NVD disclosure day

Published threat advisories for June 15, 2026

CVE advisoryCRITICAL

CVE-2026-48853

Elixir-GRPC Erlpack Deserialization Leads to Node Crash and RCE

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Vulnerabilities in the elixir-grpc grpc library allow unauthenticated attackers to crash the server or execute arbitrary code. By sending a crafted payload, an attacker could exhaust the server's atom table, causing a denial of service, or achieve remote code execution. This issue is critical because it can be exploite

CVE advisoryCRITICAL

CVE-2026-12205

Crypt::DSA Reused Nonce Vulnerability Allows Private Key Recovery.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Crypt::DSA Perl library allows attackers to recover private keys if a key is used for multiple signatures. This could lead to the exposure of sensitive information and the ability to forge signatures. It is uncertain how widely this library is used within the environment, necessitating confirmati

CVE advisoryCRITICAL

CVE-2026-48713

i18next-fs-backend Prototype Pollution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A prototype pollution vulnerability exists in a translation management library when processing untrusted missing translation keys, potentially altering global program settings. This could lead to application instability or security bypasses if the affected feature is reachable by unauthenticated users. Determining if y

CVE advisoryCRITICAL

CVE-2026-11832

Dancer2 OAuth Plugin Predictable Nonce Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A predictable nonce in an OAuth authentication plugin for Perl applications can be guessed by attackers, potentially allowing them to impersonate users and gain unauthorized access. This issue affects how security codes are generated, making them susceptible to predictable patterns.

CVE advisoryCRITICAL

CVE-2026-9691

PHP Object Injection in ActiveCampaign and Contact Form 7 Integration Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated PHP Object Injection vulnerability exists in an integration plugin for popular WordPress form builders. This flaw could allow attackers to execute arbitrary code on the server, potentially compromising website integrity and data. The risk is present if the integration is exposed to the intern

CVE advisoryCRITICAL

CVE-2026-52703

FastDup Plugin Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated path traversal vulnerability exists in FastDup technology. Attackers could potentially access or modify sensitive files on a server, impacting data confidentiality and integrity. Confirming the relevance and exposure to your business systems is recommended.

CVE advisoryCRITICAL

CVE-2026-52693

Unauthenticated SQL Injection in eCommerce Product Catalog

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in an eCommerce product catalog system. This could allow attackers to access or manipulate sensitive data without needing to log in, potentially impacting product information. It is important to determine if this system is in use and assess the risk of exposure.

CVE advisoryCRITICAL

CVE-2026-49781

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in the OttoKit web application component. If reachable, an attacker could exploit this flaw via network requests to execute arbitrary code on the affected system, potentially compromising its integrity and availability. Readers should care because unauthentic

CVE advisoryCRITICAL

CVE-2026-49776

GPTranslate SQL Injection Vulnerability Affects WordPress Translations

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a WordPress translation plugin, potentially allowing attackers to access or alter website database information. This flaw is reachable over the network, posing a risk to data integrity and confidentiality for affected sites.

CVE advisoryCRITICAL

CVE-2026-49770

WP Travel Engine PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the WP Travel Engine plugin, allowing unauthenticated PHP object injection. This could lead to arbitrary code execution, impacting data confidentiality, integrity, and system availability. The technology is a WordPress plugin, commonly internet-facing. The uncertainty is whether this

CVE advisoryCRITICAL

CVE-2026-49769

Unauthenticated PHP Object Injection in wpForo Forum

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical PHP object injection vulnerability exists in a WordPress forum plugin that can be reached over the network. Unauthenticated attackers may exploit this to inject malicious code, potentially impacting system confidentiality, integrity, and availability. Confirming the plugin's presence and exposure is crucial

CVE advisoryCRITICAL

CVE-2026-49768

PHP Object Injection in Happyforms Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in the Happyforms plugin, allowing attackers to potentially execute arbitrary PHP code. This could lead to unauthorized access and manipulation of data on affected websites. Readers should verify the presence and public accessibility of the Happyforms plugin

CVE advisoryCRITICAL

CVE-2026-49766

WP User Manager Arbitrary File Deletion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in WP User Manager allows authenticated users to delete arbitrary files on a server, potentially leading to data loss or system compromise. This flaw exists in versions prior to 2.9.16 and is a concern due to the plugin's common use in WordPress sites. The primary concern is confirming the plug

CVE advisoryCRITICAL

CVE-2026-49765

Unauthenticated PHP Object Injection in Mailchimp and Contact Form 7 Integration <= 1.1.8

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical unauthenticated PHP object injection vulnerability exists in a WordPress integration plugin. Attackers could inject malicious code, potentially compromising website confidentiality, integrity, and availability. Confirming the plugin's use is essential for assessing risk.

CVE advisoryCRITICAL

CVE-2026-49764

RegistrationMagic Unauthenticated Broken Authentication Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a registration and form management technology, allowing unauthenticated attackers to bypass authentication and potentially gain unauthorized access. This issue could impact systems that handle user sign-ups and access controls. Confirming if this technology is in use is advised.

CVE advisoryCRITICAL

CVE-2026-49763

Unauthenticated PHP Object Injection in Contact Form 7 HubSpot Integration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP Object Injection vulnerability exists in the Integration for Contact Form 7 HubSpot plugin. Unauthenticated attackers can exploit this flaw to potentially execute arbitrary code, compromise system data, and impact website integrity. It is important to determine if this plugin is in use and exposed on pub

CVE advisoryCRITICAL

CVE-2026-49109

PHP Object Injection in Salesforce and Form Integration Plugin.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in a WordPress plugin that integrates contact forms with Salesforce and other builders. If reachable, this could allow attackers to inject malicious PHP objects, potentially leading to code execution. Confirming the plugin's use is critical to assessing risk.

CVE advisoryCRITICAL

CVE-2026-49106

Unauthenticated PHP Object Injection in Contact Form 7 and Constant Contact Integration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Integration for Contact Form 7 and Constant Contact plugin. Attackers could exploit this to execute arbitrary code on the server, potentially compromising the website and its data. Confirming if this plugin is in use and accessible from the internet is

CVE advisoryCRITICAL

CVE-2026-49105

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7 and other form plugins <= 1.1.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in multiple WordPress form plugins. This could allow attackers to execute arbitrary code on a server, potentially compromising confidentiality, integrity, and availability. Confirm if your organization uses these plugins to understand potential exposure and i

CVE advisoryCRITICAL

CVE-2026-49104

Unauthenticated PHP Object Injection in Keap Infusionsoft Integration Plugin.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP Object Injection vulnerability exists in a WordPress integration plugin, potentially allowing unauthenticated attackers to inject malicious code, leading to system compromise and data manipulation. This issue is relevant for any organization using this plugin for contact forms and CRM integration, as it

CVE advisoryCRITICAL

CVE-2026-49085

PHP Object Injection in WP Insightly for WordPress Forms

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability affects popular WordPress form plugins, allowing attackers to execute arbitrary code remotely via specially crafted requests. This issue could expose sensitive data or disrupt services if these plugins are in use and reachable externally. It is important to confirm

CVE advisoryCRITICAL

CVE-2026-49067

SQL Injection in Advanced 301 and 302 Redirect

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Advanced 301 and 302 Redirect plugin, potentially allowing attackers to access or modify sensitive data in the plugin's database. Because the vulnerability is network-reachable without authentication, it could impact systems relying on this redirect functiona

CVE advisoryCRITICAL

CVE-2026-48886

JS Help Desk SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in JS Help Desk software could permit attackers to interfere with database operations, potentially affecting data integrity and service availability. This issue is reachable over the network, and its relevance depends on the deployment of this specific software.

CVE advisoryCRITICAL

CVE-2026-48881

TrueBooker <= 1.1.9 Unauthenticated Broken Access Control

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated broken access control vulnerability exists in the TrueBooker appointment booking system, potentially allowing unauthorized users to access or modify sensitive information. This issue is externally reachable and could lead to data exposure or modification if the system is in use. Confirmation of its p

CVE advisoryCRITICAL

CVE-2026-48836

Easy Invoice Unauthenticated Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Easy Invoice allows unauthenticated remote code execution, enabling attackers to run unauthorized commands on affected systems. This could lead to a system compromise. Confirming its presence and reachability within the environment is crucial.

CVE advisoryCRITICAL

CVE-2026-45439

Unauthenticated SQL Injection in Realtyna Organic IDX Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Realtyna Organic IDX plugin, allowing an attacker to inject malicious SQL commands. This could lead to unauthorized access to sensitive data or service disruption. Confirming its presence and reachability within our environment is crucial to assess potential

CVE advisoryCRITICAL

CVE-2026-42665

WP Data Access Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WP Data Access plugin, potentially allowing attackers to execute malicious SQL commands. This could lead to unauthorized access to sensitive data or disruption of database operations if the plugin is used in relevant configurations. It is important to determi

CVE advisoryCRITICAL

CVE-2026-42639

GD Rating System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a WordPress rating system plugin. If reachable, this could allow unauthorized access to or modification of rating data, impacting data integrity and potentially leading to unauthorized access. The vulnerability is network-exploitable and not yet listed in known e

CVE advisoryCRITICAL

CVE-2026-42386

SQL Injection in WooCommerce Order Delivery Date Plugin

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Order Delivery Date feature of a WooCommerce plugin. This could allow attackers to access or modify sensitive database information if the feature is reachable. It is important to confirm if this plugin is in use to understand potential exposure.

CVE advisoryCRITICAL

CVE-2026-42381

Funnel Builder by FunnelKit SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Funnel Builder by FunnelKit, potentially allowing unauthorized access to sensitive data. This issue affects public-facing web applications where the plugin processes user interactions. Confirming relevance and exposure is key to understanding the business impact.

CVE advisoryCRITICAL

CVE-2026-40798

wpForo Forum Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in a popular forum plugin, potentially allowing attackers to access sensitive database information without authentication. This issue could lead to unauthorized data disclosure if the plugin is present and reachable. Confirmation of its use and impact is advised.

CVE advisoryCRITICAL

CVE-2026-40772

GeekyBot Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated arbitrary file upload vulnerability exists in GeekyBot, potentially allowing attackers to upload malicious files and gain unauthorized control of affected systems. This issue could lead to code execution or service disruption. Confirming if your environment is exposed and assessing the business impac

CVE advisoryCRITICAL

CVE-2026-40771

Contest Gallery Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in the Contest Gallery plugin could allow attackers to access or manipulate database information. Because this plugin is often used in internet-facing web applications, it may be reachable by external actors, posing a risk to sensitive data.

CVE advisoryCRITICAL

CVE-2026-39591

WP-BusinessDirectory Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability exists in a WordPress business directory plugin. If reachable, an attacker with limited privileges could upload malicious files, potentially leading to code execution or data compromise. You should care because this could impact system integrity and data confidentiality.

CVE advisoryCRITICAL

CVE-2026-39583

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Datalogics Ecommerce Delivery plugins that allows unauthenticated attackers to gain elevated privileges. This could lead to unauthorized access and modification of system data, impacting e-commerce operations. Confirming the use and network exposure of this plugin is crucial for asses

CVE advisoryCRITICAL

CVE-2026-39519

GeekyBot Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in GeekyBot, potentially allowing attackers to access or modify sensitive data in the application's database. The issue is reachable over the network without authentication, making it a concern for organizations using this software.

CVE advisoryCRITICAL

CVE-2026-39512

GeoDirectory Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in the GeoDirectory plugin allows attackers to access or modify database information through network requests. This could lead to unauthorized data access or service disruption for public-facing web components. Confirming relevance and exposure within your web infrastructu

CVE advisoryCRITICAL

CVE-2026-39511

WP Photo Album Plus SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the WP Photo Album Plus WordPress plugin. If reachable, attackers could inject malicious SQL code, potentially leading to database information exposure or service disruption. Confirming its use and exposure within the organization is important.

CVE advisoryCRITICAL

CVE-2026-39502

Form Maker by 10Web Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Form Maker plugin, potentially allowing attackers to access sensitive data from a website's database. This critical issue affects public-facing websites, and organizations should confirm if they use the affected plugin and assess its exposure.

CVE advisoryCRITICAL

CVE-2026-39493

SQL Injection in Simply Schedule Appointments Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability in an appointment scheduling plugin could allow attackers to access or modify sensitive data. While the exact business impact is uncertain, any team managing public-facing web applications should assess the relevance and exposure of this technology.

CVE advisoryCRITICAL

CVE-2026-39465

Responsive Slider by MetaSlider Editor Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in the Responsive Slider by MetaSlider WordPress plugin, potentially allowing an attacker with editor privileges to compromise a website. This issue impacts website content management and could lead to unauthorized code execution on the server if the vulnerable comp

CVE advisoryCRITICAL

CVE-2026-39441

Feed KuantoKusta WooCommerce Plugin SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Feed KuantoKusta for WooCommerce plugin, allowing attackers to inject malicious SQL commands. This could potentially lead to unauthorized access or manipulation of sensitive data stored within the WooCommerce system. The vulnerability is network-exposed, mean

CVE advisoryCRITICAL

CVE-2026-34901

iControlWP Unauthenticated Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in the iControlWP plugin. If reachable, an attacker could gain administrative control of a WordPress site without prior authentication, potentially impacting system integrity and availability. Uncertainty remains regarding the specific versions and business i

CVE advisoryCRITICAL

CVE-2026-27053

Broadcast Live Video Plugin PHP Object Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP object injection vulnerability exists in live video broadcasting technology. This flaw could allow unauthorized remote system access and significant data compromise if reachable. Leadership should ensure security teams confirm relevance and exposure to this critical issue.

CVE advisoryCRITICAL

CVE-2026-50890

Grocy Spending Report SQL Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability exists in a product management tool, allowing attackers to access sensitive database information via crafted SQL statements. While this could lead to unauthorized data access, the tool's typical self-hosted or internal deployment means external exposure may vary. It is important to determi

CVE advisoryCRITICAL

CVE-2026-50883

Matze Wastebin HTML Injection Executes Arbitrary Scripts

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An HTML injection vulnerability in a component of matze wastebin could allow attackers to execute arbitrary scripts via crafted input. This could potentially impact application behavior or lead to unauthorized actions if the affected system is reachable and processes malicious content.

CVE advisoryCRITICAL

CVE-2026-50880

YouTransfer sendmail Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated vulnerability in YouTransfer's sendmail transport integration allows attackers to execute arbitrary code via a crafted request. This could lead to a compromise of the affected system. The primary concern is confirming its relevance and exposure within our environment.

CVE advisoryCRITICAL

CVE-2026-50873

Flatnotes Attachment Handling Arbitrary File Upload Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An arbitrary file upload vulnerability exists in the attachment handling of flatnotes, a note-taking application. Attackers could exploit this to execute arbitrary code by uploading crafted HTML or SVG files. This is a concern for internally hosted web applications, especially those exposed to the internet. Uncertainty

CVE advisoryCRITICAL

CVE-2026-50872

Selfoss Loopback Request Handling Command Execution and Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can exploit a vulnerability in the loopback request handling of a web-based RSS reader to execute arbitrary commands and obtain sensitive information by sending a crafted HTTP request. This issue is relevant if the software is used and exposed, as it could lead to unauthorized command

CVE advisoryCRITICAL

CVE-2026-50871

Kanishka-Linux Reminiscence OS Command Injection Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An OS command injection flaw exists in a media archiving and export component, permitting arbitrary command execution through crafted input. The risk of this vulnerability depends on the component's reachability within the environment. If accessible, it could lead to unauthorized command execution on the system.

CVE advisoryCRITICAL

CVE-2026-50869

Bludit Directory Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A directory traversal vulnerability in Bludit's api/plugin.php component could allow attackers to access or modify arbitrary files on the server. This could potentially impact the integrity and availability of the entire system. The primary concern is to confirm if this technology is in use within our environment.

CVE advisoryCRITICAL

CVE-2026-49952

Discuz! X5.0 Authentication Bypass via Database Backup API

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Discuz! X5.0 has an authentication bypass vulnerability in its database backup API that allows unauthenticated attackers to access sensitive backup and restore functions. This could lead to unauthorized data access and user impersonation. It is critical to confirm if this affects any hosted community sites.

CVE advisoryCRITICAL

CVE-2026-48114

Metacat SQL Injection in Harvester Registration Endpoint Allows Full Database Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Metacat, used for data preservation and sharing, has a critical SQL injection vulnerability in its harvester registration endpoint. This flaw allows unauthenticated attackers to execute arbitrary commands, read, or write to the Metacat database, potentially impacting data integrity and availability. Organizations shoul

CVE advisoryCRITICAL

CVE-2026-45390

OCaml-tar Directory Traversal Leading to Arbitrary File Writes.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in the OCaml-tar library, allowing crafted archives to overwrite arbitrary files outside the intended extraction directory. This could impact systems processing archives if an attacker can reach a decompression endpoint. Uncertainty remains regarding how widely this library is integrated

CVE advisoryHIGH

CVE-2026-45389

OCaml-TLS Client Authentication Bypass Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in OCaml-TLS server implementations allows clients to bypass authentication by presenting certificates not intended for client authentication due to insufficient validation. This could enable impersonation and unauthorized access to services that rely on client certificate authentication. The relevance

CVE advisoryCRITICAL

CVE-2026-45388

OCaml-TLS Certificate Validation Flaw Allows Impersonation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in the OCaml-TLS library allows for server impersonation due to insufficient certificate validation. This could enable attackers to intercept or manipulate sensitive data exchanged during TLS sessions by tricking clients into connecting to malicious servers. Confirmation of OCaml-TLS usage and assessment of expo

CVE advisoryCRITICAL

CVE-2026-39196

Datadog Vector SQL Injection Vulnerability Allows Database Access.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability in Datadog Vector could allow attackers to access sensitive database information via crafted SQL statements. This affects the `KeyPartitioner::partition` function. Attackers can exploit this vulnerability remotely without authentication, potentially leading to unauthorized data exposure.

CVE advisoryCRITICAL

CVE-2026-39006

SNMP4J-Agent Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

SNMP4J-Agent has a vulnerability that could allow a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. This could impact system data and service behavior if the affected technology is in use and reachable. Understanding your deployment of this network management component is important for

CVE advisoryCRITICAL

CVE-2026-38812

RuoYi SQL Injection in Code Generation Module

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A SQL injection vulnerability in a code generation module of RuoYi may allow an authenticated attacker to access sensitive database information. This issue is in a tool typically used by administrators, and while network-accessible, its exposure is generally limited to authenticated internal users. Confirming its relev

CVE advisoryCRITICAL

CVE-2026-38329

Bludit CMS API Plugin Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Bludit CMS's API plugin allows remote code execution. This flaw, stemming from insufficient authorization and validation in a file upload endpoint, could enable an attacker with an API token to upload and execute malicious scripts on the server.

CVE advisoryCRITICAL

CVE-2026-38065

Tenda 5G03 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in Tenda 5G03 routers within the action_ims_on_with_apn function. If reachable, an unauthenticated attacker could inject commands by manipulating the ims_apn parameter. This could lead to a compromise of the device. The affected technology is a network edge gateway, making it a

CVE advisoryCRITICAL

CVE-2026-38064

Tenda 5G03 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in Tenda 5G03 devices, allowing unauthenticated attackers to execute arbitrary commands remotely. This could lead to device compromise, affecting system data and service behavior. Verifying the presence and network exposure of these devices is crucial.

CVE advisoryCRITICAL

CVE-2026-38063

Tenda 5G03 Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability exists in Tenda 5G03 routers, allowing unauthenticated attackers to execute arbitrary commands over the network by manipulating a specific function's parameter. This could compromise the device's integrity and the security of the network it manages.

CVE advisoryCRITICAL

CVE-2026-38062

Tenda 5G03 Command Injection Vulnerability in ratMode Function.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Tenda 5G03 routers have a critical command injection vulnerability exploitable remotely without authentication. An attacker could execute arbitrary commands, potentially compromising the device and its managed network. Confirm if these routers are in use and exposed to understand the risk.

CVE advisoryCRITICAL

CVE-2026-38061

Tenda 5G03 Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Tenda 5G03 routers are affected by a critical command injection vulnerability in the `action_set_volume` function. Attackers can exploit this flaw over the network to execute arbitrary commands, potentially leading to full device compromise. This vulnerability affects network edge devices and requires assessment of exp

CVE advisoryCRITICAL

CVE-2026-36537

ThingsBoard v4.3.0.1 Authentication Bypass via OAuth Code Exchange

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the platform's OAuth authorization code exchange allows unauthenticated attackers to bypass authentication by manipulating user identity data, leading to full account takeover. This critical issue affects any existing user account accessible through the platform.

CVE advisoryCRITICAL

CVE-2026-30121

Remotion Arbitrary File Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical arbitrary file write vulnerability exists in a software library used for programmatic video creation. This flaw could permit unauthorized file modifications on affected systems if reachable. It is important to determine if this library is utilized and assess its integration into operations.

CVE advisoryCRITICAL

CVE-2026-30120

Remotion Remote Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical remote code execution vulnerability exists in the Remotion software, a development tool used for creating videos programmatically. If reachable, an attacker could execute arbitrary code on affected systems without authentication. Confirming where Remotion is used within our environment is crucial to assess r

CVE advisoryKnown Exploit

CVE-2026-20262

Cisco Catalyst SD-WAN Manager File Write Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Cisco Catalyst SD-WAN Manager's web UI allows authenticated users to create or overwrite files on the system. This occurs due to improper input validation during file uploads. If exploited, an attacker could potentially gain elevated privileges by manipulating system files. This impacts systems reach

• CISA KEV

CVE advisoryCRITICAL

CVE-2026-9862

Fortra BoKS OS Command Injection in boks_autoregisterd Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical OS command injection vulnerability exists in Fortra's Core Privileged Access Manager's autoregistration service. This flaw may allow a remote attacker with network access to execute commands with elevated privileges. It is uncertain if this technology is in use or how exposed it may be.

CVE advisoryCRITICAL

CVE-2026-52704

WooCommerce PDF Invoice Builder Code Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in a WooCommerce PDF Invoice Builder plugin, enabling remote code inclusion. Attackers can potentially execute arbitrary code, impacting system integrity and availability. It is crucial to identify if this plugin is deployed within the environment to assess its relevance and exposure.

CVE advisoryCRITICAL

CVE-2018-25436

WordPress Plugin Baggage Freight Shipping Australia Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A WordPress plugin has an unrestricted file upload vulnerability, allowing unauthenticated attackers to upload arbitrary files. This could lead to remote code execution if the `upload-package.php` endpoint is reachable. You should care because it enables attackers to run malicious code on your systems without authentic

CVE advisoryCRITICAL

CVE-2026-5482

Responsive FileManager Unrestricted File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Responsive FileManager allows unauthenticated attackers to upload unrestricted file types, potentially leading to remote code execution. As the project is unmaintained, understanding its presence and exposure is crucial for security. Attackers can exploit the `dialog.php` endpoint to execute

CVE advisoryCRITICAL

CVE-2026-49757

AshAuthentication Bypass Allows Account Takeover via OAuth2/OIDC

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in team-alembic AshAuthentication, allowing attackers to take over local user accounts via OAuth2/OIDC sign-in by spoofing email addresses. This could grant attackers full local privileges if they can control an OAuth provider account with a victim's email. The relevance an

CVE advisoryCRITICAL

CVE-2026-8935

WP MAPS PRO Unauthenticated Admin Account Creation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in the WP MAPS PRO WordPress plugin allows unauthenticated users to create an administrator account and gain full site access. This occurs because an AJAX action can be triggered with a publicly available nonce, leading to the unconditional creation of an admin account and a magic-login URL. This could