NVD disclosure day

Published threat advisories for March 31, 2026

CVE advisoryCRITICAL

CVE-2026-4800

lodash Template Import Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the Lodash JavaScript utility library, allowing for arbitrary code execution. This occurs when untrusted input is used in specific import key names within the templating function, potentially enabling attackers to run unauthorized code. Although exploitation requires certain condition

CVE advisoryCRITICAL

CVE-2026-30283

PEAKSEL Animal Sounds and Ringtones Arbitrary File Overwrite Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in the PEAKSEL NIS Animal Sounds and Ringtones application, enabling attackers to overwrite critical internal files through a file import process. This could result in arbitrary code execution or information exposure. It is uncertain if this application is relevant to th

CVE advisoryCRITICAL

CVE-2026-30282

Cast to TV Arbitrary File Overwrite Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in the Cast to TV Screen Mirroring application, allowing attackers to overwrite critical internal files via file import. This could lead to arbitrary code execution or information exposure. Relevance and exposure must be confirmed, as this is a client-side Android applic

CVE advisoryCRITICAL

CVE-2026-30278

FLY is FUN Aviation Navigation Arbitrary File Overwrite Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in FLY is FUN Aviation Navigation, allowing attackers to overwrite critical internal files via file import. This could lead to arbitrary code execution or information exposure. Confirm if this specific software is in use and if the vulnerable function is accessible.

CVE advisoryCRITICAL

CVE-2026-4317

Umami Software web app allows attackers to steal customer data or take control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated attacker can exploit a SQL injection flaw in the Umami Software web application to steal sensitive data or execute dangerous commands. This vulnerability deserves attention now due to the potential for data compromise.