A new bundle, The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains), has been published on Vulnerability-Lookup:
http://vulnerability.circl.lu/bundle/8b291831-2785-48c5-bce6-8e1ad5925260
Vulnerability-Lookup
This account shares a variety of activities, including comments and bundles, related to events on the vulnerability.circl.lu community.
A new bundle, OpenSSL Security Advisory [27th January 2026], has been published on Vulnerability-Lookup:
http://vulnerability.circl.lu/bundle/d647957e-5a47-4523-9e9b-00e9f18ef11e
A new bundle, Lantronix EDS3000PS and EDS5000, has been published on Vulnerability-Lookup:
http://vulnerability.circl.lu/bundle/49b900ec-633f-4111-a614-2dc8b0b77752
A new bundle, NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368, has been published on Vulnerability-Lookup:
http://vulnerability.circl.lu/bundle/1ae9c3df-c65f-4755-b3a9-4d76f8c0e772
🚨 CVE-2026-6574
📊 VLAI Score: Medium (confidence: 0.80)
📦️ Product: LightPicture
🏢 Vendor: osuuu
📅 Published: 2026-04-19 13:30
📝 A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The att…
🚨 CVE-2026-6573
📊 VLAI Score: Low (confidence: 0.54)
📦️ Product: PHPEMS
🏢 Vendor: n/a
📅 Published: 2026-04-19 12:45
📝 A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attac…
🚨 CVE-2026-6572
📊 VLAI Score: Low (confidence: 0.83)
📦️ Product: KodExplorer
🏢 Vendor: Collabora
📅 Published: 2026-04-19 12:15
📝 A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileUpload Endpoint. The manipulation of the argument fileUpload l…
🚨 CVE-2026-6571
📊 VLAI Score: Medium (confidence: 0.67)
📦️ Product: KodExplorer
🏢 Vendor: kodcloud
📅 Published: 2026-04-19 12:00
📝 A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization…
🚨 CVE-2026-6570
📊 VLAI Score: Medium (confidence: 0.66)
📦️ Product: KodExplorer
🏢 Vendor: kodcloud
📅 Published: 2026-04-19 11:00
📝 A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be…
🚨 CVE-2026-6568
📊 VLAI Score: Medium (confidence: 0.65)
📦️ Product: KodExplorer
🏢 Vendor: kodcloud
📅 Published: 2026-04-19 09:45
📝 A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path t…
🚨 CVE-2026-6564
📊 VLAI Score: Medium (confidence: 0.56)
📦️ Product: EMQX Enterprise
🏢 Vendor: EMQ
📅 Published: 2026-04-19 09:30
📝 A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been…
🚨 CVE-2026-6569
📊 VLAI Score: Medium (confidence: 0.98)
📦️ Product: KodExplorer
🏢 Vendor: kodcloud
📅 Published: 2026-04-19 10:15
📝 A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. Th…
🚨 CVE-2026-6563
📊 VLAI Score: High (confidence: 1.00)
📦️ Product: Magic B1
🏢 Vendor: H3C
📅 Published: 2026-04-19 08:30
📝 A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to initiate the attack remotely. The…
🚨 CVE-2026-6562
📊 VLAI Score: Medium (confidence: 0.69)
📦️ Product: muucmf
🏢 Vendor: dameng100
📅 Published: 2026-04-19 08:15
📝 A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword can lead to sql injection. The attack may be performed from remote. The exploi…
🚨 CVE-2026-6561
📊 VLAI Score: Medium (confidence: 0.56)
📦️ Product: EyouCMS
🏢 Vendor: n/a
📅 Published: 2026-04-19 07:15
📝 A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be car…
🚨 CVE-2026-6560
📊 VLAI Score: High (confidence: 1.00)
📦️ Product: Magic B0
🏢 Vendor: H3C
📅 Published: 2026-04-19 06:45
📝 A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exp…
🚨 CVE-2026-6559
📊 VLAI Score: Medium (confidence: 0.89)
📦️ Product: WL-WN579A3
🏢 Vendor: Wavlink
📅 Published: 2026-04-19 05:15
📝 A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading t…
🚨 CVE-2026-0868
📊 VLAI Score: Medium (confidence: 1.00)
📦️ Product: EMC – Easily Embed Calendly Scheduling
🏢 Vendor: turn2honey
📅 Published: 2026-04-19 03:26
📝 The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions up to, and including, 4.4 due to insufficient input sanitiz…
🚨 CVE-2026-4801
📊 VLAI Score: Medium (confidence: 1.00)
📦️ Product: Page Builder Gutenberg Blocks – CoBlocks
🏢 Vendor: godaddy
📅 Published: 2026-04-18 03:37
📝 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insufficient output escaping of event t…
🚨 CVE-2026-6048
📊 VLAI Score: Medium (confidence: 1.00)
📦️ Product: Flipbox Addon for Elementor
🏢 Vendor: dragwyb
📅 Published: 2026-04-18 03:37
📝 The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2.1.1 due to insufficient validation of custo…
🚨 CVE-2026-6518
📊 VLAI Score: High (confidence: 0.87)
📦️ Product: CMP – Coming Soon & Maintenance Plugin by NiteoThemes
🏢 Vendor: niteo
📅 Published: 2026-04-18 03:37
📝 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_instal…
🚨 CVE-2026-40494
📊 VLAI Score: High (confidence: 0.66)
📦️ Product: sail
🏢 Vendor: HappySeaFox
📅 Published: 2026-04-18 01:42
📝 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE decoder in `tga.c` has an asymmetric bounds check vulnerability.…
🚨 CVE-2026-40491
📊 VLAI Score: High (confidence: 0.86)
📦️ Product: gdown
🏢 Vendor: wkentaro
📅 Published: 2026-04-18 01:36
📝 gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the library fails to sanitize or validate the fi…
🚨 CVE-2026-40493
📊 VLAI Score: High (confidence: 0.70)
📦️ Product: sail
🏢 Vendor: HappySeaFox
📅 Published: 2026-04-18 01:41
📝 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes bytes-per-pixel (`bpp`) from raw header fields `channels * dep…
A new bundle, NEWS for rsync 3.4.3 (20 May 2026), has been published on Vulnerability-Lookup:
https://vulnerability.circl.lu/bundle/e7759270-c4f2-4aa0-a716-96c00d40f0a0
