-2019-25729 — PDF: Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25729

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute system commands and retrieve sensitive information from the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 352VNDPdfTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25728 — Care2x: 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25728

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.php, and various module files to extract sensitive database information without authentication. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDCare2xTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-06-04 14:16Z
CRIT

CVE-2019-25727 — WordPress: Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25727

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 14:16Z
HIGH

CVE-2019-25726 — One: All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25726

All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames, databases, and version details. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDOneTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-06-04 12:16Z
CRIT

CVE-2026-4104 — Authorization: bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4104

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 12:16Z
CRIT

CVE-2026-10840 — A flaw was found in the OpenShift Pipelines operator.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10840

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secret CVSSv3.1 9.6 (CRITICAL)

CWECWE 732TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-06-04 12:00Z
CRIT

VerdantBamboo: Just Another BRICKSTORM in the Firewall

Volexity·volexity.comin the wild

Volexity disclosed a 18+ month intrusion by Chinese APT VerdantBamboo (WARP PANDA, UNC5221) targeting a victim organization and its MSP via compromised Egnyte Storage Sync and pfSense firewall appliances. The threat actor deployed three malware families—BRICKSTORM (Golang/Rust RAT), AGENTPSD (Python reverse shell), and PLENET (.NET Core backdoor)—to establish persistent access, bypass Conditional Access policies on M365, and pivot through the victim's infrastructure. The attack exploited a local privilege escalation in Egnyte's sudo configuration, credential theft from the MSP, and exposed firewall administrative interfaces.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFNetwork ApplianceTACTA0003TACTA0008TACTA0011
92
Edit Score
5d ago
2026-06-04 10:16Z
CRIT

CVE-2026-50225 — Acer Connect_m6e_5g_firmware: The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile

CWECWE 306VNDAcerTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
5d ago
2026-06-04 10:16Z
CRIT

CVE-2026-50214 — Acer Connect_m6e_5g_firmware: The /v1/Plan service relies entirely on a shared global API token for full administrative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50214

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 345VNDAcerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 09:16Z
CRIT

CVE-2026-50211 — Acer Connect_m6e_5g_firmware: Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50211

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers. CVSSv3.1 9.8 (CRITICAL)

CWECWE 134VNDAcerVNDLeftoverTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 09:16Z
CRIT

CVE-2026-50208 — Acer Connect_m6e_5g_firmware: Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50208

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic. CVSSv3.1 9.4 (CRITICAL)

CWECWE 330VNDAcerVNDHighTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
5d ago
2026-06-04 07:16Z
HIGH

CVE-2026-50205 — Acer Connect_m6e_5g_firmware: System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50205

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data. CVSSv3.1 8.2 (HIGH)

CWECWE 532VNDAcerTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-06-04 07:16Z
HIGH

CVE-2026-49203 — Acer Connect_m6e_5g_firmware: Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted. CVSSv3.1 8.3 (HIGH)

CWECWE 287VNDAcerVNDCrucialTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-06-04 07:16Z
HIGH

CVE-2026-49202 — Acer Connect_m6e_5g_firmware: Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. CVSSv3.1 8.6 (HIGH)

CWECWE 287VNDAcerTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-06-04 07:16Z
HIGH

CVE-2026-49194 — Acer Connect_m6e_5g_firmware: The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDAcerVNDScreen ClickTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-06-04 07:16Z
CRIT

CVE-2026-49191 — Acer Connect_m6e_5g_firmware: The production build of the M3WebServer hard-codes its backend API keys, which can be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDAcerVNDM3webserverTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 07:16Z
HIGH

CVE-2026-49190 — Acer Connect_m6e_5g_firmware: The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49190

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDAcerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-06-04 06:30Z
CRIT

FSB’s matryoshka #3/3 – Gamaredon’s gifts that keeps unpacking – GammaSteel

Sekoia.io·sekoia.ioin the wild

Sekoia.io's third report in their Gamaredon trilogy documents GammaSteel, the FSB-operated intrusion set's final-stage stealer payload targeting Ukrainian government and critical infrastructure. The malware operates fileless via PowerShell, leveraging Windows DPAPI encryption in the registry, and deploys three concurrent data-acquisition mechanisms: hourly filesystem scans, USB hardware event monitoring, and real-time file-change surveillance. Exfiltration routes through S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled C2 and Dead Drop Resolvers, with local MD5-based deduplication to minimize network noise.

SRFApplicationSRFOsTACTA0002TACTA0007TACTA0003TACTA0009SWPowershellVNDMicrosoft
92
Edit Score
5d ago
2026-06-04 06:16Z
CRIT

CVE-2026-49188 — Acer Connect_m6e_5g_firmware: The ai_cmd utility executes with full root permissions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 489VNDAcerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-06-04 04:17Z
CRIT

CVE-2026-49186 — Acer Connect_m6e_5g_firmware: This allows any client to subscribe using wildcard characters (# or +) to enumerate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49186

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDMqttVNDAcerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score