2026-04-23
2026-04-23 20:16Z
CRIT

CVE-2026-25874 — Huggingface Lerobot: through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25874

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls. CVSSv3.1 9.8 (CRITICAL) · EPSS 96th percentile

CWECWE 502VNDHuggingfaceVNDLerobotTYPVulnerability
9.8
CVSS v3.1
100
Edit Score
2026-04-23
2026-04-23 19:17Z
CRIT

CVE-2026-6074 — Intrado: 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6074

Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended directory. CVSSv3.1 9.8 (CRITICAL) · EPSS 22th percentile

CWECWE 35VNDIntradoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 19:17Z
HIGH

CVE-2026-41246 — Contour: From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41246

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[].pathRewrite.value that results in arbitrary code execution in the Envoy proxy. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDContourTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-23
2026-04-23 19:17Z
HIGH

CVE-2026-41241 — pretalx is a conference planning tool.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41241

pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown using innerHTML string interpolation. Any user who controls one of those fields (which includes any registered user whose display name is looked up by an administrator) could include HTML or JavaScript that would execute in an organiser's browser when the organiser's search query CVSSv3.1 8.7 (HIGH)

CWECWE 79TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-23
2026-04-23 18:16Z
HIGH

CVE-2026-6921 — Google Chrome: Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6921

Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDGoogleVNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-6920 — Google Chrome: Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6920

Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 125VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-6919 — Google Chrome: Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6919

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-23
2026-04-23 18:16Z
HIGH

CVE-2026-5039 — Tp-link Tl-wr841n_firmware: A network-adjacent attacker can exploit this weakness to gain unauthorized access to the protocol

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5039

TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker can exploit this weakness to gain unauthorized access to the protocol, read debug data, modify certain device configuration values, and trigger device reboot, resulting in loss of integrity and a denial-of-service condition. CVSSv3.1 8.8 (HIGH) · EPSS 3th percentile

CWECWE 1394VNDTp LinkVNDLinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-31533 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31533

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-free due to double cleanup of encrypt_pending and the scatterlist entry. When crypto_aead_encrypt() returns -EBUSY, the request is enqueued to the cryptd backlog and the async callback tls_enc CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-31181 — ToToLink: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31181

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-31178 — ToToLink: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31178

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-31177 — ToToLink: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31177

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 18:16Z
CRIT

CVE-2026-31175 — Totolink A3300r_firmware: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31175

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2026-40472 — In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40472

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks. CVSSv3.1 9.9 (CRITICAL)

CWECWE 79TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2026-40471 — Site: hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40471

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts). CVSSv3.1 9.6 (CRITICAL)

CWECWE 352TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2026-40470 — XSS: A critical XSS vulnerability affected hackage-server and hackage.haskell.org.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40470

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses to the package pages or documentation uploaded by a malicious package maintainer, their session can be hijacked to upload packages or documentation, amend maintainers or other pack CVSSv3.1 9.9 (CRITICAL)

CWECWE 79VNDXssTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2026-39087 — Ntfy: An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39087

An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDNtfyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2026-23751 — Kofax: An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23751

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a remote System.Net.WebClient object and read arbitrary files from the server fil CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 441VNDKofaxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2025-62373 — Pipecat: This means that a malicious WebSocket client can send a crafted pickle payload to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-62373

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integration. The class's `deserialize()` method uses Python's `pickle.loads()` on data received from WebSocket clients without any validation or sanitization. This means that a malicious W CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDPipecatTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 16:16Z
CRIT

CVE-2025-50229 — Jizhicms: v2.5.4 is vulnerable to SQL injection in the product editing module.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-50229

Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDJizhicmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 16:00Z
INFO

MSSQLHound Now Available in Go

SpecterOps·specterops.io

SpecterOps released MSSQLHound in Go, a rewrite of the PowerShell MSSQL reconnaissance tool that dramatically improves performance (17 minutes to 17 seconds), adds cross-platform support, SOCKS proxying, NT hash/Kerberos authentication, and integrates with BloodHound's OpenGraph schema for attack path visualization. The Go version adds 7 new nodes and 37 new MSSQL attack path edges while maintaining feature parity with the original.

SRFApplicationTACTA0007VNDBloodhoundVNDSpecteropsTYPToolSTGDiscoverySTGLat MovementTECT1087
72
Edit Score
2026-04-23
2026-04-23 15:42Z
CRIT

CVE-2026-33824: Remote Code Execution in Windows IKEv2

Zero Day Initiative·thezdi.comCVE-2026-33824

CVE-2026-33824 is a double-free vulnerability in Windows IKEv2 (IKEEXT.DLL) triggered during fragment reassembly when processing crafted IKE_SA_INIT and IKE_AUTH messages. An unauthenticated remote attacker can send malicious packets to UDP ports 500/4500 to achieve arbitrary code execution under SYSTEM context. Microsoft patched this in April 2026; detection requires correlating specific byte sequences across sequential IKE packets.

SRFOsTACTA0001TACTA0002SRFNetworkVNDMicrosoftTYPWriteupTYPVulnerabilitySTGExecution
9.8
CVSS v3.1
82
Edit Score
2026-04-23
2026-04-23 15:37Z
HIGH

CVE-2026-41461 — SocialEngine: versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41461

SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can supply arbitrary URLs including internal network addresses and loopback addresses to cause the server to issue HTTP requests to attacker-controlled destinations, enabling internal CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDSocialengineTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-23
2026-04-23 15:37Z
CRIT

CVE-2026-41460 — SocialEngine: versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41460

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary data from the database, reset administrator account passwords, and gain unauthorized access to the Packages Manager in the Admin Panel, potentially enabling CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSocialengineTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 13:16Z
CRIT

CVE-2026-39440 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39440

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94TYPVulnerability
9.9
CVSS v3.1
100
Edit Score