Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 89TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-14
2026-04-14 00:00Z
CRIT
Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT
Elastic Security Labs·elastic.coin the wild
Elastic Security Labs disclosed a novel supply-chain attack leveraging Obsidian's legitimate community plugin ecosystem to deliver PhantomPulse, a previously undocumented AI-generated RAT. Threat actors conduct social engineering via LinkedIn and Telegram, posing as venture capital firms, to trick targets in financial/crypto sectors into enabling community plugin sync on a malicious Obsidian vault, triggering silent code execution via the Shell Commands plugin. The Windows attack chain employs multi-stage reflective loading with AES-256-CBC encryption, timer-queue callbacks, and blockchain-based C2 resolution via Ethereum transaction data; a critical weakness in the C2 mechanism allows third parties to hijack implants by submitting competing transactions to the monitored wallet.
Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT
Elastic Security Labs·elastic.coin the wild
Elastic Security Labs disclosed a novel social engineering campaign (REF6598) targeting financial and cryptocurrency professionals via LinkedIn and Telegram, abusing Obsidian's legitimate Shell Commands and Hider community plugins to achieve code execution. The attack chain delivers PHANTOMPULSE, a previously undocumented AI-assisted Windows RAT featuring blockchain-based C2 resolution via Ethereum transaction data, cross-platform support (Windows/macOS), and advanced in-memory injection techniques. A critical weakness in the blockchain C2 mechanism allows third parties to hijack implant C2 resolution by submitting competing transactions to the monitored wallet address.
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
Affected Products:
UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio Port (Version 1.0.24 and earlier)
Mitigation:
Update UniFi Play PowerAmp to Version 1.0.38 or later
Update UniFi Play Audio Port to Version 1.1.9 or later
CVSSv3.1 9.8 (CRITICAL)
CWECWE 284VNDAccessTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 22:16Z
CRIT
CVE-2026-22563 — Input: A series of Improper Input Validation vulnerabilities could allow a Command Injection by a
A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network.
Affected Products:
UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio Port (Version 1.0.24 and earlier)
Mitigation:
Update UniFi Play PowerAmp to Version 1.0.38 or later
Update UniFi Play Audio Port to Version 1.1.9 or later
CVSSv3.1 9.8 (CRITICAL)
CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 22:16Z
CRIT
CVE-2026-22562 — A malicious actor with access to the UniFi Play network could exploit a Path
A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE).
Affected Products:
UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier)
Mitigation:
Update UniFi Play PowerAmp to Version 1.0.38 or later Update UniFi Play Audio Port to Version 1.1.9 or later
CVSSv3.1 9.8 (CRITICAL)
CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 22:00Z
INFO
BSIM explained once and for all!
Quarkslab·blog.quarkslab.com
Quarkslab publishes a comprehensive technical deep-dive into Ghidra's BSIM (Behavioral Similarity) algorithm, reverse-engineering its previously undocumented internals. The post covers P-code lifting, normalization, Weisfeiler-Lehman graph hashing, TF-IDF weighting, and cosine similarity comparison used to identify semantically equivalent binary functions across compilers and architectures.
An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.
CVSSv3.1 9.8 (CRITICAL) · EPSS 25th percentile
CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 19:16Z
HIGH
CVE-2026-6200 — Tenda: This manipulation of the argument menufacturer/Go causes stack-based buffer overflow.
A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the file /goform/webtypelibrary. This manipulation of the argument menufacturer/Go causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 19:16Z
HIGH
CVE-2026-6199 — Tenda: The manipulation of the argument page results in stack-based buffer overflow.
A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 19:16Z
HIGH
CVE-2026-6198 — The manipulation of the argument page leads to stack-based buffer overflow.
A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 19:16Z
HIGH
CVE-2026-6197 — Executing a manipulation of the argument mit_ssid can lead to stack-based buffer overflow.
A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Executing a manipulation of the argument mit_ssid can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 19:16Z
CRIT
CVE-2026-40044 — Pachno: 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files with predictable names in the cache directory, which are unserialized during framework bootstrap before authentication checks occur.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 502VNDPachnoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 19:16Z
CRIT
CVE-2026-40042 — Pachno: 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to
Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_NONET restrictions.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 403VNDPachnoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 19:16Z
HIGH
CVE-2026-40040 — Pachno: 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directories and execute them to achieve remote code execution on the server.
CVSSv3.1 8.8 (HIGH)
CWECWE 434VNDPachnoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 19:16Z
HIGH
CVE-2026-29955 — Cloudark Kubeplus: The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command
The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute shell commands, and the user-supplied `chartName` parameter is directly concatenated into the command string without any sanitization or validation. An attacker can inject arbitrary shell commands by crafting a malicious `chartName` parameter value.
CVSSv3.1 8.8 (HIGH) · EPSS 25th percentile
CWECWE 94VNDCloudarkVNDKubeplusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 19:00Z
INFO
BloodHound 9.0 — Product Updates
SpecterOps·specterops.io
SpecterOps released BloodHound 9.0, expanding attack path analysis beyond Active Directory to SaaS platforms including Okta, Jamf, and GitHub via OpenGraph extensions. The release introduces OpenHound (a standardized data collection framework), Environment Targeted Access Control (ETAC) for multi-tenant deployments, and improved graph visualization and query capabilities.
A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 18:16Z
CRIT
CVE-2026-6195 — Such manipulation of the argument admpass leads to os command injection.
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 18:16Z
HIGH
CVE-2026-6194 — This manipulation of the argument wan-url causes stack-based buffer overflow.
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 18:16Z
HIGH
CVE-2026-6100 — Use: Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.
The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `
CVSSv3.1 8.1 (HIGH)
CWECWE 416CWECWE 787CWECWE 825TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-13
2026-04-13 18:16Z
HIGH
CVE-2026-32316 — JSON: An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, cau
CVSSv3.1 8.2 (HIGH)
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as Git's flexible option parsing allows numerous character combinations (e.g., -vu, -4u, -nu) to circumvent the regular-expression-based blocklist in the unsafe operat
CVSSv3.1 8.1 (HIGH)
CWECWE 78VNDGitTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-13
2026-04-13 16:16Z
HIGH
CVE-2026-6186 — The manipulation of the argument NatBind leads to buffer overflow.
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the function strcpy of the file /goform/formNatStaticMap. The manipulation of the argument NatBind leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
CVSSv3.1 8.8 (HIGH)
CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 16:16Z
HIGH
CVE-2025-69627 — Gonitro Nitro_pdf_pro: Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI and logging helper functions. Because the freed memory region may contain unpredictable heap data or remnants of attacker-controlled JavaScript strings, downstream routines such as wcscmp() may proces
CVSSv3.1 8.4 (HIGH)