Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-42450

OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser_CVE-2026-42450

OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with ...

AcademySoftwareFoundation OpenColorIO < 2.5.2 CVE
HIGH 8.6 CVE-2026-35025

ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR_CVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory AC...

ProFTPD Project ProFTPD 1.3.9b, 1.3.10rc2 CVE
CRITICAL 10 CVE-2026-12537

Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows_CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub A...

Google Cloud Gemini CLI CVE
MEDIUM 5.5 CVE-2026-11968

Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) in TortoiseGit_CVE-2026-11968

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

TortoiseGit team TortoiseGit 1.8.10.0 CVE
MEDIUM 6.9 CVE-2026-13150

SSRF in Pentestify PDF generation endpoint via Host header_CVE-2026-13150

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 ...

Pentestify Pentestify CVE
HIGH 7.9 CVE-2026-10745

CVE-2026-10745_CVE-2026-10745

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampe...

upKeeper Solutions upKeeper Instant Privilege Access CVE
MEDIUM 4.3 CVE-2026-9724

MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update_CVE-2026-9724

The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing ...

motordesk MotorDesk CVE
MEDIUM 4.3 CVE-2026-9721

Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update_CVE-2026-9721

The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is ...

chuhpl Book a Room Event Calendar CVE
HIGH 7.2 CVE-2026-9643

WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging_CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versio...

joomunited WP Meta SEO CVE
MEDIUM 6.4 CVE-2026-9620

WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripting via Post Content Image src Attribute_CVE-2026-9620

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions ...

joomunited WP Latest Posts CVE