Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2384 articles · 130606 vulns · 36/41 feeds (7d)
← Back to list
6.3
CVE-2026-3965KEVEXPLOITED

A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the

Description

A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.20.2 is able to address this issue. The identifier of the patch is 6bec52dca158481258315ba0fc2f11206df7b719. It is advisable to upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

References

  • https://github.com/A7cc/cve/issues/6
  • https://github.com/A7cc/cve/issues/6#issue-3999235307(Exploit)
  • https://github.com/whyour/qinglong/
  • https://github.com/whyour/qinglong/commit/6bec52dca158481258315ba0fc2f11206df7b719
  • https://github.com/whyour/qinglong/pull/2941
  • https://github.com/whyour/qinglong/releases/tag/v2.20.2
  • https://vuldb.com/?ctiid.350394
  • https://vuldb.com/?id.350394
  • https://vuldb.com/?submit.768861

Related News (1 articles)

Tier D
The Hacker News3h ago
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
→ No new info (linked only)
CVSS 3.16.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-693
PublishedMar 12, 2026
Last enriched28d ago
Trending Score92
Source articles1
Independent1
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 12, 2026
Added to CISA KEV
Mar 12, 2026
Actively Exploited
Mar 12, 2026
Discovered by ZDM
Apr 1, 2026