2026-04-21
2026-04-21 21:16Z
CRIT

CVE-2026-34285 — Oracle Identity_manager_connector: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34285

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDOracleVNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-21
2026-04-21 21:16Z
CRIT

CVE-2026-34279 — Oracle Enterprise_manager_base_platform: Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34279

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Su CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile

CWECWE 306VNDOracleVNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-21
2026-04-21 21:16Z
CRIT

CVE-2026-34275 — Oracle Advanced_inbound_telephony: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34275

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 9.8 (Confidentiality, Integ CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

CWECWE 306VNDOracleVNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-21
2026-04-21 21:16Z
CRIT

CVE-2026-33519 — Esri Portal_for_arcgis: An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. CVSSv3.1 9.8 (CRITICAL) · EPSS 17th percentile

CWECWE 266VNDEsriTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-21
2026-04-21 21:16Z
CRIT

CVE-2026-33518 — Esri Portal_for_arcgis: An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33518

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. CVSSv3.1 9.8 (CRITICAL) · EPSS 17th percentile

CWECWE 266VNDEsriTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-21
2026-04-21 21:16Z
HIGH

CVE-2026-21997 — Oracle Life_sciences_empirica_signal: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21997

Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal. While the vulnerability is in Oracle Life Sciences Empirica Signal, attacks may significantly impact additional products (scope change). Successful at CVSSv3.1 8.5 (HIGH) · EPSS 8th percentile

CWECWE 284VNDOracleVNDVulnerabilityTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-21
2026-04-21 21:16Z
HIGH

CVE-2025-70420 — Genesys Latitude: A SQL injection vulnerability exists in Genesys Latitude v25.1.0.420 that allows an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-70420

A SQL injection vulnerability exists in Genesys Latitude v25.1.0.420 that allows an authenticated attacker to execute arbitrary SQL queries against the backend database. The vulnerability is caused by unsanitized user-supplied input being concatenated directly into SQL statements. CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

CWECWE 89VNDGenesysTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-21
2026-04-21 20:17Z
HIGH

CVE-2026-6819 — Hkuds Openharness: prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6819

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can remotely manage plugin trust and activation state, enabling unauthorized plugin installation and activation on the system. CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 276VNDHkudsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 20:17Z
HIGH

CVE-2026-40909 — Wwbn Avideo: An admin attacker (or any user who can CSRF an admin, since no CSRF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40909

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` parameter is then written verbatim to that path via `fwrite()` at line 40. An admin attacker (or any user who can CSRF an admin, since no CSRF token is checked and cookies use `SameSite=None`) can traverse out of the `local CVSSv3.1 8.7 (HIGH)

CWECWE 22VNDWwbnTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 20:17Z
CRIT

CVE-2026-40903 — Goshs Goshs: ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40903

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6. CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile

CWECWE 829VNDGoshsVNDSimplehttpserverTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-21
2026-04-21 20:17Z
HIGH

CVE-2026-40885 — Goshs Goshs: is a SimpleHTTPServer written in Go.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40885

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the collaborator websocket broadcasts raw request headers, including Authorization. An unauthenticated observer can capture a victim's folder-specific basic-auth header and replay it to CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

CWECWE 200VNDGoshsVNDSimplehttpserverTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 20:17Z
CRIT

CVE-2026-40884 — Goshs Goshs: Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40884

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install any SFTP password handler. As a result, an unauthenticated network attacker can connect to the SFTP service and access files without a password. This vulnerability is fixed in 2.0.0-beta.6. CVSSv3.1 9.8 (CRITICAL) · EPSS 17th percentile

CWECWE 306VNDGoshsVNDSimplehttpserverTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-21
2026-04-21 20:17Z
HIGH

CVE-2026-40883 — Goshs Goshs: From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40883

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because goshs relies on HTTP basic auth alone and performs no CSRF, Origin, or Referer validation for those routes. This vulnerability is fixed in 2.0.0-beta.6. CVSSv3.1 8.1 (HIGH) · EPSS 5th percentile

CWECWE 352VNDGoshsVNDSimplehttpserverTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-21
2026-04-21 20:17Z
HIGH

CVE-2026-40880 — Zfnd Zebra-consensus: Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40880

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from t CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

CWECWE 1025VNDZfndVNDZebraTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-21
2026-04-21 20:17Z
HIGH

CVE-2026-40876 — Goshs Goshs: is a SimpleHTTPServer written in Go.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40876

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose or modify unrelated server files. The SFTP subsystem routes requests through sftpserver/sftpserver.go into DefaultHandler.GetHandler() in sftpserver/handler.go, which forwards fil CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 22VNDGoshsVNDSimplehttpserverTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 20:16Z
CRIT

CVE-2026-40372 — Microsoft Asp.net_core: Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40372

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

CWECWE 347VNDMicrosoftTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-21
2026-04-21 19:16Z
HIGH

CVE-2026-40868 — Kyverno Kyverno: Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ...

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40868

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a policy does not explicitly set an Authorization header. Because context.apiCall.service.url is policy-controlled, this can send the kyverno serviceaccount token to an attacker-controlled endpoint (confused deputy). Namespaced policies are bloc CVSSv3.1 8.1 (HIGH) · EPSS 9th percentile

CWECWE 922VNDKyvernoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-21
2026-04-21 19:16Z
HIGH

CVE-2026-40614 — Pjsip Pjsip: In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40614

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames due to insufficient buffer size validation in the Opus codec decode path. The FEC decode buffers (dec_frame[].buf) were allocated based on a PCM-derived formula: (sample_rate/1000) * 60 * channel_cnt * 2. At 8 kHz mono this yields only 960 bytes, but codec_parse() can output encoded frames up to MAX_ENCODED_PACKET_SIZE CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDPjsipTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 18:16Z
HIGH

CVE-2026-40611 — Encrypt: Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40611

Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fixed in 4.34.0. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDEncryptTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 17:16Z
CRIT

CVE-2026-5652 — Craftycontrol Crafty_controller: An insecure direct object reference vulnerability in the Users API component of Crafty Controller

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5652

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. CVSSv3.1 9.0 (CRITICAL) · EPSS 21th percentile

CWECWE 639VNDCraftycontrolTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-21
2026-04-21 17:16Z
HIGH

CVE-2026-40583 — Ultradag Ultradag: In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40583

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred. CVSSv3.1 8.2 (HIGH) · EPSS 12th percentile

CWECWE 460CWECWE 696VNDUltradagTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-21
2026-04-21 17:16Z
CRIT

CVE-2026-38835 — Tenda W30e_firmware: W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38835

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. CVSSv3.1 9.8 (CRITICAL) · EPSS 38th percentile

CWECWE 77VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-21
2026-04-21 17:16Z
HIGH

CVE-2026-21571 — Atlassian Bamboo: This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21571

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands on the remote system, which has high impact to confidentiality, high impact to integrity CVSSv3.1 8.8 (HIGH) · EPSS 67th percentile

CWECWE 78VNDAtlassianVNDCriticalTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-21
2026-04-21 17:05Z
LOW

v9.0.2

BloodHound releases·github.comCVE-2026-33815CVE-2026-33816

BloodHound v9.0.2 released with routine maintenance updates including cipher additions, Azure post-processing fixes, and a pgx dependency upgrade to remediate two CVEs in the database driver. The release includes minor feature additions and build improvements.

SRFApplicationVNDBloodhoundVNDSpecter OpsTYPToolTYPVulnerability
9.8
CVSS v3.1
35
Edit Score
2026-04-21
2026-04-21 16:16Z
CRIT

CVE-2025-15638 — Atrodo Net\: Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15638

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437. CVSSv3.1 10.0 (CRITICAL) · EPSS 46th percentile

VNDAtrodoTYPVulnerability
10.0
CVSS v3.1
100
Edit Score