2026-04-24
2026-04-24 21:16Z
CRIT

CVE-2026-41478 — Saltcorn: Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41478

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depen CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDSaltcornTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-24
2026-04-24 21:16Z
CRIT

CVE-2026-41473 — Cyberpanel Cyberpanel: versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41473

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with ma CVSSv3.1 9.1 (CRITICAL) · EPSS 44th percentile

CWECWE 306VNDCyberpanelTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 21:16Z
CRIT

CVE-2026-41248 — Clerk: createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41248

Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7, 2.17.10, and 3.0.15; @clerk/nextjs 5.7.6, 6.39.2, and 7.2.1; @clerk/nuxt 1.13.28 and 2.2.2; and @clerk/shared 2.22.1, 3.47.4, anc 4.8.1 CVSSv3.1 9.1 (CRITICAL)

CWECWE 863CWECWE 436VNDClerkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 20:17Z
HIGH

Metasploit Wrap-Up 25/04/2026

Metasploit 6.4.129 release adds four new modules including a Langflow prompt-injection RCE (CVE-2026-27966), Camaleon CMS directory traversal, and WebDAV PHP upload exploit with Linux support. The update also improves check method visibility with reasoning information, enhances SMB module reliability for legacy targets, and includes performance optimizations and bug fixes.

SRFApplicationSRFWebVNDRapid7VNDMetasploitTYPToolSTGExecutionEXPRceEXPLfi
68
Edit Score
2026-04-24
2026-04-24 20:16Z
HIGH

CVE-2026-41476 — Deskflow Deskflow: Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41476

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected peer to trigger an out-of-bounds read by sending a malformed clipboard update. The issue is in the implementation of src/lib/deskflow/IClipboard.cpp. This is reachable because ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp validates only the outer clipboard transfer size. It does not validate the CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

CWECWE 120VNDDeskflowTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 20:16Z
CRIT

CVE-2026-41475 — Bacnetstack Bacnet_stack: Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41475

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM request. The vulnerability stems from wpm_decode_object_property() calling the deprecated decode_tag_number_and_value() function, which performs no bounds checking on the input buf CVSSv3.1 9.1 (CRITICAL) · EPSS 34th percentile

CWECWE 125VNDBacnetstackVNDBacnetTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 20:16Z
HIGH

CVE-2026-41433 — OpenTelemetry: From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41433

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a local attacker controlling a Java workload to overwrite arbitrary host files when Java injection is enabled and OBI is running with elevated privileges. The injector trusted TMPDIR from the target process and used unsafe file creation semantics, enabling both filesystem boundary escape and symlink-ba CVSSv3.1 8.4 (HIGH)

CWECWE 22CWECWE 59VNDOpentelemetryTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-24
2026-04-24 20:16Z
HIGH

CVE-2026-41429 — Arduino: Prior to 3.3.8, there is a remotely reachable memory corruption issue in the NBNS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41429

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruption issue in the NBNS packet handling path. When NetBIOS is enabled by calling NBNS.begin(...), the device listens on UDP port 137 and processes untrusted NBNS requests from the local network. The request parser trusts the attacker-controlled name_len field without enforcing a bound consistent with th CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDArduinoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 20:16Z
CRIT

CVE-2026-41428 — Budibase: Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41428

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query string, an attacker can access any protected endpoint by appending a public endpoint path as a query parameter. For example, POST /api/global/users/search?x=/api/system/status bypasses all authentication because the regex /api/system/s CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDBudibaseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 19:17Z
CRIT

CVE-2026-41492 — Dgraph: Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41492

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker can retrieve that token and replay it in the X-Dgraph-AuthToken header to access admin-only endpoints. This is a variant of the previously fixed /debug/pprof/cmdline issue, but the current f CVSSv3.1 9.8 (CRITICAL)

CWECWE 200VNDDgraphTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 19:17Z
HIGH

CVE-2026-41421 — SiYuan: On desktop builds, this is not limited to ordinary XSS.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41421

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast layer, and the frontend inserts it into the DOM with insertAdjacentHTML(...) at message.ts. On desktop builds, this is not limited to ordinary XSS. Electron windows are created with CVSSv3.1 8.8 (HIGH)

CWECWE 79CWECWE 78VNDSiyuanTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 19:17Z
CRIT

CVE-2026-41328 — Dgraph: The second sends a crafted JSON mutation to /mutate?commitNow=true where a JSON key contains

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41328

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with @unique @index(exact) @lang via /alter (also unauthenticated in default config). The second sends a crafted JS CVSSv3.1 9.1 (CRITICAL)

CWECWE 943VNDDgraphTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 19:17Z
CRIT

CVE-2026-41327 — Dgraph: Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41327

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack is a single HTTP POST to /mutate?commitNow=true containing a crafted cond field in an upsert mutation. The cond value is concatenated directly into a DQL query string via strings.Builder.Wri CVSSv3.1 9.1 (CRITICAL)

CWECWE 943VNDDgraphTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 19:17Z
HIGH

CVE-2026-41326 — Katacontainers Confidential_containers: From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41326

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fi CVSSv3.1 8.2 (HIGH) · EPSS 5th percentile

CWECWE 61VNDKatacontainersVNDKataTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-24
2026-04-24 18:16Z
HIGH

CVE-2026-41678 — Rust-openssl_project Rust-openssl: From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() +

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41678

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provi CVSSv3.1 8.1 (HIGH) · EPSS 21th percentile

CWECWE 787VNDOpensslVNDRust Openssl ProjectTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-24
2026-04-24 18:16Z
HIGH

CVE-2026-41140 — Poetry: Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41140

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4. CVSSv3.1 8.7 (HIGH) · EPSS 19th percentile

CWECWE 22VNDPoetryTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 17:16Z
HIGH

CVE-2026-6912 — Improperly: controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6912

Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched CVSSv3.1 8.8 (HIGH)

CWECWE 915VNDImproperlyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 17:16Z
CRIT

CVE-2026-6911 — JWT: Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6911

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the deployment's User Pool, via a crafted JWT sent to the API Gateway endpoint. To remediate this issue, users should redeploy from the updated repository and ensure any forked or deriva CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDJwtTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 17:16Z
HIGH

CVE-2026-40897 — Math: From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40897

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0. CVSSv3.1 8.8 (HIGH)

CWECWE 915VNDMathTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 16:16Z
CRIT

CVE-2026-39920 — BridgeHead: FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39920

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1188CWECWE 1391VNDBridgeheadTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31669 — Linux: In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31669

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU read-side critical sections. Both tcp_prot and tcpv6_prot have their slab caches created with this flag via proto_register(). However, MPTCP's mptcp_subflow_init() copies tcpv6_prot into tcpv6_prot_override during inet_init() (fs_i CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31668 — Linux: In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31668

In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 lwtunnel uses a single dst_cache per encap route, shared between seg6_input_core() and seg6_output_core(). These two paths can perform the post-encap SID lookup in different routing contexts (e.g., ip rules matching on the ingress interface, or VRF table separation). Whichever path runs first populates the cache, and the other reu CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31659 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31659

In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_global_data() builds the allocation length for a global TT response in 16-bit temporaries. When a remote originator advertises a large enough global TT, the TT payload length plus the VLAN header offset can exceed 65535 and wrap before kmalloc(). The full-table response path still uses the original TT payload length when it fill CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31657 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31657

In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow the pointer. The netlink claim dump path dereferences claim->backbone_gw->orig and takes claim->backbone_gw->crc_lock without pinning the underlying backbone gateway. batadv_bla_check_claim() still has the same naked pointer access CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31649 — Linux: On IOMMU-less SoCs (the typical deployment for stmmac), this maps arbitrary kernel memory to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31649

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally computes len = nopaged_len - bmax; where nopaged_len = skb_headlen(skb) (linear bytes only) and bmax is BUF_SIZE_8KiB or BUF_SIZE_2KiB. However, the caller stmmac_xmit() decides to invoke jumbo_frm() based on skb->len (total length including page fragments): is_jumbo = stmmac_is_jumbo_frm(p CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score