2026-04-29
2026-04-29 20:16Z
HIGH

CVE-2018-25300 — XATABoost: CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25300

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDXataboostTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-29
2026-04-29 20:16Z
HIGH

CVE-2018-25299 — Prime95: 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25299

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and execute system commands. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDPrime95TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-29
2026-04-29 20:02Z
INFO

v2.12.1-rc2

AzureHound releases·github.com

AzureHound v2.12.1-rc2 release candidate includes bug fixes for Management Group collection scoping, Microsoft Graph authorization error handling, access token decoding, request timeouts, and GitHub Actions artifact signing. This is a pre-release version with incremental improvements to the Azure reconnaissance tool.

SRFIdentitySRFCloudSWAzurehoundVNDSpecteropsTYPTool
35
Edit Score
2026-04-29
2026-04-29 20:00Z
CRIT

CVE-2026-41940: cPanel & WHM Authentication Bypass

Rapid7 Research·rapid7.comCVE-2026-41940in the wild

CVE-2026-41940 is a critical authentication bypass (CVSS 9.8) in cPanel & WHM caused by CRLF injection in session handling. Unauthenticated attackers can manipulate the `whostmgrsession` cookie to inject arbitrary session properties (e.g., `user=root`), gaining administrative access. The vulnerability is actively exploited in the wild with evidence of zero-day activity since February 2026; a public PoC is available.

SRFApplicationTACTA0001SRFWebSWCpanelSWWhmSWWp SquaredVNDCpanelTYPVulnerability
95
Edit Score
2026-04-29
2026-04-29 19:16Z
HIGH

CVE-2026-7466 — AgentFlow: contains an arbitrary code execution vulnerability that allows attackers to execute local Python

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7466

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to load and execute existing Python pipeline files on disk, resulting in code execution in the context of the user running AgentFlow. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDAgentflowTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-29
2026-04-29 19:16Z
HIGH

CVE-2026-7424 — Integer: underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7424

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single crafted DHCPv6 packet. The issue is present whenever DHCPv6 is enabled. To mitigate this issue, users should upgrade to version V4.2.6 or V4.4.1 CVSSv3.1 8.1 (HIGH)

CWECWE 191TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-29
2026-04-29 19:16Z
CRIT

CVE-2026-30893 — Wazuh: From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30893

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the intended extraction directory on other cluster nodes. This can be escalated to code execution in the Wazuh service context by overwriting Python modules loaded by Wazuh components (p CVSSv3.1 9.0 (CRITICAL)

CWECWE 22CWECWE 73VNDWazuhTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-29
2026-04-29 19:08Z
CRIT

CVE-2026-41940

Horizon3.ai·horizon3.aiCVE-2026-41940

CVE-2026-41940 is a critical authentication bypass in cPanel and WHM (CVSS 9.8) that allows unauthenticated remote attackers to establish authenticated sessions without valid credentials. The vulnerability impacts the login flow itself and enables full administrative control over hosting environments. cPanel has released patches across multiple version tiers (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 and later).

SRFApplicationTACTA0001SRFWebSWCpanelSWWhmVNDCpanelTYPVulnerabilityTYPAdvisory
92
Edit Score
2026-04-29
2026-04-29 18:16Z
HIGH

CVE-2026-5712 — This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5712

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing. CVSSv3.1 8.0 (HIGH)

CWECWE 863TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-29
2026-04-29 18:16Z
CRIT

CVE-2026-26015 — Arc53 Docsgpt: From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26015

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 53th percentile

CWECWE 77VNDArc53VNDDocsgptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-29
2026-04-29 17:19Z
CRIT

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)

watchTowr Labs·labs.watchtowr.comCVE-2026-41940in the wild0day

watchTowr Labs disclosed CVE-2026-41940, a critical authentication bypass in cPanel & WHM affecting all supported versions. The vulnerability combines CRLF injection via HTTP Basic auth headers with improper session encoding to forge authenticated sessions and gain root-level access to the control panel. In-the-wild exploitation has been confirmed; patches are available across all release tracks (110.0.x through 136.0.x).

SRFApplicationTACTA0001TACTA0006SRFWebSWCpanelSWWhmVNDCpanelTYPResearch
98
Edit Score
2026-04-29
2026-04-29 17:16Z
HIGH

CVE-2026-0204 — A vulnerability in the access control mechanism of SonicOS may allow certain management interface

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0204

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. CVSSv3.1 8.0 (HIGH)

CWECWE 306CWECWE 1390TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-29
2026-04-29 16:16Z
HIGH

CVE-2026-6849 — Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6849

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-29
2026-04-29 16:16Z
CRIT

CVE-2026-5166 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5166

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pardus Software Center: before 1.0.3. CVSSv3.1 9.6 (CRITICAL)

CWECWE 22TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-29
2026-04-29 16:16Z
CRIT

CVE-2026-41940 — WHM: cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41940

cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDWhmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-29
2026-04-29 16:16Z
HIGH

CVE-2026-38991 — Cockpit: This allows an authenticated attacker to rename arbitrary files with the .php file extension

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38991

Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary files with the .php file extension enabling arbitrary code to be executed on the underlying server. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDCockpitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-29
2026-04-29 15:16Z
HIGH

CVE-2026-7111 — Text: Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7111

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through CVSSv3.1 8.4 (HIGH)

CWECWE 416CWECWE 825VNDTextTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-29
2026-04-29 15:16Z
HIGH

CVE-2026-5161 — Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5161

Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before v1.2.1. CVSSv3.1 8.8 (HIGH)

CWECWE 59TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-29
2026-04-29 15:16Z
HIGH

CVE-2026-5141 — Privilege: Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5141

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: before 1.0.3. CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 266CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-29
2026-04-29 15:16Z
CRIT

CVE-2026-38992 — Cockpit: v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38992

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDCockpitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-29
2026-04-29 15:16Z
CRIT

CVE-2026-36841 — TOTOLINK: N200RE V5 was discovered to contain a command injection vulnerability via the macstr

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36841

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-29
2026-04-29 14:16Z
CRIT

CVE-2026-5140 — CRLF: Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5140

Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus allows Authentication Bypass. This issue affects Pardus: from <=0.6.4 before 0.8.0. CVSSv3.1 9.6 (CRITICAL)

CWECWE 93VNDCrlfTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-29
2026-04-29 14:16Z
HIGH

CVE-2026-42524 — Jenkins: HTML Publisher Plugin 427 and earlier does not escape job name and URL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42524

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDJenkinsTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-29
2026-04-29 14:16Z
CRIT

CVE-2026-42523 — Jenkins: GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42523

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission. CVSSv3.1 9.0 (CRITICAL)

CWECWE 79VNDJenkinsTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-29
2026-04-29 12:16Z
CRIT

CVE-2026-42249 — Ollama Ollama: for Windows contains a Remote Code Execution vulnerability in its update mechanism due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42249

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers without validation. These values are passed directly to filepath.Join, allowing path traversal sequences (../) to be resolved and enabling files to be written outside the intended update staging directory. An a CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

CWECWE 22CWECWE 494VNDOllamaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score