2026-05-12
2026-05-12 10:16Z
CRIT

CVE-2025-6577 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-6577

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection. This issue affects E-Commerce Website: before 4.5.001. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 10:16Z
CRIT

CVE-2025-40949 — This could allow an authenticated remote attacker to execute arbitrary commands with root privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-40949

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All versions < V2.17.1), RUGGEDCOM ROX RX1524 (All versions < V2.17.1), RUGGEDCOM ROX RX CVSSv3.1 9.1 (CRITICAL)

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 10:16Z
HIGH

CVE-2025-40946 — A CRC16-based algorithm for generating Technical Service credentials could allow an attacker to derive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-40946

A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M11 (All versions), blueplanet 125 TL3 (All versions), blueplanet 125 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 137 TL3 (All versions), blueplanet 150 TL3 (All versions), blueplanet 150 TL3 GEN2 (All version CVSSv3.1 8.3 (HIGH)

CWECWE 321TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 09:16Z
HIGH

CVE-2026-39432 — Authorization: Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39432

Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53. CVSSv3.1 8.2 (HIGH)

CWECWE 862TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 09:00Z
HIGH

Exploiting the Tesla Wall Connector from its charge port connector - Part 2: bypassing the anti-downgrade

Synacktiv·synacktiv.com

Synacktiv researchers demonstrate a bypass of Tesla Wall Connector Gen 3's anti-downgrade security mechanism introduced in firmware 24.44.3. The attack exploits a race condition between partition table writes and slot erasure in the UDS update routine, allowing attackers to write and boot vulnerable firmware (0.8.58) on fully patched devices. The vulnerability has been patched by Tesla in subsequent firmware updates.

TACTA0001TACTA0002SRFFirmwareSRFHardwareSWTesla Wall ConnectorVNDTeslaTYPResearchTYPWriteup
82
Edit Score
2026-05-12
2026-05-12 07:00Z
HIGH

State of ransomware in 2026

Kaspersky Securelist·securelist.com

Kaspersky's 2026 ransomware report documents a shift from encryption-focused attacks to encryptionless extortion leveraging data theft, the emergence of post-quantum cryptography in ransomware families (PE32 using ML-KEM/Kyber1024), and the industrialization of initial access via RDWeb targeting and Access-as-a-Service brokers. Despite a formal decline in affected organizations, ransomware remains a persistent threat with new groups like The Gentlemen demonstrating professionalized, data-centric attack workflows and heavy exploitation of network appliances (FortiOS, SonicWall, Cisco ASA).

SRFApplicationTACTA0005TACTA0001SRFNetworkTACTA0003TACTA0008TACTA0011TACTA0009
78
Edit Score
2026-05-12
2026-05-12 04:16Z
HIGH

CVE-2026-7256 — UNSUPPORTED: ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7256

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDUnsupportedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-12
2026-05-12 03:16Z
CRIT

CVE-2026-34263 — Spring: Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34263

Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. CVSSv3.1 9.6 (CRITICAL)

CWECWE 459VNDSpringTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 03:16Z
CRIT

CVE-2026-34260 — SAP: S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34260

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sanitization. Upon successful exploitation, an attacker may gain unauthorized access to sensitive database information and could pot CVSSv3.1 9.6 (CRITICAL)

CWECWE 89VNDSapTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 03:16Z
HIGH

CVE-2026-34259 — Command: Successful exploitation could allow the attacker to read or modify any system data or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34259

Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify any system data or shut down the system, resulting in a complete compromise of confidentiality, integrity, and availability. CVSSv3.1 8.2 (HIGH)

CWECWE 77VNDCommandTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 02:16Z
CRIT

CVE-2026-45393 — Reserved: Details will be published at disclosure.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45393

Reserved. Details will be published at disclosure. CVSSv3.1 9.8 (CRITICAL)

VNDReservedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 02:16Z
CRIT

CVE-2026-45392 — Reserved: Details will be published at disclosure.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45392

Reserved. Details will be published at disclosure. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDReservedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 02:16Z
CRIT

CVE-2026-45391 — Reserved: Details will be published at disclosure.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45391

Reserved. Details will be published at disclosure. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDReservedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 01:16Z
CRIT

CVE-2026-45321 — On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/*

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45321

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base t CVSSv3.1 9.6 (CRITICAL)

CWECWE 506TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 00:00Z
HIGH

Inside the lethal trifecta: Blast radius reduction in AI agent deployments

Sophos X-Ops·news.sophos.com

Sophos X-Ops publishes a comprehensive defensive framework for mitigating indirect prompt injection attacks against AI agents operating in the 'lethal trifecta' (accessing private data, processing untrusted content, communicating externally). The article outlines seven tactical patterns—agent sandboxing, credential isolation, sealed tool endpoints, egress restriction, EDR integration, human-gated approval, and memory/audit controls—that practitioners can deploy within 1–6 months to reduce blast radius without waiting for mature architectural solutions like CaMeL or Dual LLM.

TACTA0006TACTA0009SRFAiTACTA0010TYPResearchSTGDefense EvasionSTGCred AccessSTGExfil
78
Edit Score
2026-05-11
2026-05-11 23:20Z
HIGH

CVE-2026-43913 — Vaultwarden: Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43913

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step process: accepting an invite transitions membership from Invited to Accepted, and a separate confirmation by an existing owner upgrades it to Confirmed. The POST /api/ciphers/purge endpoint uses plain Headers and only checks that the membership type is Owner with CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDVaultwardenTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 23:20Z
HIGH

CVE-2026-43912 — Vaultwarden: This lets an attacker who is Admin in Organization A, and only a low-privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43912

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.collections_uuid entry belongs to the same organization as collections_groups.groups_uuid. Multiple organization group-management endpoints accept arbitrary MembershipId and CollectionId values and persist them directly without verifying org CVSSv3.1 8.7 (HIGH)

CWECWE 285VNDVaultwardenTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 23:20Z
CRIT

CVE-2026-43900 — DeepChat: Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43900

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer (src/main/lib/svgSanitizer.ts) restricts script execution by scrubbing javascript: protocols using plain-text regular expressions. However, it fails to account for HTML entity decodi CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDDeepchatTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-11
2026-05-11 23:20Z
CRIT

CVE-2026-43899 — DeepChat: Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43899

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). While the patch correctly restricted api.openExternal() inside the renderer's preload/index.ts script, it structurally neglected to sanitize native Electron pop-up window handlers. An attacker or a compromised AI endpoint returnin CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDDeepchatTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-11
2026-05-11 23:19Z
HIGH

CVE-2026-34963 — barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34963

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to validate that PointerToRawData plus copied size remains within the PE file buffer. An attacker can supply a malicious EFI PE binary via TFTP, USB, SD card, or ne CVSSv3.1 8.4 (HIGH)

CWECWE 190TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-11
2026-05-11 22:22Z
HIGH

CVE-2026-43893 — Node: A newline or carriage return inside one of those strings could split a single

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43893

exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ - mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into ExifTool arguments without rejecting line delimiters. A newline or carriage return inside one of those strings could split a single intended argument into multiple ExifTool arguments, allowing argument CVSSv3.1 8.2 (HIGH)

CWECWE 88TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 22:22Z
HIGH

CVE-2026-43888 — Outline: is a service that allows for collaborative documentation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43888

Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by passing a full filesystem path through trimFileAndExt, a filename helper that calls path.basename on its input when truncating. When a zip entry's nested path is long enough to push the joined filesystem path over MAX_PATH_LENGTH (4096 bytes), trimFileAndExt silently drops all directory components and returns a bare filename. fs.cr CVSSv3.1 8.7 (HIGH)

CWECWE 22VNDOutlineTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-11
2026-05-11 22:22Z
HIGH

CVE-2026-43886 — Outline: is a service that allows for collaborative documentation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43886

Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing the function to accept the entire scope array if any single scope is valid. An attacker can smuggle the wildcard * scope by requesting scope=read *, escalating a read-only OAuth token to full unrestricted API access including write, delete, and admin operations. This vulnerability CVSSv3.1 8.2 (HIGH)

CWECWE 269VNDOutlineTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 22:22Z
HIGH

CVE-2026-42564 — Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename].

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42564

jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is joined into a filesystem path without traversal/boundary validation, allowing file reads outside data/uploads/app-icons/. This vulnerability is fixed in 1.22.0. CVSSv3.1 8.2 (HIGH)

CWECWE 200CWECWE 22TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-11
2026-05-11 21:19Z
HIGH

CVE-2026-41489 — DNS: On a default Pi-hole installation this yields local privilege escalation to root via SSH

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41489

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by systemd (pihole-FTL-prestart.sh and pihole-FTL-poststop.sh) read the files.pid path from this config without validation and use it in privileged file operations (install and rm -f). By writing an arbitrary path into files.pid, an attacker with pihole privilege can cause root to del CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 732CWECWE 15VNDDnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score