2026-06-01
2026-06-01 19:16Z
HIGH

CVE-2026-43623 — microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43623

microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a crafted TAR archive with non-null-terminated name or linkname fields. The function uses strcpy() to copy 100-byte ustar format fields that lack null terminators, causing writes of up to 355 bytes into a 100-byte destination buffer when mtar_open(), mtar_find(), or mtar_read_header() CVSSv3.1 8.8 (HIGH)

CWECWE 121TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 19:16Z
HIGH

CVE-2026-41013 — Input: validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41013

Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0 CVSSv3.1 8.1 (HIGH)

CWECWE 88VNDInputTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-01
2026-06-01 19:16Z
HIGH

CVE-2026-37232 — OpenAirInterface5G: This results in complete 5G cell service interruption for all connected UEs.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37232

An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in openair2/E2AP/RAN_FUNCTION/O-RAN/ran_func_kpm_subs.c (lines 182 and 197) compute PRB usage percentages by dividing by the difference of two consecutive total_prb_aggregate samples without checking for zero. When a malicious xApp sends a high volume of E42_RIC_SUBSCRIPTION_REQUESTs via CVSSv3.1 8.6 (HIGH)

CWECWE 369VNDOpenairinterface5gTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-01
2026-06-01 19:16Z
CRIT

CVE-2026-22872 — Projectcapsule Capsule: Prior to version 0.13.0, tenant administrators can leverage the Controller's elevated privileges to create

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22872

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for cluster-scoped resources. Prior to version 0.13.0, tenant administrators can leverage the Controller's elevated privileges to create cluster-scoped resources (such as ClusterRole and ValidatingWebhookConfiguration) that they cannot create direc CVSSv3.1 9.1 (CRITICAL)

CWECWE 863CWECWE 20VNDProjectcapsuleVNDCapsuleTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-01
2026-06-01 19:16Z
HIGH

CVE-2024-52011 — launch-editor allows users to open files with line numbers in editor from Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-52011

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9. CVSSv3.1 8.3 (HIGH) · EPSS 39th percentile

CWECWE 77CWECWE 88TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-01
2026-06-01 18:08Z
INFO

BloodHound CE v9.2.2

BloodHound releases·github.com

BloodHound CE v9.2.2 released with bug fixes including a hotfix for current vulnerabilities (#2843) and a dependency bump to dawgs v0.5.5 to resolve an index regression. This is a minor patch release with no new features.

SWBloodhoundTYPTool
35
Edit Score
2026-06-01
2026-06-01 17:21Z
HIGH

lpe-toolkit — Multi-architecture Linux privilege escalation toolkit with 19 pre-built and runtime-compilable exploits. Auto-detects ke

lpe-toolkit is a multi-architecture Linux privilege escalation toolkit bundling 19 pre-built and runtime-compilable exploits targeting kernel vulnerabilities across amd64, arm64, 386, mips, and other architectures. The toolkit auto-detects kernel version, filters patched exploits, and attempts each sequentially until root is achieved, with support for non-interactive command execution and GTFOBins sudo abuse techniques.

SRFOsTACTA0004OSLinuxTYPToolSTGPrivescEXPPrivilege Escalation
72
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-01
2026-06-01 17:17Z
HIGH

CVE-2026-45156 — Nextcloud: From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45156

Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDNextcloudTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-01
2026-06-01 17:17Z
CRIT

CVE-2026-45132 — CloudPirates: Open Source Helm Charts is a collection of Helm charts.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45132

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been patched via commit fcf9302. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCloudpiratesTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-01
2026-06-01 17:17Z
CRIT

CVE-2026-45131 — CloudPirates: Open Source Helm Charts is a collection of Helm charts.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45131

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring maintainer approval. This issue has been patched via commit fcf9302. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCloudpiratesTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-01
2026-06-01 17:17Z
CRIT

CVE-2026-44211 — Cline: In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44211

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches. CVSSv3.1 9.6 (CRITICAL)

CWECWE 306CWECWE 1385VNDClineTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-01
2026-06-01 17:16Z
CRIT

CVE-2026-42672 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42672

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-01
2026-06-01 17:16Z
HIGH

CVE-2026-10270 — The manipulation of the argument Time results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10270

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 16:00Z
HIGH

CVE-2026-4387: StrongDM State File Reuse

SpecterOps·specterops.ioCVE-2026-4387

SpecterOps disclosed CVE-2026-4387, a credential reuse vulnerability in StrongDM Desktop and CLI where authentication material (JWT, public/private keys) was stored in plaintext in C:\Users\<username>\.sdm\state.kv. An attacker with user-level file access could exfiltrate and replay this state file on any other host to gain authenticated sessions as the original user. StrongDM patched the vulnerability in Desktop v23.74.0 and CLI v53.77.0 by migrating to platform-native credential storage (DPAPI/Keychain) instead of plaintext files.

SRFApplicationTACTA0006TACTA0008SWStrongdmVNDStrongdmTYPWriteupTYPVulnerabilitySTGCred Access
78
Edit Score
2026-06-01
2026-06-01 15:16Z
CRIT

CVE-2026-48879 — Incorrect: Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48879

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-01
2026-06-01 15:16Z
CRIT

CVE-2026-48866 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48866

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1. CVSSv3.1 9.6 (CRITICAL)

CWECWE 22TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-01
2026-06-01 15:16Z
CRIT

CVE-2026-42682 — Authorization: Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42682

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-01
2026-06-01 15:16Z
CRIT

CVE-2026-42680 — Incorrect: Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42680

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-01
2026-06-01 15:16Z
HIGH

CVE-2026-10259 — Such manipulation of the argument param leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10259

A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 15:16Z
INFO

CVE-2026-0826 — In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0826

In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform. EPSS 98th percentile

CWECWE 121TYPVulnerability
57
Edit Score
2026-06-01
2026-06-01 15:16Z
HIGH

CVE-2024-40646 — Vertex: Versions prior to commit fbde301b97986d5913fc4bc95f5445750d282e11 are vulnerable to path traversal.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-40646

Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc95f5445750d282e11 are vulnerable to path traversal. Users should upgrade to a version containing commit fbde301b97986d5913fc4bc95f5445750d282e11 to receive a patch. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDVertexTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-01
2026-06-01 13:42Z
CRIT

Adobe Acrobat Reader Escript.api Use-After-Free Remote Code Execution

Exodus Intel·blog.exodusintel.comCVE-2026-34621CVE-2026-34626CVE-2026-34622

A use-after-free vulnerability in Adobe Acrobat Reader's Escript.api module allows remote code execution via malicious PDF documents. The flaw stems from desynchronization between two bookkeeping mechanisms (reference counting and event scope stack) when exception handlers fail to properly clean up scoped objects during stack overflow conditions. An attacker can exploit __defineGetter__ to recursively invoke util.scand() and exhaust the C++ stack, leaving a dangling pointer that can be dereferenced for arbitrary code execution.

SRFApplicationTACTA0002SWAcrobat ReaderVNDAdobeTYPResearchTYPVulnerabilitySTGExecutionTECT1203
92
Edit Score
2026-06-01
2026-06-01 13:00Z
CRIT

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

Rapid7 Research·rapid7.comCVE-2026-0826

CVE-2026-0826 is a critical unauthenticated stack-based buffer overflow in HP Poly VVX and Trio VoIP phones that allows remote code execution without authentication. The vulnerability bypasses modern memory protections and can be exploited to gain root access on trusted office devices. The research highlights the emerging threat of compromised VoIP phones as collection points for high-quality audio data to feed AI-powered impersonation and social engineering attacks.

TACTA0001TACTA0002SRFNetwork ApplianceSWPoly TrioSWPoly VvxVNDHpTYPVulnerabilitySTGInitial Access
78
Edit Score
2026-06-01
2026-06-01 13:00Z
CRIT

CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

Rapid7 Research·rapid7.comCVE-2026-0826

Rapid7 discovered a critical unauthenticated stack-based buffer overflow (CVE-2026-0826, CVSS 9.2) in HP Poly VVX and Trio VoIP phones affecting all VVX models and three Trio models. The vulnerability exists in the parsing of SDP ICE candidate attributes and allows remote code execution with root privileges when ICE is enabled. Patches are available: VVX UCS 6.4.8, Trio 8300 UCS 8.1.7, Trio 8500/8800 UCS 7.2.8.

TACTA0001SRFNetwork ApplianceSWPoly TrioSWPoly VvxVNDHpTYPExploitTYPVulnerabilitySTGExecution
92
Edit Score
2026-06-01
2026-06-01 10:00Z
CRIT

Containers on fire: from container escapes to supply chain attacks

Kaspersky Securelist·securelist.comCVE-2019-5736CVE-2022-0492CVE-2024-21626

Kaspersky's comprehensive analysis of container attack vectors covering exploitation of host vulnerabilities (runC, cgroups), malicious activity within containers, container escape techniques via Linux capability misconfigurations (CAP_SYS_ADMIN, CAP_SYS_MODULE, CAP_SYS_PTRACE, CAP_NET_ADMIN), orchestration API abuse, and supply chain attacks including Docker Hub poisoning. The article details real-world APT campaigns like TeamPCP's Checkmarx KICS compromise and provides technical walkthroughs of escape primitives including kernel module injection and ptrace-based process hijacking.

SRFOsTACTA0004SRFCloudTACTA0008SWKubernetesSWDockerSWRuncVNDKaspersky
82
Edit Score