Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.
CVE-2026-23550
Modular DS
General
⚡ nuclei
10.0
CRITICAL
EPSS
4.8%
CVE-2026-28409
WeGIA
General
⚡ nuclei
10.0
CRITICAL
EPSS
1.4%
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.
CVE-2026-41940
🔥 KEV
cPanel
General
⚡ nuclei
9.3
CRITICAL
EPSS
67.0%
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVE-2026-25616
Blesta
General
⚡ nuclei
4.7
MEDIUM
EPSS
2.5%
Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.