Omni Global IntelligenceSynced 2026-04-11 22:25:31 UTC
KEVCVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Vulnerability Database

20 of 20 vulnerabilities
IDSeverityCVSSEPSSDetailsPublished
CVE-2026-5526HIGH7.30.05%

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been released

2026-04-04
CVE-2026-5527MEDIUM5.30.04%

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to

2026-04-05
CVE-2026-5528MEDIUM6.30.34%

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be

2026-04-05
CVE-2026-5529MEDIUM4.30.01%

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now pub

2026-04-05
CVE-2026-5530MEDIUM6.30.03%

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disc

2026-04-05
CVE-2026-5531MEDIUM5.30.02%

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may be initiated remotely.

2026-04-05
CVE-2026-5532MEDIUM6.30.86%

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command injection. The attack may

2026-04-05
CVE-2026-5533MEDIUM4.30.03%

A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. T

2026-04-05
CVE-2026-5534HIGH7.30.04%

A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such manipulation of the argument USERID leads to sql injection. The attack can be executed remotely. The

2026-04-05
CVE-2026-5535MEDIUM4.30.04%

A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The ex

2026-04-05
CVE-2026-5536HIGH7.30.04%

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclos

2026-04-05
CVE-2026-5537MEDIUM6.30.03%

A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the component HTTP GET Parameter Handler. The manipulation of the argument seid leads to sql injection. I

2026-04-05
CVE-2026-5538MEDIUM6.30.04%

A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoint. The manipulation results in server-side request forgery. It is possible to launch the attack remo

2026-04-05
CVE-2026-5539MEDIUM4.30.03%

A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firstName causes cross site scripting. The attack can be initiated remotely. The exploit has been publish

2026-04-05
CVE-2026-5590MEDIUM6.40.04%

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without

2026-04-05
CVE-2026-5540HIGH7.30.04%

A vulnerability has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler. Such manipulation of the argument firstName leads to sql injection. The attack can be launched remotely. The exploit ha

2026-04-05
CVE-2026-5541MEDIUM4.30.03%

A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipulation of the argument userid results in cross site scripting. The attack may be initiated remotely.

2026-04-05
CVE-2026-5542MEDIUM4.30.03%

A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The expl

2026-04-05
CVE-2026-5543MEDIUM6.30.03%

A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. Th

2026-04-05
CVE-2026-5544HIGH8.80.05%

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has

2026-04-05
25 articles
SourceArticle TitlePublished
Bleeping Computer

Over 20,000 crypto fraud victims identified in international crackdown

2026-04-11
The Hacker News

Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data

2026-04-11
Bleeping Computer

ChatGPT rolls out new $100 Pro subscription to challenge Claude

2026-04-11
Dark Reading

Hims Breach Exposes the Most Sensitive Kinds of PHI

2026-04-10
Dark Reading

Your Next Breach Will Look Like Business as Usual

2026-04-10
Bleeping Computer

Nearly 4,000 US industrial devices exposed to Iranian cyberattacks

2026-04-10
Dark Reading

FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats

2026-04-10
Cisco Talos

[Video] The TTP Ep. 22: The Collapse of the Patch Window

2026-04-10
The Hacker News

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

2026-04-10
SentinelOne

The Good, the Bad and the Ugly in Cybersecurity – Week 15

2026-04-10
The Hacker News

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

2026-04-10
ESET WeLiveSecurity

Recovery scammers hit you when you’re down: Here’s how to avoid a second strike

2026-04-10
Cisco Talos

The threat hunter’s gambit

2026-04-09
SentinelOne

Edge Decay: How a Failing Perimeter Is Fueling Modern Intrusions

2026-04-09
Cisco Talos

From the field to the report and back again: How incident responders can use the Year in Review

2026-04-09
Kaspersky Securelist

The long road to your crypto: ClipBanker and its marathon infection chain

2026-04-09
Palo Alto Unit 42

Cracks in the Bedrock: Agent God Mode

2026-04-08
Kaspersky Securelist

Financial cyberthreats in 2025 and the outlook for 2026

2026-04-08
Palo Alto Unit 42

Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox

2026-04-07
Krebs on Security

Russia Hacked Routers to Steal Microsoft Office Tokens

2026-04-07
ESET WeLiveSecurity

As breakout time accelerates, prevention-first cybersecurity takes center stage

2026-04-07
Palo Alto Unit 42

Understanding Current Threats to Kubernetes Environments

2026-04-06
Krebs on Security

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

2026-04-06
SentinelOne

Securing the Supply Chain: How SentinelOne®’s AI EDR Stops the Axios Attack Autonomously

2026-04-02
ESET WeLiveSecurity

Digital assets after death: Managing risks to your loved one’s digital estate

2026-04-01