2026-04-07
2026-04-07 17:16Z
CRIT

CVE-2024-36058 — Send: The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-36058

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSendTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-35521 — FTLDNS: From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35521

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP hosts configuration parameter (dhcp.hosts). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 93VNDFtldnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-35520 — FTLDNS: From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35520

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configuration parameter (dhcp.leaseTime). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulne CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 93VNDFtldnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-35519 — FTLDNS: From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35519

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configuration parameter (dns.hostRecord). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulne CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 93VNDFtldnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-35518 — FTLDNS: From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35518

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS CNAME records configuration parameter (dns.cnameRecords). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This v CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 93VNDFtldnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-35517 — FTLDNS: From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35517

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the upstream DNS servers configuration parameter (dns.upstreams). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This v CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 93VNDFtldnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 16:16Z
CRIT

CVE-2026-35490 — Webtechnologies Changedetection: changedetection.io is a free open source web page change detection tool.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35490

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these route CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDWebtechnologiesTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-35488 — Tandoor: Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35488

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_permission() returns True for all HTTP methods — including DELETE, PUT, and PATCH — without checking request.method in SAFE_METHODS. Any user who is in the shared list of a RecipeBook can delete or overwrite it, even though shared ac CVSSv3.1 8.1 (HIGH)

CWECWE 749VNDTandoorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 16:16Z
CRIT

CVE-2026-33816 — Pgx_project Pgx: Memory-safety vulnerability in github.com/jackc/pgx/v5.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33816

Memory-safety vulnerability in github.com/jackc/pgx/v5. CVSSv3.1 9.8 (CRITICAL)

VNDPgx ProjectTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 16:16Z
CRIT

CVE-2026-33815 — Pgx_project Pgx: Memory-safety vulnerability in github.com/jackc/pgx/v5.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33815

Memory-safety vulnerability in github.com/jackc/pgx/v5. CVSSv3.1 9.8 (CRITICAL)

VNDPgx ProjectTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2026-30460 — Thedaylightstudio Fuel_cms: Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30460

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDThedaylightstudioVNDDaylightTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 16:16Z
CRIT

CVE-2025-52908 — Samsung Exynos_1280_firmware: Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-52908

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 1 of 2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDSamsungTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2025-24818 — Nokia: MantaRay NM is vulnerable to an OS command injection vulnerability due to improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-24818

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application. CVSSv3.1 8.0 (HIGH)

CWECWE 77VNDNokiaTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-07
2026-04-07 16:16Z
HIGH

CVE-2025-24817 — Nokia: MantaRay NM is vulnerable to an OS command injection vulnerability due to improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-24817

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application. CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDNokiaTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-07
2026-04-07 16:16Z
CRIT

CVE-2024-36057 — Koha: Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-36057

Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data can be controlled by an attacker and is directly included in a system command, i.e., an attack can occur via malicious filenames after uploading a .zip file and clicking Process Images. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDKohaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 15:44Z
INFO

v2.12.0-rc1

AzureHound releases·github.com

AzureHound v2.12.0-rc1 released with bug fixes including removal of a race condition in unit tests, correction of role filtering logic for listResourceGroupUserAccessAdmins, and expanded collection of AzureContributor role assignments across management groups, resource groups, and subscriptions.

SRFIdentitySRFCloudVNDSpecteropsVNDMicrosoft AzureTYPTool
35
Edit Score
2026-04-07
2026-04-07 15:17Z
HIGH

CVE-2026-5373 — An issue that allowed all-organization administrators to promote accounts to superuser status has been

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5373

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version 4.0.260202.0 of the runZero Platform. CVSSv3.1 8.1 (HIGH)

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 15:17Z
HIGH

CVE-2026-4740 — Open: Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4740

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster. CVSSv3.1 8.2 (HIGH)

CWECWE 295TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 15:17Z
CRIT

CVE-2026-4277 — Djangoproject Django: An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4277

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDDjangoprojectTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 15:17Z
HIGH

CVE-2026-35463 — Pyload-ng_project Pyload-ng: A non-admin user with SETTINGS permission can change this path to achieve remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35463

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only applied to core config options, not to plugin config options. The AntiVirus plugin stores an executable path (avfile) in its config, which is passed directly to subprocess.Popen(). A CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDPyload Ng ProjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 15:17Z
CRIT

CVE-2026-35458 — Thecodingmachine Gotenberg: In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35458

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1333VNDThecodingmachineVNDGotenbergTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 15:17Z
HIGH

CVE-2026-35457 — Protocol Libp2p: libp2p-rust is the official rust language Implementation of the libp2p networking stack.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35457

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. CVSSv3.1 8.2 (HIGH)

CWECWE 770TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 15:17Z
CRIT

CVE-2026-30079 — Openairinterface Oai-cn5g-amf: In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30079

In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDOpenairinterfaceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 15:17Z
HIGH

CVE-2026-24660 — Libraw Libraw: A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24660

A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. CVSSv3.1 8.1 (HIGH)

CWECWE 190VNDLibrawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 15:17Z
HIGH

CVE-2026-24450 — Libraw Libraw: An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24450

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. CVSSv3.1 8.1 (HIGH)

CWECWE 190VNDLibrawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score