Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.2 CVE-2026-12567

Symlink-following arbitrary write via github_workflows module_CVE-2026-12567

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacke...

Black Lantern Security BBOT 2.0.0 CVE
LOW 3.1 CVE-2026-12566

SSRF via unvalidated WWW-Authenticate realm in docker_pull module_CVE-2026-12566

The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without va...

Black Lantern Security BBOT 2.0.0 CVE
MEDIUM 5.3 CVE-2026-12565

Path Traversal (Zip-Slip) in unarchive module_CVE-2026-12565

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behav...

Black Lantern Security BBOT 2.3.1 CVE
HIGH 7.2 CVE-2026-53676

CVE-2026-53676_CVE-2026-53676

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can lo...

ThingsBoard ThingsBoard prior to v4.3.1.2 CVE
HIGH 7.5 CVE-2026-45357

LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)_CVE-2026-45357

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime...

harttle liquidjs < 10.26.0 CVE
HIGH 8.8 CVE-2026-55202

Tinyproxy – Stathost Detection Bypass via Host Header Manipulation_CVE-2026-55202

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated a...

tinyproxy tinyproxy CVE
HIGH 7.4 CVE-2026-55201

Evil-WinRM – Path Traversal in download_dir() Function_CVE-2026-55201

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or comp...

Hackplayers evil-winrm CVE
CRITICAL 9.2 CVE-2026-55200

libssh2 – Out-of-Bounds Write via Unchecked packet_length in transport.c_CVE-2026-55200

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper ...

libssh2 libssh2 CVE
HIGH 8.2 CVE-2026-55199

libssh2 – Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler_CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in s...

libssh2 libssh2 CVE
MEDIUM 6.9 CVE-2026-12529

SourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access control_CVE-2026-12529

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown ...

SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 CVE