2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43134 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43134

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAP_CR_LE_BAD_KEY_SIZE. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43125 — Linux: When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43125

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree(). Add length validation to prevent potential buffer overflow. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2025-31951 — HCL: A flaw in a component's input handling was identified that could permit unauthorized command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-31951

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution. CVSSv3.1 8.8 (HIGH)

CWECWE 77CWECWE 451CWECWE 351VNDHclTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 10:16Z
CRIT

CVE-2026-43117 — Linux: In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43117

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid assignment will lead to a crash. Use file_inode(file)->i_sb to always get btrfs_sb. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-06
2026-05-06 10:16Z
CRIT

CVE-2026-43114 — Linux: Due to incorrect masking, the skip-step finds the next matching element *only considering the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43114

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4 . port' key, i.e. nft -f foo. This works. Then, it reloads the set after a flush: (echo flush set t s; cat foo) | nft -f - This is expected to work, because its the same set after all and it was a CVSSv3.1 9.4 (CRITICAL)

TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-06
2026-05-06 10:16Z
HIGH

CVE-2026-43113 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43113

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the firmware completion ID directly to index the fixed 16-entry wl->tx_frames[] array. The ID is a raw u8 from the completion block, and the callback does not currently verify that it fits the array before dereferencing it. Reject completion IDs that fall outside wl->tx_frames[] and keep the existing NULL check in the sa CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 10:16Z
HIGH

CVE-2026-43112 — Linux: In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43112

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced. This results in an out-of-bounds read. This patch adds an early exit check after stripping prepended delimiters. If no path content remains, the function re CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-06
2026-05-06 10:16Z
HIGH

CVE-2026-43110 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43110

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event() validates the firmware-provided interface index before it touches drvr->iflist[], but it still uses the raw bsscfgidx field as an array index without a matching range check. Reject IF events whose bsscfg index does not fit in drvr->iflist[] before indexing the interface array. [add missing wifi prefix] CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 10:16Z
CRIT

CVE-2026-43083 — Linux: queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43083

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-06
2026-05-06 10:16Z
CRIT

CVE-2026-40010 — Apache Wicket: Missing invocation of Servlet http web request method changeSessionId after session binding can be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40010

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 384VNDApacheVNDServletTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-06
2026-05-06 09:12Z
MED

1 little known secret of forfiles.exe, part 2

Hexacorn·hexacorn.com

Hexacorn demonstrates a second abuse technique for forfiles.exe on Windows, leveraging environment variable expansion in the default cmd /c echo @file command. By creating a file with an environment variable name (e.g., %foo%) and setting that variable to a command payload, forfiles will execute arbitrary code when enumerating the file, enabling command execution via indirect variable substitution.

SRFOsTACTA0005TACTA0002OSWindowsTYPTechniqueSTGDefense EvasionSTGExecutionTECT1036
68
Edit Score
2026-05-06
2026-05-06 08:16Z
HIGH

CVE-2026-7841 — A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7841

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 22:16Z
CRIT

CVE-2026-28780 — Heap: Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 21:16Z
HIGH

CVE-2026-40068 — Anthropic Claude_code: An attacker could craft a malicious repository with a commondir file pointing to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40068

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the victim had previously trusted, causing Claude Code to bypass its trust confirmation dialog and immediately execute hooks defined in `.claude/settings.json`. Exploitation requires the victim to clone the malicious repository and run CVSSv3.1 8.8 (HIGH)

CWECWE 77CWECWE 20VNDAnthropicTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 21:16Z
HIGH

CVE-2026-39852 — Quarkus Quarkus: In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39852

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Quarkus's security layer performs authorization checks on the raw URL path which preserves matrix parameters (semicolons), while RESTEasy Reactive's CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDQuarkusTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-05
2026-05-05 21:16Z
HIGH

CVE-2026-39849 — Pi-hole Ftldns: On installations with no admin password set (the default for many deployments), the configuration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39849

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline characters without validation, allowing an attacker to inject arbitrary directives into the generated dnsmasq configuration file. On installations with no admin password set (the default for many deployments), the configuration API is fully accessible without credentials, allowing a net CVSSv3.1 8.8 (HIGH)

CWECWE 93VNDPi HoleVNDFtlTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 21:16Z
CRIT

CVE-2026-35579 — Coredns.io Coredns: An unauthenticated network attacker can exploit this to bypass TSIG-protected functionality such as AXFR/IXFR

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35579

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in the configuration but never calls dns.TsigVerify() to validate the HMAC. If the key name matches a configured key, the tsigStatus field remains nil and the tsig plugin treats the request as successfully authenticated regardless of the MAC valu CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDCoredns IoVNDCorednsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-44331 — ProFTPD: In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44331

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDProftpdTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-35397 — Jupyter Jupyter_server: In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35397

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named "test", the API permits access to a sibling directory named "testtest" through a crafted request to the /api/contents endpoint using encoded path components CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDJupyterTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-34464 — Sandboxie-plus Sandboxie: This can lead to a crash of the SbieSvc service or potential code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34464

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed WCHAR pipename[160] stack buffer using wcscat without verifying null termination. The handler only enforces a minimum packet size, and since the service pipe accepts variable-length messages, a sandboxed caller can fill the server[48] field with non-zero data and append additio CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 170VNDSandboxie PlusVNDSandboxieTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-34459 — Sandboxie-plus Sandboxie: First, when a sandboxed process sends an IPC request with cbSize set to 0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34459

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that can be chained for sandbox escape. First, when a sandboxed process sends an IPC request with cbSize set to 0, up to 32KB of uninitialized stack memory from the service process is returned, leaking return addresses and stack cookies which bypass ASLR and /GS protections. S CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDSandboxie PlusVNDSandboxieTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-34458 — Sandboxie-plus Sandboxie: In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34458

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandboxie.ini configuration file. The background service skips authorization checks for IPC messages targeting sections beginning with UserSettings_, but does not sanitize CRLF characters CVSSv3.1 8.8 (HIGH)

CWECWE 93VNDSandboxie PlusVNDSandboxieTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 20:16Z
CRIT

CVE-2026-34084 — Phpoffice Phpspreadsheet: The phar:// wrapper triggers deserialization of the PHAR metadata, which can lead to remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34084

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ssh2.sftp://) that passes the is_file() check in File::assertFile(). The phar:// wrapper triggers deserialization of the PHAR metadata, which CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 918VNDPhpofficeVNDPhpspreadsheetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-33324 — Fit2cloud Sqlbot: In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33324

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the SQL extracted from the LLM response is executed against the database without validation or sanitization. An authenticated attacker can craft a malicious question to manipulate the L CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDFit2cloudVNDSqlbotTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 19:46Z
INFO

BloodHound CE v9.1.0

BloodHound releases·github.com

BloodHound CE v9.1.0 released with incremental improvements including PDF attack paths table export, UI component refactoring (Doodle UI migration), OpenGraph extension permissions, and various bug fixes across graph rendering, authentication, and data ingestion.

SWBloodhoundTYPTool
35
Edit Score