Daily digest
Sunday 5 April 2026
A quiet day: only 14 new CVEs against a recent average of about 51. Of those, 5 high. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2026-5567High· 8.8A flaw has been found in Tenda M3 1.0.0.10
A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead …
CVE-2026-5566High· 8.8A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote explo…
CVE-2026-5530Medium· 6.3PoCA flaw has been found in Ollama up to 0.18.1
A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be …
CVE-2026-5570High· 7.3A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30
A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible to initiate the atta…
CVE-2026-5569High· 7.3A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be perf…
CVE-2026-5565High· 7.3A security vulnerability has been detected in code-projects Simple Laundry System 1.0
A security vulnerability has been detected in code-projects Simple Laundry System 1.0. Affected by this issue is some unknown functionality of the file /delmemberinfo.php of the component Parameter Handler. Such manipulation of the argum…
CVE-2026-5590Medium· 6.4A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context da…
CVE-2026-5559Medium· 6.3PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py
PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py
CVE-2026-5528Medium· 6.3A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the atta…
CVE-2026-5531Medium· 5.3A vulnerability has been found in SourceCodester Student Result Management System 1.0
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext stor…
CVE-2026-5527Medium· 5.3A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation c…
CVE-2026-5529Medium· 4.3A vulnerability was detected in Dromara lamp-cloud up to 5.8.1
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorizatio…
Most-affected vendors
By CVEs published in the period.