NVD disclosure day

Published threat advisories for March 31, 2026

CVE advisoryCRITICAL

CVE-2026-34449

SiYuan Remote Code Execution via Permissive CORS Policy

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

SiYuan, a personal knowledge management system, has a vulnerability that could allow a malicious website to execute arbitrary code on a user's desktop. This occurs when a user visits a compromised website while SiYuan is active, enabling a JavaScript snippet to be injected via the API and run with full OS access. This

CVE advisoryCRITICAL

CVE-2026-34448

SiYuan Stored XSS to OS Command Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in SiYuan allows an attacker to execute arbitrary OS commands by placing a malicious URL in an Attribute View field. This can be triggered when a victim opens the Gallery or Kanban view with a specific setting enabled. The issue is present in versions prior to 3.6.2.

CVE advisoryCRITICAL

CVE-2026-34406

APTRS Account Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the APTRS reporting tool allows any authenticated user to escalate their privileges to superuser by exploiting an improperly validated API endpoint. This grants unrestricted access to all application functions. The issue is addressed in version 2.0.1.

CVE advisoryCRITICAL

CVE-2026-4800

lodash Template Import Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the Lodash JavaScript utility library, allowing for arbitrary code execution. This occurs when untrusted input is used in specific import key names within the templating function, potentially enabling attackers to run unauthorized code. Although exploitation requires certain condition

CVE advisoryCRITICAL

CVE-2026-30285

Zora Post Trade Earn Crypto Arbitrary File Overwrite Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in the Zora cryptocurrency application allows overwriting internal files, potentially leading to arbitrary code execution or information exposure. This is concerning if the affected application is in use, as it is remotely exploitable without authentication via the file import process.

CVE advisoryCRITICAL

CVE-2026-3356

MS27102A Remote Spectrum Monitor Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The MS27102A Remote Spectrum Monitor has an inherent authentication bypass vulnerability, allowing unauthorized access to its management interface without credentials. This design flaw means attackers could potentially access and manipulate the device's functions, impacting its operational status and management integri

CVE advisoryCRITICAL

CVE-2026-30286

Funambol Zefiro Arbitrary File Overwrite Leading to Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file overwrite vulnerability in Funambol Zefiro Cloud allows attackers to overwrite internal files, potentially leading to arbitrary code execution or information exposure. This vulnerability is network-accessible without authentication and can be exploited via the file import process.

CVE advisoryCRITICAL

CVE-2026-30283

PEAKSEL Animal Sounds and Ringtones Arbitrary File Overwrite Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in the PEAKSEL NIS Animal Sounds and Ringtones application, enabling attackers to overwrite critical internal files through a file import process. This could result in arbitrary code execution or information exposure. It is uncertain if this application is relevant to th

CVE advisoryCRITICAL

CVE-2026-30282

Cast to TV Arbitrary File Overwrite Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in the Cast to TV Screen Mirroring application, allowing attackers to overwrite critical internal files via file import. This could lead to arbitrary code execution or information exposure. Relevance and exposure must be confirmed, as this is a client-side Android applic

CVE advisoryCRITICAL

CVE-2026-30278

FLY is FUN Aviation Navigation Arbitrary File Overwrite Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in FLY is FUN Aviation Navigation, allowing attackers to overwrite critical internal files via file import. This could lead to arbitrary code execution or information exposure. Confirm if this specific software is in use and if the vulnerable function is accessible.

CVE advisoryCRITICAL

CVE-2026-34361

HAPI FHIR Validator Token Stealing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

HAPI FHIR, a Java implementation of the HL7 FHIR standard, has a vulnerability in its Validator HTTP service. The unauthenticated "/loadIG" endpoint can be tricked into making outbound requests to attacker-controlled URLs. This allows an attacker to steal authentication tokens by registering a domain that matches a con

CVE advisoryCRITICAL

CVE-2026-34359

HAPI FHIR Credentials Leakage Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in HAPI FHIR, a Java implementation of the HL7 FHIR standard for healthcare interoperability, potentially exposing sensitive authentication credentials. An attacker could exploit a URL matching flaw to intercept tokens, basic auth credentials, or API keys meant for legitimate FHIR server

CVE advisoryCRITICAL

CVE-2026-24164

NVIDIA BioNeMo Untrusted Deserialization Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

NVIDIA BioNeMo contains a deserialization vulnerability that could allow an attacker to execute code, cause a denial of service, disclose information, or tamper with data. This issue is reachable over the network without privileges or user interaction. It is uncertain if this technology is in use within our environment

CVE advisoryCRITICAL

CVE-2026-24148

NVIDIA Jetson Initialization Logic Vulnerability Allows Data Tampering and Disclosure

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

NVIDIA Jetson devices have a system initialization vulnerability allowing unprivileged attackers to potentially disclose or tamper with encrypted data and cause partial denial of service for devices sharing a machine ID. This issue stems from an insecure default setting during resource initialization.

CVE advisoryCRITICAL

CVE-2026-34243

wenxian Command Injection Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

wenxian, a tool for generating BIBTEX files, has a command injection vulnerability in its GitHub Actions workflow that can allow arbitrary code execution. This issue arises from processing untrusted user input from issue comments directly within a shell command. At the time of this advisory, no patches are publicly ava

CVE advisoryCRITICAL

CVE-2026-34220

MikroORM SQL Injection Vulnerability in Node.js Applications

Halo Surface Signal: 3 out of 5 — possibly public-facing.

MikroORM, a Node.js data management tool, contains a critical SQL injection vulnerability when processing specially crafted objects as raw SQL query fragments. If reachable, this could allow attackers to manipulate or access sensitive database information. Organizations should confirm if their applications use affected

CVE advisoryCRITICAL

CVE-2026-30281

Maru Neo Maru Arbitrary File Overwrite Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file overwrite vulnerability exists in a MaruNuri application, allowing attackers to replace critical internal files via its import function. This could lead to arbitrary code execution or information exposure. Uncertainty exists regarding the exploitability of this vulnerability given the nature of the af

CVE advisoryCRITICAL

CVE-2026-30276

DeftPDF Document Translator Arbitrary File Overwrite Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A file overwrite vulnerability in DeftPDF Document Translator may allow attackers to replace critical internal files via import, potentially leading to code execution or information exposure. The relevance and exposure of this technology within your environment should be confirmed to understand associated risks.

CVE advisoryCRITICAL

CVE-2026-34532

Parse Server Cloud Function Access Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Parse Server, an open-source backend, has a vulnerability allowing unauthenticated attackers to bypass Cloud Function access controls by appending specific strings to function names in URLs. This could enable unauthorized invocation of protected functions. Readers should care because this bypass skips intended access c

CVE advisoryCRITICAL

CVE-2026-34162

FastGPT Unauthenticated HTTP Proxy Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

FastGPT's HTTP tools testing endpoint is exposed without authentication, allowing unauthenticated attackers to make arbitrary server-side HTTP requests. This could expose internal services or sensitive information. This vulnerability affects FastGPT versions prior to 4.14.9.5 and has been patched in later versions.

CVE advisoryCRITICAL

CVE-2026-33579

OpenClaw Privilege Escalation Via Missing Scope Validation in Device Pair Approval.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

OpenClaw contains a privilege escalation vulnerability where a user with pairing privileges can approve device requests for broader administrative scopes due to missing scope validation. This could allow unauthorized administrative access.

CVE advisoryCRITICAL

CVE-2026-30314

Ridvay Auto-Approval Module Command Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical command injection vulnerability exists in the Ridvay Code's command auto-approval module, which bypasses its security controls and allows for remote code execution. Attackers can exploit this by sending crafted commands that the module misinterprets as safe due to insufficient parsing of command substitution

CVE advisoryCRITICAL

CVE-2026-30312

DSAI-Cline Command Auto-Approval OS Command Injection Leads to Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical OS command injection vulnerability exists in DSAI-Cline's auto-approval module, allowing remote code execution by exploiting improper handling of newline characters in command parsing. While the module is designed for developer tools and not typically exposed externally, an attacker could potentially trigger

CVE advisoryCRITICAL

CVE-2026-30311

Ridvay Code Auto-Approval OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical OS command injection vulnerability in Ridvay Code's command auto-approval module allows attackers to execute arbitrary commands remotely. The system's parsing of commands with shell substitution is flawed, enabling attackers to bypass security and achieve remote code execution without user interaction. This

CVE advisoryCRITICAL

CVE-2026-34156

NocoBase Workflow Script Node Sandbox Escape Leading to RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

NocoBase, a no-code/low-code platform, has a critical vulnerability that allows authenticated attackers to execute arbitrary code on the server. By exploiting a sandbox escape in the Workflow Script Node, an attacker could gain root-level control, potentially compromising business applications and the underlying system

CVE advisoryCRITICAL

CVE-2026-32917

OpenClaw Remote Command Injection in iMessage Attachment Staging

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

OpenClaw contains a critical remote command injection vulnerability in its iMessage attachment staging flow, allowing attackers to execute arbitrary commands on remote hosts. This occurs when unsanitized attachment paths are passed to the SCP operand without validation, enabling command execution if remote attachment s

CVE advisoryCRITICAL

CVE-2026-32916

OpenClaw Plugin Authorization Bypass Via Synthetic Admin Scopes.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenClaw contains an authorization bypass vulnerability allowing unauthenticated remote requests to plugin-owned routes to invoke privileged gateway actions, such as session deletion and agent execution, by exploiting synthetic operator client scopes. This could enable unauthorized control of gateway functions if affec

CVE advisoryCRITICAL

CVE-2026-4317

Umami Software web app allows attackers to steal customer data or take control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated attacker can exploit a SQL injection flaw in the Umami Software web application to steal sensitive data or execute dangerous commands. This vulnerability deserves attention now due to the potential for data compromise.