Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-13163

Lack of input validation in Mailerup input parameter leads to Open Redirect_CVE-2026-13163

Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c//) in Mailerup

Mailerup Mailerup CVE
HIGH 8.8 CVE-2026-12242

AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute_CVE-2026-12242

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' ...

adegans AdRotate Banner Manager CVE
HIGH 8.4 CVE-2026-42450

OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser_CVE-2026-42450

OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with ...

AcademySoftwareFoundation OpenColorIO < 2.5.2 CVE
HIGH 8.6 CVE-2026-35025

ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR_CVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory AC...

ProFTPD Project ProFTPD 1.3.9b, 1.3.10rc2 CVE
CRITICAL 10 CVE-2026-12537

Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows_CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub A...

Google Cloud Gemini CLI CVE
MEDIUM 5.5 CVE-2026-11968

Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) in TortoiseGit_CVE-2026-11968

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

TortoiseGit team TortoiseGit 1.8.10.0 CVE
MEDIUM 6.9 CVE-2026-13150

SSRF in Pentestify PDF generation endpoint via Host header_CVE-2026-13150

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 ...

Pentestify Pentestify CVE
HIGH 7.9 CVE-2026-10745

CVE-2026-10745_CVE-2026-10745

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampe...

upKeeper Solutions upKeeper Instant Privilege Access CVE
MEDIUM 4.3 CVE-2026-9724

MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update_CVE-2026-9724

The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing ...

motordesk MotorDesk CVE
MEDIUM 4.3 CVE-2026-9721

Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update_CVE-2026-9721

The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is ...

chuhpl Book a Room Event Calendar CVE