2026-04-07
2026-04-07 22:16Z
CRIT

CVE-2026-39846 — SiYuan: Prior to 3.6.4, a malicious note synced to another user can trigger remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39846

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextIsolation disabled, attacker-controlled JavaScript executes with access to Node.js CVSSv3.1 9.0 (CRITICAL)

CWECWE 94CWECWE 79VNDSiyuanTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-07
2026-04-07 22:16Z
CRIT

CVE-2026-34582 — Botan_project Botan: Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34582

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 841CWECWE 166VNDBotan ProjectVNDBotanTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 22:16Z
CRIT

CVE-2026-34078 — Flatpak Flatpak: Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4. CVSSv3.1 10.0 (CRITICAL) · EPSS 13th percentile

CWECWE 61VNDFlatpakTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-04-07
2026-04-07 22:16Z
CRIT

CVE-2026-31789 — Openssl Openssl: Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31789

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which a CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDOpensslTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 22:16Z
HIGH

CVE-2026-28387 — Openssl Openssl: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28387

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-E CVSSv3.1 8.1 (HIGH)

CWECWE 416VNDOpensslTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 22:16Z
HIGH

CVE-2026-28386 — Openssl Openssl: Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28386

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to o CVSSv3.1 7.5 (HIGH) · EPSS 15th percentile

CWECWE 125VNDOpensslTYPVulnerability
7.5
CVSS v3.1
88
Edit Score
2026-04-07
2026-04-07 21:17Z
CRIT

CVE-2026-39397 — PayloadCMS: @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39397

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The access option passed to createPuckPlugin() and any access rules defined on Puck-registered collections were silently ignored on these endpoints. This vulnerability is fixed in 0.6. CVSSv3.1 9.4 (CRITICAL)

CWECWE 862VNDPayloadcmsTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-07
2026-04-07 21:17Z
HIGH

CVE-2026-34045 — Podman: Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose intern CVSSv3.1 8.2 (HIGH)

CWECWE 284CWECWE 209CWECWE 400VNDPodmanTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 21:17Z
CRIT

CVE-2026-33439 — Openidentityplatform Openam: Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33439

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was applied to the jato.pageSession parameter after CVE-2021-35464. An unauthenticated attacker can achieve arbitrary command execution on the server by sending a crafted CVSSv3.1 9.8 (CRITICAL) · EPSS 95th percentile

CWECWE 502VNDOpenidentityplatformTYPVulnerability
9.8
CVSS v3.1
100
Edit Score
2026-04-07
2026-04-07 20:16Z
HIGH

CVE-2026-39371 — Rwsdk Redwoodsdk: In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39371

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers send SameSite=Lax cookies on top-level GET requests. This affected all server functions -- both serverAction() handlers and bare exported functions in CVSSv3.1 8.1 (HIGH) · EPSS 0th percentile

CWECWE 352VNDRedwoodsdkVNDRwsdkTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 20:16Z
HIGH

CVE-2026-39322 — Polarlearn Polarlearn: In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39322

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. That session is then accepted across authenticated /api routes, enabling account data access and authenticated actions as the banned user. CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDPolarlearnTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 20:16Z
CRIT

CVE-2025-69515 — JXL: An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69515

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location. CVSSv3.1 9.1 (CRITICAL)

CWECWE 941VNDJxlTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 19:32Z
CRIT

10 Minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)

CVE-2026-34197 is a critical RCE in Apache ActiveMQ Classic that chains the Jolokia API, network connector functionality, and VM transport to force remote Spring XML configuration loading and arbitrary code execution. The vulnerability requires authentication (default admin:admin credentials are common), but becomes unauthenticated on versions 6.0.0–6.1.1 due to CVE-2024-32114. Patches are available in ActiveMQ 5.19.4 and 6.2.3.

SRFApplicationTACTA0002SRFNetworkTACTA0003VNDApacheVNDActivemqTYPWriteupTYPExploit
8.8
CVSS v3.1
92
Edit Score
2026-04-07
2026-04-07 19:30Z
CRIT

CVE-2026-34197 — Apache-activemq: The vulnerability affects versions before 5.19.4 and 6.0.0 before 6.2.3, and becomes

Horizon3.ai·horizon3.aiCVE-2026-34197CVE-2024-32114

CVE-2026-34197 is an authenticated remote code execution vulnerability in Apache ActiveMQ Classic's Jolokia JMX-HTTP bridge that allows attackers to inject malicious Spring XML configurations via crafted URIs to broker management operations (addNetworkConnector, addConnector). The vulnerability affects versions before 5.19.4 and 6.0.0 before 6.2.3, and becomes unauthenticated RCE when combined with CVE-2024-32114. Apache released patches on March 30, 2026, with public disclosure on April 7, 2026.

SRFApplicationTACTA0002SRFWebTACTA0003VNDApache ActivemqTYPExploitTYPVulnerabilitySTGExecution
8.8
CVSS v3.1
92
Edit Score
2026-04-07
2026-04-07 19:16Z
CRIT

CVE-2026-39355 — Kreaweb Genealogy: Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39355

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces and unrestricted access to all genealogy data associated with the compromised team. This vulnerability is fixed in 5.9.1. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862VNDKreawebVNDGenealogyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-07
2026-04-07 19:16Z
CRIT

CVE-2026-39351 — Frappe Frappe: Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39351

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDFrappeTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 19:16Z
CRIT

CVE-2025-71058 — Dual: DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71058

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject forged responses and poison the DNS cache, potentially redirecting victims to attacker-controlled destinations. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDDualTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39344 — Churchcrm Churchcrm: Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39344

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused by the lack of sanitization or encoding of the username parameter received from the URL. The username parameter value is directly displayed in the login page input element without filter, allowing attackers to insert malicious JavaScript scripts. If successful, script can be executed on the client side, potentia CVSSv3.1 8.1 (HIGH)

CWECWE 79CWECWE 80VNDChurchcrmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39342 — Churchcrm Churchcrm: Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39342

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39341 — ChurchCRM: Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39341

ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not used to create the SQL query. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39340 — Churchcrm Churchcrm: Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39340

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration functionality for managing property type categories (People → Person Properties / Family Properties). The vulnerability was introduced when legacyFilterInput() which both strips HTML and escapes SQL — was replaced with sanitizeText(), which strips HTML only. User-supplied values from the Name and Description fields ar CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 18:16Z
CRIT

CVE-2026-39339 — Churchcrm Churchcrm: Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39339

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywhere in the request URL, leading to complete exposure of church member data and system information. This vulnerability is fixed in 7.1.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDChurchcrmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 18:16Z
CRIT

CVE-2026-39337 — Churchcrm Churchcrm: Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39337

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The "$dbPassword" variable is not sanitized. This vulnerability exists due to an incomplete fix for CVE-2025-62521. This vulnerability is fixed in 7.1.0. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDChurchcrmTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39334 — Churchcrm Churchcrm: Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.php in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39334

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.php in ChurchCRM 7.0.5. Authenticated users without any specific privileges can inject arbitrary SQL statements through the type array parameter via the index and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39333 — Churchcrm Churchcrm: This constitutes a reflected XSS vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39333

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. An authenticated attacker can craft a malicious URL that executes arbitrary JavaScript when visited by another authenticated user. This constitutes a reflected XSS vulnerability. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDChurchcrmTYPVulnerability
8.7
CVSS v3.1
94
Edit Score