2026-04-20
2026-04-20 21:16Z
CRIT

CVE-2026-33432 — Roxy-wi Roxy-wi: An unauthenticated attacker can inject LDAP filter metacharacters into the username field to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33432

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without escaping LDAP special characters. An unauthenticated attacker can inject LDAP filter metacharacters into the username field to manipulate the search query, cause the directory to retur CVSSv3.1 9.1 (CRITICAL) · EPSS 34th percentile

CWECWE 287VNDRoxy WiVNDRoxyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-20
2026-04-20 21:16Z
CRIT

CVE-2026-32613 — Linuxfoundation Spinnaker: This enabled a user to use arbitrary java classes which allow deep access to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32613

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enabled a user to use arbitrary java classes which allow deep access to the system. This enabled CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDLinuxfoundationVNDSpinnakerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-20
2026-04-20 21:16Z
CRIT

CVE-2026-32604 — Linuxfoundation Spinnaker: In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32604

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20VNDLinuxfoundationVNDSpinnakerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-20
2026-04-20 20:16Z
CRIT

CVE-2026-32311 — Reconurge Flowsint: allows a user to create investigations, which are used to manage sketches and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32311

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites, etc) within these nodes and relationships. The nodes can have automated processes execute on the CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDReconurgeVNDFlowsintTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-20
2026-04-20 20:16Z
CRIT

CVE-2026-29649 — Xiangshan Nemu: This can lead to incorrect enforcement of virtualization configuration and may cause unexpected traps

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-29649

NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode write to menvcfg can implicitly modify the hypervisor's environment configuration. This can lead to incorrect enforcement of virtualization configuration and may cause unexpected traps or denial of service when executing cache-block management instructions in virtualized contexts ( CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 693VNDXiangshanVNDNemuTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-20
2026-04-20 18:39Z
LOW

v9.0.2-rc2

BloodHound releases·github.comCVE-2026-33815CVE-2026-33816

BloodHound v9.0.2-rc2 release candidate published with routine maintenance updates including PFC checks, OpenHound collector link addition, and a pgx dependency upgrade to remediate two CVEs (CVE-2026-33815 and CVE-2026-33816).

SRFApplicationVNDBloodhoundVNDSpecter OpsTYPToolTYPVulnerability
9.8
CVSS v3.1
25
Edit Score
2026-04-20
2026-04-20 17:16Z
HIGH

CVE-2026-41445 — KissFFT: before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41445

KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc() to allocate an undersized buffer. Attackers can trigger heap buffer overflow by providing crafted dimensions that cause the multiplication to exceed INT_MAX, allowing writes beyon CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

CWECWE 122CWECWE 190VNDKissfftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-20
2026-04-20 17:16Z
HIGH

CVE-2026-40488 — Openmage Magento: Files are stored in the publicly accessible `media/custom_options/quote/` directory, which lacks server-side execution restrictions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40488

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be trivially bypassed by using alternative PHP-executable extensions such as `.phtml` CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDMagentoVNDOpenmageTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-20
2026-04-20 17:16Z
CRIT

CVE-2026-30269 — Doorman Doorman: Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30269

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privilege escalation to high-privileged roles. CVSSv3.1 9.9 (CRITICAL) · EPSS 13th percentile

CWECWE 269VNDDoormanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-20
2026-04-20 17:16Z
HIGH

CVE-2026-25524 — Openmage Magento: Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25524

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger deserialization when processing `phar://` stream wrapper paths. OpenMage LTS uses these functions with potentially controllable file paths during image validation and m CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDMagentoVNDOpenmageTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-20
2026-04-20 16:16Z
CRIT

CVE-2026-39918 — Vvveb: prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39918

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the define statement to achieve unauthenticated remote code execution as the web server user. CVSSv3.1 9.8 (CRITICAL) · EPSS 47th percentile

CWECWE 94VNDVvvebTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-20
2026-04-20 16:16Z
HIGH

CVE-2026-34427 — Vvveb: prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34427

Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=1 into profile save requests to escalate to Super Administrator privileges, enabling plugin upload functionality for remote code execution. CVSSv3.1 8.8 (HIGH) · EPSS 43th percentile

CWECWE 915VNDVvvebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-20
2026-04-20 16:16Z
HIGH

CVE-2026-26944 — Dell Powerprotect_dp_series_appliance: PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26944

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action. CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-20
2026-04-20 16:16Z
CRIT

CVE-2026-24467 — Filigran Openaev: Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's password reset implementation contains

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24467

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's password reset implementation contains multiple security weaknesses that together allow reliable account takeover. The primary issue is that password reset tokens do not expire. Once a token is generated, it remains valid indefinitely, even if significant time has passed or if ne CVSSv3.1 9.0 (CRITICAL) · EPSS 73th percentile

CWECWE 640VNDOpenaevVNDFiligranTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-20
2026-04-20 14:16Z
CRIT

CVE-2026-5760 — SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment(). CVSSv3.1 9.8 (CRITICAL) · EPSS 59th percentile

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-20
2026-04-20 14:16Z
HIGH

CVE-2026-4048 — Progress Connection_manager_for_objectscale: OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4048

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process. CVSSv3.1 8.4 (HIGH) · EPSS 23th percentile

CWECWE 77VNDProgressVNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-20
2026-04-20 14:16Z
HIGH

CVE-2026-3519 — Progress Connection_manager_for_objectscale: OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3519

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command CVSSv3.1 8.4 (HIGH) · EPSS 23th percentile

CWECWE 77VNDProgressVNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-20
2026-04-20 14:16Z
HIGH

CVE-2026-3518 — Progress Connection_manager_for_objectscale: OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3518

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command CVSSv3.1 8.4 (HIGH) · EPSS 23th percentile

CWECWE 77VNDProgressVNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-20
2026-04-20 14:16Z
HIGH

CVE-2026-3517 — Progress Connection_manager_for_objectscale: OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3517

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command CVSSv3.1 8.4 (HIGH) · EPSS 23th percentile

CWECWE 77VNDProgressVNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-20
2026-04-20 14:16Z
CRIT

CVE-2026-33557 — Apache Kafka: A possible security vulnerability has been identified in Apache Kafka.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33557

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it. We advise the Kafka users using kafka v4.1.0 or CVSSv3.1 9.1 (CRITICAL)

CWECWE 303CWECWE 1285VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-20
2026-04-20 09:22Z
CRIT

FakeWallet crypto stealer spreading through iOS apps in the App Store

Kaspersky Securelist·securelist.comin the wild

Kaspersky discovered 26+ phishing apps in the Apple App Store masquerading as popular cryptocurrency wallets (MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, Bitpie), primarily targeting Chinese users. Once installed, these apps redirect to malicious pages that distribute trojanzed wallet versions engineered to steal recovery phrases and private keys via library injection, method swizzling, and sophisticated phishing overlays. The campaign has been active since at least fall 2025 and employs both hot-wallet credential harvesting and cold-wallet phishing, with some samples also containing SparkKitty modules, suggesting possible threat-actor overlap.

SRFApplicationSRFMobileTACTA0001TACTA0006TACTA0009VNDAppleVNDCoinbaseVNDLedger
82
Edit Score
2026-04-20
2026-04-20 09:16Z
HIGH

CVE-2026-5967 — Teamt5 Threatsonar_anti-ransomware: ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5967

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges. CVSSv3.1 8.8 (HIGH) · EPSS 34th percentile

CWECWE 78VNDTeamt5VNDThreatsonarTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-20
2026-04-20 08:16Z
HIGH

CVE-2026-5966 — Teamt5 Threatsonar_anti-ransomware: ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5966

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system. CVSSv3.1 8.1 (HIGH) · EPSS 57th percentile

CWECWE 22CWECWE 23VNDTeamt5VNDThreatsonarTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-20
2026-04-20 08:16Z
CRIT

CVE-2026-5964 — Digiwin Easyflow_.net: EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5964

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. CVSSv3.1 9.8 (CRITICAL) · EPSS 28th percentile

CWECWE 89VNDDigiwinVNDEasyflowTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-20
2026-04-20 08:16Z
CRIT

CVE-2026-5963 — Digiwin Easyflow_.net: EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5963

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. CVSSv3.1 9.8 (CRITICAL) · EPSS 28th percentile

CWECWE 89VNDDigiwinVNDEasyflowTYPVulnerability
9.8
CVSS v3.1
99
Edit Score