Retour aux CVE tendances

Semaine du 4 mai 2026

CVE tendances* des 7 derniers jours (du 27 avril 2026 au 4 mai 2026)

1
CVE-2026-31431Linux / Linux Kernel
NouveauKEV
Score SYRN95
CVSS7.8
Activité385
Publié22/04/2026
StatutTrès actif

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

2
CVE-2026-3854Github / Enterprise Server
Score SYRN63
CVSS8.7
Activité142
Publié10/03/2026
StatutTrès actif

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7 and 3.19.4.

3
CVE-2026-41940Cpanel / Cpanel
NouveauKEV
Score SYRN97
CVSS9.3
Activité140
Publié29/04/2026
StatutTrès actif

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

4
CVE-2026-32202Microsoft / Microsoft Windows
KEV
Score SYRN91
CVSS4.3
Activité80
Publié14/04/2026
StatutTrès actif

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

5
Score SYRN65
CVSS
Activité58
Publié
StatutTrès actif
6
CVE-2026-25874Huggingface / Lerobot
Score SYRN77
CVSS9.3
Activité20
Publié23/04/2026
StatutActif

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.

7
CVE-2026-42167Proftpd / Proftpd
Nouveau
Score SYRN80
CVSS8.1
Activité13
Publié28/04/2026
StatutActif

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

8
CVE-2026-6443Essentialplugin / Accordion And Accordion Slider
Score SYRN44
CVSS9.8
Activité12
Publié17/04/2026
StatutActif

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

9
CVE-2024-1708Connectwise / Screenconnect
KEV
Score SYRN97
CVSS8.4
Activité11
Publié21/02/2024
StatutActif

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

10
CVE-2026-3008Notepad++ / Notepad++
Score SYRN50
CVSS6.6
Activité8
Publié27/04/2026
StatutActif

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement