2026-05-05
2026-05-05 20:16Z
HIGH

CVE-2026-33324 — Fit2cloud Sqlbot: In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33324

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the SQL extracted from the LLM response is executed against the database without validation or sanitization. An authenticated attacker can craft a malicious question to manipulate the L CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDFit2cloudVNDSqlbotTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 19:46Z
INFO

BloodHound CE v9.1.0

BloodHound releases·github.com

BloodHound CE v9.1.0 released with incremental improvements including PDF attack paths table export, UI component refactoring (Doodle UI migration), OpenGraph extension permissions, and various bug fixes across graph rendering, authentication, and data ingestion.

SWBloodhoundTYPTool
35
Edit Score
2026-05-05
2026-05-05 19:16Z
HIGH

CVE-2026-7855 — Performing a manipulation of the argument Name results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7855

A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of the argument Name results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 19:16Z
CRIT

CVE-2026-7854 — Such manipulation leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7854

A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 19:16Z
CRIT

CVE-2026-38428 — Kestra: v1.3.3 and before is vulnerable to SQL Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDKestraTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 19:16Z
CRIT

CVE-2026-27960 — OpenCTI: In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27960

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue has been fixed in version 6.9.13. As a workaround, the default admin can be disabled using the `APP__ADMIN__EXTERNALLY_MANAGED` configuration. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDOpenctiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 18:16Z
CRIT

CVE-2026-7853 — This manipulation of the argument enable/time causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7853

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-05
2026-05-05 17:17Z
CRIT

CVE-2026-38431 — ERPNext: v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38431

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDErpnextTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 17:17Z
CRIT

CVE-2026-38429 — OpenCMS: v20 and before is vulnerable to XML External Entity (XXE) in the Admin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38429

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml. CVSSv3.1 9.8 (CRITICAL)

CWECWE 611VNDOpencmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 17:17Z
HIGH

CVE-2026-25589 — Redisbloom Redisbloom: An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25589

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTOR CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDRedisbloomTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 17:17Z
HIGH

CVE-2026-25588 — Redistimeseries Redistimeseries: An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25588

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDRedistimeseriesTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 17:17Z
HIGH

CVE-2026-25243 — Redis Redis: An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25243

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDRedisTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 17:17Z
HIGH

CVE-2026-23631 — Redis Redis: In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23631

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3. CVSSv3.1 8.1 (HIGH)

CWECWE 416VNDRedisTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-05
2026-05-05 17:17Z
HIGH

CVE-2026-23479 — Redis Redis: If a blocked client is evicted during this flow, an authenticated attacker can trigger

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23479

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3. CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDRedisTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 17:05Z
CRIT
78
Edit Score
2026-05-05
2026-05-05 16:16Z
HIGH

CVE-2026-7412 — Eclipse: This allows an attacker to bypass network segmentation and pivot into isolated internal IT/OT

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7412

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or external targets. This allows an attacker to bypass network segmentation and pivot into isolated internal IT/OT infrastructure or target Cloud Metadata services (IM CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDEclipseTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-05
2026-05-05 16:16Z
CRIT

CVE-2026-7411 — Eclipse: In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7411

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host filesystem accessible by the Java process. This can lead to Remote Code Execution (RC CVSSv3.1 10.0 (CRITICAL)

CWECWE 22VNDEclipseTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-05
2026-05-05 16:16Z
CRIT

CVE-2026-43071 — Linux: In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43071

In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address: ffff888b30b774b0 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page Oops: Oops: 0000 [#1] SMP PTI RIP: 0010:__d_lookup+0x56/0x120 Call Trace: d_lookup.cold+0x16/0x5d lookup_dc CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-05
2026-05-05 16:16Z
CRIT

CVE-2026-43067 — Linux: Does this allow allocating blocks beyond the 32-bit limit for indirect block mapped files?

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43067

In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Commit 4865c768b563 ("ext4: always allocate blocks only from groups inode can use") restricts what blocks will be allocated for indirect block based files to block numbers that fit within 32-bit block numbers. However, when using a review bot running on the latest Gemini LLM to check this commit when backporting into an LTS based CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 16:16Z
HIGH

CVE-2026-31196 — The traceroute diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31196

The traceroute diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authenticated remote attackers to execute arbitrary commands as root via crafted destAddr parameters using shell command substitution. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 16:16Z
HIGH

CVE-2026-31195 — The ping diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31195

The ping diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authenticated remote attackers to execute arbitrary commands as root via crafted destAddr parameters using shell command substitution. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 14:16Z
CRIT

CVE-2026-7834 — Such manipulation leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7834

A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 14:16Z
CRIT

CVE-2026-36356 — GoAhead: The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36356

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306CWECWE 78VNDGoaheadTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-05
2026-05-05 14:16Z
CRIT

CVE-2026-34408 — Gambio: An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34408

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known. CVSSv3.1 9.1 (CRITICAL)

CWECWE 640VNDGambioTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-05
2026-05-05 13:40Z
CRIT

Copy-Fail-CVE-2026-31431-Kubernetes-PoC — PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corrup

GitHub · container escape·github.comGITHUB POCCVE-2026-31431in the wild

A proof-of-concept exploit for CVE-2026-31431 demonstrates a fully unprivileged container escape to node-level code execution on Kubernetes clusters. The attack exploits a Linux kernel page-cache corruption vulnerability in the AF_ALG splice race condition, combined with shared container image layers and privileged DaemonSets (e.g., kube-proxy), to achieve arbitrary code execution with node privileges. The PoC has been validated on Alibaba Cloud ACK and Amazon EKS.

TACTA0004TACTA0005SRFCloudOSLinuxSWKube ProxySWKubernetesTYPExploitTYPVulnerability
95
Edit Score