2026-04-13
2026-04-13 16:16Z
HIGH

CVE-2025-69627 — Gonitro Nitro_pdf_pro: Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69627

Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI and logging helper functions. Because the freed memory region may contain unpredictable heap data or remnants of attacker-controlled JavaScript strings, downstream routines such as wcscmp() may proces CVSSv3.1 8.4 (HIGH)

CWECWE 416VNDNitroVNDGonitroTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-13
2026-04-13 15:47Z
INFO

v9.0.0

BloodHound releases·github.com

BloodHound v9.0.0 released with incremental feature additions and bug fixes including API key expiration support, OpenGraph extension management improvements, Azure ingestion enhancements, and UI/UX refinements across 40+ contributors.

VNDBloodhoundVNDSpecter OpsTYPTool
35
Edit Score
2026-04-13
2026-04-13 15:17Z
HIGH

CVE-2026-33858 — Dag: Authors, who normally should not be able to execute code in the webserver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33858

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDDagTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 15:17Z
CRIT

CVE-2026-31283 — Totara: In Totara LMS v19.1.5 and before, the forgot password API does not implement rate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31283

In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. NOTE: the Supplier's position is that the pwresettime configuration defaults to 30 minutes, the pwresettime configuration is a hard control enforced via flag PWRESET_STATUS_ALREADYSENT, and no further password-reset email messages are sent if this flag is active for a specific email address. CVSSv3.1 9.8 (CRITICAL)

CWECWE 770VNDTotaraTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 15:17Z
CRIT

CVE-2026-31282 — Totara: LMS v19.1.5 and before is vulnerable to Incorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31282

Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker can chain that with missing rate-limit on the login form to launch a brute force attack. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDTotaraTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 15:17Z
HIGH

CVE-2026-31281 — Totara: LMS v19.1.5 and before is vulnerable to HTML Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31281

Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the application, resulting in executing the code and may lead to session hijacking and executing commands on the victim's browser. NOTE: The supplier states that the product name is Totara Learning and that the functionality referenced is the in app messaging client. They note that the in app messaging client only has the abili CVSSv3.1 8.0 (HIGH) · EPSS 13th percentile

CWECWE 79VNDTotaraTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-13
2026-04-13 15:17Z
HIGH

CVE-2026-1462 — A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1462

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker- CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-13
2026-04-13 14:16Z
CRIT

CVE-2026-31414 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31414

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to the master conntrack is unsafe. Use exp->master->helper in ctnetlink path if userspace does not provide an explicit helper when creating an expectation to retain the existing behaviour. The ctnetlink expectation path holds the reference on th CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 10:16Z
HIGH

CVE-2026-35337 — Deserialization: of Untrusted Data vulnerability in Apache Storm.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35337

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An authenticated user with topology submission rights could supply a crafted serialized object in the "TGT" credential field, leading to remote code execution in bot CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 09:00Z
CRIT

JanelaRAT: a financial threat targeting users in Latin America

Kaspersky Securelist·securelist.comin the wild

JanelaRAT is an active banking trojan targeting Latin American financial users, particularly in Brazil and Mexico, with 26,434 detected attacks in 2025. The malware evolved from BX RAT and employs multi-stage infection chains using MSI droppers, DLL sideloading, and custom C2 infrastructure with daily rotation via dynamic DNS. Version 33 introduces live banking session hijacking, credential harvesting overlays mimicking legitimate banking interfaces, keystroke injection, and anti-analysis evasion targeting banking security software.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
78
Edit Score
2026-04-13
2026-04-13 08:16Z
CRIT

CVE-2026-0234 — Paloaltonetworks Cortex_xsiam: An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0234

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. CVSSv3.1 9.1 (CRITICAL) · EPSS 15th percentile

CWECWE 347VNDPaloaltonetworksTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-13
2026-04-13 08:16Z
HIGH

CVE-2026-0233 — Paloaltonetworks Autonomous_digital_experience_manager: A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0233

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

CWECWE 295VNDPaloaltonetworksVNDPaloTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 07:16Z
HIGH

CVE-2026-6168 — This manipulation of the argument ssid5g causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6168

A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid5g causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 07:16Z
HIGH

CVE-2026-5936 — This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5936

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment. CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-13
2026-04-13 07:16Z
CRIT

CVE-2026-5085 — Mcrawfor Solstice\: Predictable session ids could allow an attacker to gain access to systems.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5085

Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the process id. The same method is used in the _generateID method in Solstice::Subsession, which is part of the same distribution. The epoch time may be guessed, if it is not leaked in the HTTP Date header. Stringified hash refences will contain pr CVSSv3.1 9.1 (CRITICAL)

CWECWE 338CWECWE 340VNDSolsticeVNDMcrawforTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-13
2026-04-13 07:16Z
HIGH

CVE-2026-3830 — Product: The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3830

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks CVSSv3.1 8.6 (HIGH)

CWECWE 89TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-13
2026-04-13 05:16Z
HIGH

CVE-2026-25208 — Integer: overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25208

Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. CVSSv3.1 8.1 (HIGH)

CWECWE 190TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-13
2026-04-13 04:16Z
HIGH

CVE-2026-6157 — Totolink: The manipulation of the argument apcliSsid results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6157

A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDTotolinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-13
2026-04-13 04:16Z
CRIT

CVE-2026-6156 — The manipulation of the argument Comment leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6156

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument Comment leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 04:16Z
CRIT

CVE-2026-6155 — Executing a manipulation of the argument pppoeServiceName can lead to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6155

A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument pppoeServiceName can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 04:16Z
CRIT

CVE-2026-6154 — Performing a manipulation of the argument wizard results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6154

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wizard results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 01:16Z
CRIT

CVE-2026-6140 — Totolink: Performing a manipulation of the argument FileName results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6140

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument FileName results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 01:16Z
CRIT

CVE-2026-6139 — Such manipulation of the argument FileName leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6139

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 00:16Z
CRIT

CVE-2026-6138 — This manipulation of the argument mac causes os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6138

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mac causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-13
2026-04-13 00:16Z
HIGH

CVE-2026-6137 — Tenda: The manipulation of the argument wanmode/PPPOEPassword results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6137

A vulnerability was detected in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan. The manipulation of the argument wanmode/PPPOEPassword results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score