2026-04-20
2026-04-20 07:16Z
CRIT

CVE-2026-6644 — Asustor Data_master: A command injection vulnerability was found in the PPTP VPN Clients on the ADM.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6644

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and CVSSv3.1 9.1 (CRITICAL) · EPSS 55th percentile

CWECWE 78VNDAsustorTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-20
2026-04-20 06:24Z
HIGH

AzureAD-Attack-Defense — This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Activ

GitHub · Azure / Entra tools·github.comGITHUB POC

AzureAD-Attack-Defense is a comprehensive community-driven playbook documenting attack and defense scenarios against Microsoft Entra ID (Azure AD). The repository covers password spray, consent grant abuse, service principal exploitation in Azure DevOps, Entra Connect sync account abuse, PRT token replay, and adversary-in-the-middle phishing attacks, with detection rules and mitigation strategies mapped to MITRE ATT&CK framework.

TACTA0001TACTA0006SRFIdentitySRFCloudTACTA0008TACTA0009VNDMicrosoftTYPResearch
82
Edit Score
2026-04-20
2026-04-20 00:00Z
CRIT

The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables

Trend Micro Research·trendmicro.comin the wild

Vercel suffered a supply-chain OAuth compromise originating from Lumma Stealer malware infection at third-party vendor Context.ai in February 2026. Attackers leveraged stolen Google Workspace OAuth tokens to pivot into Vercel's internal systems and enumerate customer environment variables, exposing non-sensitive credentials stored unencrypted at rest. The incident demonstrates how OAuth trust relationships bypass perimeter defenses and how default-insecure environment variable models amplify blast radius across downstream services.

TACTA0004TACTA0001TACTA0006TACTA0007TACTA0003SRFCloudSRFSupply ChainVNDGoogle
88
Edit Score
2026-04-19
2026-04-19 18:52Z
HIGH

magnetar — A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process pro

GitHub · EDR bypass / evasion·github.comGITHUB POC

Magnetar is a Windows 10 64-bit shellcode loader framework designed to bypass EDR solutions through ETW/AMSI patching, direct syscalls via Tartarus Gate, process injection techniques (Early Bird APC, Process Hypnosis), PPID spoofing, and process protection mechanisms. The author intentionally removed the critical syscall obfuscation component from the public release due to its demonstrated effectiveness against Sophos EDR, requiring users to supply their own implementation.

SRFOsTACTA0005TACTA0002OSWindowsTYPToolSTGDefense EvasionSTGExecutionEXPProcess Injection
78
Edit Score
2026-04-18
2026-04-18 17:16Z
CRIT

CVE-2026-41242 — Protobufjs_project Protobufjs: In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41242

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDProtobufjs ProjectTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-18
2026-04-18 02:16Z
HIGH

CVE-2026-40487 — Gitroom Postiz: Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40487

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a Content-Type derived from their original extension (`text/html`, `image/svg+xml`), enabling Stored Cross-Site Scripting (XSS) in the context of the application's origin. This can le CVSSv3.1 8.9 (HIGH)

CWECWE 434CWECWE 345CWECWE 79VNDGitroomVNDPostizTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-04-18
2026-04-18 02:16Z
HIGH

CVE-2026-35582 — Nsa Emissary: In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35582

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /bin/sh -c shell command string without any escaping or input validation. The IN_FILE_ENDING and OUT_FILE_ENDING configuration keys flow directly into these paths, allowing a place author who can write or modify a .cfg file to inject arbitrary shell metacharacters that execute OS co CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 78CWECWE 116VNDNsaVNDEmissaryTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-18
2026-04-18 02:11Z
HIGH

v3.8.0

Nuclei releases·github.comGHSA-29rg-wmcw-hpf4GHSA-jm34-66cf-qpvr

Nuclei v3.8.0 released with two security fixes addressing sandbox escape vectors: JS module now respects allow-local-file-access in require() calls, and template expressions are now restricted to template-authored code only. The release also includes 20+ bug fixes covering race conditions, path handling, and concurrent map writes across fuzzing, WebSocket, and HTTP modules.

SRFApplicationVNDProjectdiscoveryTYPTool
72
Edit Score
2026-04-18
2026-04-18 01:16Z
CRIT

CVE-2026-40572 — Minecanton209 Novumos: In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40572

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions, including critical kernel structures such as the IDT, GDT, TSS, and page tables. A local attacker can exploit this to modify kernel interrupt handlers, resulting in privilege escalation from user mode to CVSSv3.1 9.0 (CRITICAL) · EPSS 4th percentile

CWECWE 269VNDMinecanton209VNDNovumosTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-18
2026-04-18 01:16Z
HIGH

CVE-2026-40350 — Leepeuker Movary: Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40350

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the route definitions do not enforce admin-only middleware, and the controller-level authorization check uses a broken boolean condition. As a result, any user with a valid web session cookie c CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 863VNDLeepeukerVNDMovaryTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-18
2026-04-18 01:16Z
CRIT

CVE-2026-40317 — Minecanton209 Novumos: In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40317

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allowing any Ring 3 user-mode process to jump to kernel addresses and execute arbitrary code in Ring 0 context, resulting in local privilege escalation. This issue has been fixed in version 0.24. If developers are unable to immediately update, they should restrict CVSSv3.1 9.3 (CRITICAL) · EPSS 6th percentile

CWECWE 269CWECWE 20VNDMinecanton209VNDNovumosTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-18
2026-04-18 00:16Z
HIGH

CVE-2026-40349 — Leepeuker Movary: Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40349

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a user edit their own profile, but it updates the sensitive `isAdmin` field without any admin-only authorization check. Version 0.71.1 patches the issue. CVSSv3.1 8.8 (HIGH) · EPSS 3th percentile

CWECWE 862VNDLeepeukerVNDMovaryTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-18
2026-04-18 00:16Z
CRIT

CVE-2026-40324 — Hot: This occurs before any validation rules run — `MaxExecutionDepth`, complexity analyzers, persisted query allow-lists

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40324

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types can trigger a `StackOverflowException` on payloads as small as 40 KB. Because `StackOverflowException` is uncatchable in .NET (since .NET 2.0), the entire worker process is termina CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile

CWECWE 674VNDHotTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-18
2026-04-18 00:09Z
MED

A few more protocol handlers :), Part 2

Hexacorn·hexacorn.com

Hexacorn documents newly discovered Windows 11 25H2 protocol handlers, expanding a multi-year catalog of custom URI schemes that can be abused for code execution and defense evasion. The post identifies 30+ new handlers including ms-recall, ms-devhome, ms-launchremotedesktop, and others that may present attack surface for protocol handler exploitation.

SRFOsTACTA0001VNDMicrosoftTYPResearchSTGInitial Access
68
Edit Score
2026-04-17
2026-04-17 22:16Z
CRIT

CVE-2026-5720 — Miniupnp_project Miniupnpd: contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5720

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the CVSSv3.1 9.1 (CRITICAL) · EPSS 19th percentile

CWECWE 125CWECWE 191VNDMiniupnp ProjectTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-17
2026-04-17 22:16Z
CRIT

CVE-2026-40478 — Thymeleaf Thymeleaf: Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40478

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine CVSSv3.1 9.0 (CRITICAL) · EPSS 12th percentile

CWECWE 1336CWECWE 917VNDThymeleafTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-17
2026-04-17 22:16Z
CRIT

CVE-2026-40477 — Thymeleaf Thymeleaf: Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40477

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input d CVSSv3.1 9.0 (CRITICAL) · EPSS 12th percentile

CWECWE 1336CWECWE 917VNDThymeleafTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-17
2026-04-17 22:16Z
HIGH

CVE-2026-40352 — Fastgpt Fastgpt: In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40352

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 943VNDFastgptTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-17
2026-04-17 22:16Z
CRIT

CVE-2026-40351 — Fastgpt Fastgpt: This NoSQL injection bypasses the password check, enabling login as any user including the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40351

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. This issue has been fixed in version 4.14.9.5. CVSSv3.1 9.8 (CRITICAL) · EPSS 19th percentile

CWECWE 943VNDFastgptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-17
2026-04-17 22:16Z
HIGH

CVE-2026-40321 — Dnnsoftware Dotnetnuke: DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40321

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. CVSSv3.1 8.0 (HIGH)

CWECWE 87VNDDnnsoftwareVNDDnnTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-17
2026-04-17 22:16Z
CRIT

CVE-2026-40258 — Gramps: Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40258

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. An authenticated user with owner-level privileges can craft a malicious ZIP file with directory-traversal filenames to write arbitrary files outside the intended temporary extraction directory on the server's local filesystem. Startig in version 3.11.1, ZIP entry names are now v CVSSv3.1 9.1 (CRITICAL) · EPSS 21th percentile

CWECWE 22VNDGrampsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-17
2026-04-17 22:16Z
CRIT

CVE-2026-29013 — Libcoap Libcoap: contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-29013

libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options or responses during OSCORE negotiation to trigger out-of-bounds reads during CBOR parsing and potentially cause out-of-bounds reads through integer wraparound i CVSSv3.1 9.8 (CRITICAL) · EPSS 14th percentile

CWECWE 125VNDLibcoapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-17
2026-04-17 21:16Z
HIGH

CVE-2026-40196 — Sysadminsmedia Homebox: Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40196

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and prevented the user from viewing or modifying the group's contents, the API did not. Because the original group ID persisted as the user's defaultGroup, and this CVSSv3.1 8.1 (HIGH)

CWECWE 708VNDSysadminsmediaVNDHomeboxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-17
2026-04-17 21:16Z
HIGH

CVE-2026-35512 — Neutrinolabs Xrdp: Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35512

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediate CVSSv3.1 8.8 (HIGH) · EPSS 75th percentile

CWECWE 122VNDNeutrinolabsVNDRdpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-17
2026-04-17 21:16Z
CRIT

CVE-2026-33689 — Neutrinolabs Xrdp: Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33689

xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence of packets during the initial connection phase. This vulnerability results from insufficient validation of input buffer lengths before processing dynamic channel communication. Successful exploitation can lead to a denial-of-servi CVSSv3.1 9.1 (CRITICAL) · EPSS 48th percentile

CWECWE 125VNDNeutrinolabsVNDRdpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score