2026-05-07
2026-05-07 19:16Z
HIGH

CVE-2026-42215 — GitPython: From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42215

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_o CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDGitpythonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 19:16Z
CRIT

CVE-2026-41902 — FreeScout: Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41902

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until consumed. Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on the setup page, server-side log exposure, abandoned invite email CVSSv3.1 9.1 (CRITICAL)

CWECWE 613VNDFreescoutTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-07
2026-05-07 18:44Z
HIGH

CVE-2022-0847-Container-Escape — CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

GitHub · container escape·github.comGITHUB POCCVE-2022-0847

A GitHub repository demonstrates a practical container escape exploit leveraging CVE-2022-0847 (Dirty Pipe) combined with the CAP_DAC_READ_SEARCH capability to overwrite arbitrary read-only files on the host filesystem from within a container. The exploit uses splice() and open_by_handle_at() syscalls to bypass file permission checks and modify host files, with a working proof-of-concept in C.

SRFOsTACTA0004TACTA0005TYPResearchTYPExploitSTGDefense EvasionSTGPrivescEXPPrivilege Escalation
72
Edit Score
2026-05-07
2026-05-07 18:16Z
CRIT

CVE-2026-37709 — Permissions: Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 17:15Z
CRIT

CVE-2026-7415 — MQTT: The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7415

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDMqttTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 17:15Z
CRIT

CVE-2026-7414 — Yarbo: These credentials are identical across all devices running this firmware and cannot be changed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7414

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDYarboTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 16:16Z
HIGH

CVE-2026-6973 — Ivanti Endpoint_manager_mobile: A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6973in the wild

A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to inject arbitrary Apache directives, leading to remote code execution. CVSSv3.1 7.2 (HIGH) · EPSS 90th percentile

CWECWE 15VNDIvantiTYPVulnerabilitySTAitw exploited
7.2
CVSS v3.1
88
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-07
2026-05-07 16:16Z
HIGH

CVE-2026-5787 — Certificate: An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5787

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. CVSSv3.1 8.9 (HIGH)

CWECWE 295TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-05-07
2026-05-07 16:16Z
HIGH

CVE-2026-5786 — Access: An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5786

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDAccessTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 16:16Z
CRIT

CVE-2025-63704 — NPM: package query-parser-string 1.0.0 is vulnerable to Prototype Pollution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63704

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1321TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 16:16Z
CRIT

CVE-2025-63703 — npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63703

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). CVSSv3.1 9.8 (CRITICAL)

CWECWE 1321TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 16:00Z
HIGH

Shift Happens – Uncovering Two Built-in Command Injections in Windows Context Menus

SpecterOps·specterops.io

SpecterOps researcher Remi Gascou disclosed two command injection vulnerabilities in Windows Explorer's built-in "Open PowerShell window here" context menu. By crafting folder names with special characters (e.g., "folder; calc"), attackers can achieve arbitrary PowerShell command execution when users Shift+Right-Click and select the menu option. One variant affects Windows 11 Canary builds; the other existed since Windows 10 1703 (2017) and was fixed after responsible disclosure to MSRC.

SRFOsTACTA0002OSWindowsTYPResearchSTGExecutionTECT1059.001EXPCommand InjectionSTApatched
78
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2026-41654 — Weblate Weblate: http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41654

Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.object CVSSv3.1 8.1 (HIGH)

CWECWE 918CWECWE 20VNDWeblateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2026-41505 — RELATE: Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41505

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16. CVSSv3.1 8.7 (HIGH)

CWECWE 338CWECWE 330VNDRelateTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2026-41422 — Daptin: Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41422

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed authenticated users with any valid session to inject arbitrary SQL expressions. This issue has been patched in version 0.11.4. CVSSv3.1 8.3 (HIGH)

CWECWE 89VNDDaptinTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-07
2026-05-07 15:16Z
CRIT

CVE-2026-36458 — ChestnutCMS: v1.5.10 has a SQL injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36458

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDChestnutcmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 15:16Z
CRIT

CVE-2025-63706 — NPM: package next-npm-version1.0.1 is vulnerable to Command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63706

NPM package next-npm-version1.0.1 is vulnerable to Command injection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 15:16Z
HIGH

CVE-2025-63705 — NPM: package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63705

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 14:16Z
CRIT

CVE-2026-6795 — URL: DivvyDrive allows Parameter Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6795

URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. CVSSv3.1 9.6 (CRITICAL)

CWECWE 601TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-07
2026-05-07 14:16Z
CRIT

CVE-2026-41589 — Wish: From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41589

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories outside the configured root directory by sending crafted filenames containing ../ sequences over the SCP protocol. This issue has been patched in version 2.0.1. CVSSv3.1 9.6 (CRITICAL)

CWECWE 22VNDWishTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-07
2026-05-07 14:16Z
HIGH

CVE-2026-41490 — Dagster: Prior to Dagster Core version 1.13.1 and prior to Dagster libraries version 0.29.1, the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41490

Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior to Dagster libraries version 0.29.1, the DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers constructed SQL WHERE clauses by interpolating dynamic partition key values into queries without escaping. A user with the Add Dynamic Partitions permission could create a partition key that injects arbitrary SQL, which would execute CVSSv3.1 8.3 (HIGH)

CWECWE 89VNDDagsterTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-07
2026-05-07 14:16Z
CRIT

CVE-2026-30496 — Optoma: The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30496

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports both reading configuration (74 endpoints) and writing/modifying settings including volume, mute, brightness, power, network protocols enable/disable (including TELNET), display modes, and other projector functions. Any device on the same network can control the projector without auth CVSSv3.1 9.8 (CRITICAL)

CWECWE 285VNDOptomaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 14:16Z
HIGH

CVE-2026-30495 — Optoma: This allows extraction of stored WiFi credentials, installation of persistent malware, and access to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30495

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is configured with ro.adb.secure=0, which disables RSA key verification. Additionally, a functional su binary exists at /system/xbin/su that grants root privileges without authentication. An attacker on the same network can connect to the device via ADB, obtain a shell, and escalate to CVSSv3.1 8.8 (HIGH)

CWECWE 285VNDOptomaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 14:16Z
HIGH

CVE-2025-14341 — Improperly: controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-14341

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3.2. CVSSv3.1 8.3 (HIGH)

CWECWE 770CWECWE 915VNDImproperlyTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-07
2026-05-07 13:21Z
INFO

SecurityInsight — Rethink Secure Score: risk-based scoring across Defender XDR, Entra, AD, Azure, ExposureGraph, and Shodan — weighted by

GitHub · Azure / Entra tools·github.comGITHUB POC

SecurityInsight is a free, open-source PowerShell-based tool that consolidates security telemetry from Microsoft Defender, Entra ID, Active Directory, Azure, and ExposureGraph to provide risk-based prioritization across endpoints, identity, and cloud assets. It applies a four-dimensional scoring model (consequence, criticality tier, risk factors, customizable index) to rank findings by attacker opportunity rather than severity alone, outputting to Excel, Power BI, Log Analytics, and JSON.

SRFApplicationTACTA0007SRFIdentitySRFCloudSWAzureSWDefenderSWEntraVNDMicrosoft
72
Edit Score