2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25390 — HaPe: PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25390

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDHapeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25389 — HaPe: PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25389

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDHapeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25388 — HaPe: PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25388

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDHapeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25386 — HaPe: PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25386

HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus, fasilitas, and kelompok modules (for example act=print, act=editpengurus, act=editfasilitas, and act=editkelompok). Successful exploitation allows extraction of sens CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDHapeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25385 — Registrasi: E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25385

E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDRegistrasiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25383 — Free: MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25383

Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded through the Convert function, enabling execution of arbitrary code through ROP chain gadgets and shellcode injection. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDFreeTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-29
2026-05-29 16:16Z
HIGH

CVE-2018-25382 — Zechat: 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25382

Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive data from the information_schema database. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDZechatTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-29
2026-05-29 15:22Z
HIGH

CVE-2026-27771 | Gitea Container Registry Authentication Bypass Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-27771in the wild

CVE-2026-27771 is an authentication bypass in Gitea's container registry that allows unauthenticated attackers to pull private OCI container images and package artifacts without credentials. The vulnerability affects Gitea versions prior to 1.26.2 and carries a CVSS score of 8.2. Public reporting indicates 30,000+ Gitea deployments may have exposed private container images.

SRFApplicationTACTA0001SRFSupply ChainSWGiteaVNDGiteaTYPVulnerabilitySTGInitial AccessTECT1078
78
Edit Score
2026-05-29
2026-05-29 15:16Z
CRIT

CVE-2026-4290 — Travel: The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4290

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing the user ID directly to wp_delete_user() without any role validation. This makes it possible for unauthenticated attackers to delete arbitrary user accounts, inclu CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDTravelTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-29
2026-05-29 15:16Z
HIGH

CVE-2026-10063 — TRENDnet: Such manipulation of the argument peerPin leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10063

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulne CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTrendnetTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 15:16Z
HIGH

CVE-2026-10062 — TRENDnet: This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10062

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTrendnetTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 15:16Z
CRIT

CVE-2026-10042 — manga-image-translator contains a remote code execution vulnerability in the shared API server mode due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10042

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request bodies using pickle.loads(). A remote attacker can supply a crafted pickle payload to these endpoints to execute arbitrary code in the server process, resulting in full container CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-46510 — FormData: form-data-objectizer converts FormData to object.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46510

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose name starts with __proto__[...] causes the library to mutate Object.prototype, which is a prototype pollution primitive of the entire Node.js process. This vulnerability is fixed in 1.0.1. CVSSv3.1 8.2 (HIGH)

CWECWE 1321VNDFormdataTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 14:16Z
CRIT

CVE-2026-46376 — Sangoma Freepbx: From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46376

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the initial setup of UCP generic templates, but after that, without further steps by the admin, unauthenticated users may be able to gain access. This vulnerability CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDFreepbxVNDSangomaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-45707 — MCP: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45707

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request from x-n8n-url / x-n8n-key headers. Requests that omitted those headers — or supplied only one of them — silently fell back to the process-level N8N_API_URL / N8N_API_KEY credentials configured for the operator's own n8n instance. As a CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDMcpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-45615 — ASN: This forces a precise 1-byte Heap Out-of-Bounds (OOB) Read.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45615

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to validate the required bytes before extracting the Most Significant Bit (MSB). This forces a precise 1-byte Heap Out-of-Bounds (OOB) Read. Because asn1c generated CVSSv3.1 8.2 (HIGH)

CWECWE 20CWECWE 125CWECWE 130VNDAsnTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-45578 — WWBN: In 29.0 and earlier, there is a classic shell-metacharacter injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45578

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshellarg(). A ' in any of the three interpolated values ($users_id, $m3u8, $obj->liveTransmitionHistory_id) closes the quoted token and lets the attacker append arbitrary commands. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDWwbnTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-44698 — Home: Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44698

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpola CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 346CWECWE 940CWECWE 749VNDHomeTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-44239 — Sangoma Freepbx: The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44239

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. CVSSv3.1 8.8 (HIGH)

CWECWE 98VNDFreepbxVNDSangomaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-44238 — Sangoma Freepbx: Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44238

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administrator privileges are not needed. This vulnerability is fixed in 16.0.50 and 17.0.11. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDFreepbxVNDSangomaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 14:16Z
HIGH

CVE-2026-44237 — Sangoma Freepbx: Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44237

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditionally returns true, allowing any party with knowledge of a valid client_id to obtain OAuth2 access tokens without providing the correct client_secret. This vulnerability is fixed in 17.0.8. CVSSv3.1 8.1 (HIGH)

CWECWE 1390VNDFreepbxVNDSangomaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-29
2026-05-29 13:16Z
HIGH

CVE-2026-48527 — HAX: Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48527

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name. @haxtheweb/haxcms-nodejs 26.0.1 and haxcms-php 26.0.2 patch the issue. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDHaxTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-29
2026-05-29 13:16Z
CRIT

CVE-2026-45312 — RAGFlow: In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45312

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the SSTI. CVSSv3.1 9.9 (CRITICAL)

CWECWE 1336VNDRagflowTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-29
2026-05-29 13:16Z
CRIT

CVE-2026-10071 — DreamMaker: developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10071

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDDreammakerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-29
2026-05-29 13:00Z
CRIT

Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557

Bishop Fox Labs·bishopfox.comCVE-2026-22557CVE-2026-22558CVE-2026-22559

CVE-2026-22557 is an unauthenticated path traversal in UniFi Network Application's guest captive portal (CVSS 10.0) that allows reading arbitrary files including encrypted backups containing all device credentials. The vulnerability requires a customized guest portal to be enabled and is reachable on both guest and admin ports. Bishop Fox published a safe detection tool and detailed exploitation paths showing how attackers extract backups, decrypt them with hardcoded keys, and compromise all managed network devices.

TACTA0001SRFNetworkTACTA0007SRFWebSWUnifiVNDUbiquitiTYPResearchTYPVulnerability
92
Edit Score