2026-04-12
2026-04-12 04:16Z
CRIT

CVE-2026-6113 — Such manipulation of the argument ttyEnable leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6113

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument ttyEnable leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-12
2026-04-12 04:16Z
CRIT

CVE-2026-6112 — This manipulation of the argument maxRtrAdvInterval causes os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6112

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-12
2026-04-12 03:16Z
HIGH

CVE-2026-1116 — Scripting: A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1116

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This allows an attacker to inject malicious HTML or JavaScript payloads, which can be executed in the context of another user's browser. Exploitation of this vulnerability can lead to acc CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDScriptingTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-11
2026-04-11 19:16Z
CRIT

CVE-2026-31845 — XSS: A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31845

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without proper sanitization, output encoding, or content-type restrictions. The vulnerable code is: if (isset($_GET['zd_echo'])) exit($_GET['zd_echo']); An unauthenticated attacker can exploit this is CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDXssTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-11
2026-04-11 07:16Z
HIGH

CVE-2026-34621 — Adobe Acrobat_dc: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34621

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. CVSSv3.1 8.6 (HIGH)

CWECWE 1321VNDAdobeVNDAcrobatTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-11
2026-04-11 02:16Z
HIGH

CVE-2026-5144 — BuddyPress: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5144

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-silent-add` parameters from user input without proper authorization checks. The `groupblog-blogid` parameter allows any group admin (including Subscribers who create their own group) to associate their group with any blog on the Multisit CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

CWECWE 269VNDBuddypressTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-11
2026-04-11 01:16Z
CRIT

CVE-2026-5059 — AWS: aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5059

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDAwsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-11
2026-04-11 01:16Z
CRIT

CVE-2026-5058 — Command: aws-mcp-server Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5058

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnera CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDCommandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-11
2026-04-11 01:16Z
CRIT

CVE-2026-4149 — Sonos: Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4149

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the DataOffset field within SMB responses. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of CVSSv3.1 10.0 (CRITICAL)

CWECWE 119VNDSonosTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-04-10
2026-04-10 20:16Z
CRIT

CVE-2026-40189 — Goshs Goshs: This results in a critical authorization bypass affecting confidentiality, integrity, and availability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40189

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with PUT, upload files with multipart POST /upload, create directories with ?mkdir, and delete files with ?delete inside a .goshs-protected directory. By deleting the .goshs fi CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDGoshsVNDSimplehttpserverTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-10
2026-04-10 20:16Z
CRIT

CVE-2026-40175 — Axios: Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget"

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40175

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918CWECWE 113CWECWE 444VNDAxiosTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-04-10
2026-04-10 20:16Z
HIGH

CVE-2026-40168 — Gitroom Postiz: Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40168

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a result, an attacker can supply a public HTTPS URL that passes validation and then redirects the server-side request to an internal resource. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDGitroomVNDPostizTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-10
2026-04-10 20:16Z
CRIT

CVE-2026-30232 — Depomo Chartbrew: Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30232

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using request-promise without any IP address validation, enabling Server-Side Request Forgery attacks against internal networks and cloud metadata endpoints. This vulnerability is fixed in 4.8.5. CVSSv3.1 9.6 (CRITICAL)

CWECWE 918VNDDepomoVNDChartbrewTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-10
2026-04-10 19:16Z
CRIT

CVE-2026-33707 — Chamilo: Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33707

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3. CVSSv3.1 9.4 (CRITICAL)

CWECWE 640VNDChamiloTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-04-10
2026-04-10 19:16Z
HIGH

CVE-2026-33618 — Chamilo: Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33618

Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1) can inject arbitrary PHP code into the settings, which is then executed when any user (including unauthenticated) requests /platform-config/list. This vulnerability is fixed in 2.0.0-RC.3. CVSSv3.1 8.8 (HIGH)

CWECWE 95VNDChamiloTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-10
2026-04-10 19:11Z
HIGH

Metasploit Wrap-Up 10/04/2026

Rapid7 Research·rapid7.comCVE-2026-20127CVE-2026-22200in the wild

Metasploit Framework 6.4.126 adds four new modules including an authentication bypass for Cisco Catalyst SD-WAN controllers (CVE-2026-20127, recently exploited in the wild), an arbitrary file read in osTicket via PHP filter chains (CVE-2026-22200), and AD/CS web enrollment certificate issuance. The release also includes a 2x speedup to msfvenom startup time and enhancements to LDAP/ADCS reporting and Windows S4U persistence techniques.

SRFApplicationSRFOsTACTA0004TACTA0005SRFNetwork ApplianceTACTA0006TACTA0007TACTA0003
72
Edit Score
2026-04-10
2026-04-10 18:16Z
HIGH

CVE-2026-5483 — This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5483

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources. CVSSv3.1 8.5 (HIGH)

CWECWE 201TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-10
2026-04-10 18:16Z
HIGH

CVE-2026-40163 — Saltcorn: Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40163

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthenticated attacker to create arbitrary directories and write a changes.json file with attacker-controlled JSON content anywhere on the server filesystem. The GET /sync/upload_finished endpoint allows an unauthenticated attacker to list arbitrary directory contents and read specific JSON files. This vulne CVSSv3.1 8.2 (HIGH)

CWECWE 22VNDSaltcornTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-10
2026-04-10 18:16Z
CRIT

CVE-2026-32892 — Chamilo: Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32892

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a user moves a document via document.php, the move_to POST parameter — which only passes through Security::remove_XSS() (an HTML-only filter) — is concatenated direct CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDChamiloTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-10
2026-04-10 18:16Z
HIGH

CVE-2026-31939 — Chamilo: Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31939

Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into filesystem path without canonicalization or traversal checks. This vulnerability is fixed in 1.11.38. CVSSv3.1 8.3 (HIGH)

CWECWE 22CWECWE 73VNDChamiloTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-10
2026-04-10 17:17Z
HIGH

CVE-2026-40200 — Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40200

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical). CVSSv3.1 8.1 (HIGH)

CWECWE 670TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-10
2026-04-10 17:17Z
HIGH

CVE-2026-40158 — PraisonAI: Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40158

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing arbitrary code execution when running untrusted agent code. The _execute_code_direct function in praisonaiagents/tools/python_tools.py uses AST filtering to block dangerous Python attributes like __subclasses__, __globals__, and __bases__. However, the filter only checks ast.Attribute nodes, allowing a bypass. The san CVSSv3.1 8.6 (HIGH)

CWECWE 94CWECWE 693VNDPraisonaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-10
2026-04-10 17:17Z
HIGH

CVE-2026-40157 — Praison Praisonai: Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40157

PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without validating archive member paths. A .praison bundle containing ../../ entries will write files outside the intended output directory. An attacker who distributes a malicious bundle can overwrite arbitrary files on the victim's filesystem when they run praisonai recipe unpack. This vulnerability is fixed in 4.5.128. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDPraisonVNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-10
2026-04-10 17:17Z
HIGH

CVE-2026-35669 — Openclaw Openclaw: before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35669

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope boundary bypass to gain elevated privileges and perform unauthorized administrative actions. CVSSv3.1 8.8 (HIGH)

CWECWE 648VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-10
2026-04-10 17:17Z
HIGH

CVE-2026-35666 — Openclaw Openclaw: before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35666

OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers can bypass executable binding restrictions by using an unregistered time wrapper to reuse approval state for inner commands. CVSSv3.1 8.8 (HIGH)

CWECWE 706VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score