Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-56009

WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56009

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored X...

Bricksable Bricksable for Bricks Builder n/a CVE
LOW 2.1 CVE-2026-40457

Reflected XSS in LMS_CVE-2026-40457

A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netrem...

LMS LMS CVE
HIGH 8.6 CVE-2026-40456

OS Command Injection in LMS_CVE-2026-40456

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to th...

LMS LMS CVE
HIGH 8.6 CVE-2026-40455

SQL Injection in LMS_CVE-2026-40455

An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient s...

LMS LMS CVE
HIGH 7.3 CVE-2026-11958

Local privilege escalation in ANSSI’s DFIR-ORC_CVE-2026-11958

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior...

ANSSI DFIR-ORC CVE
HIGH 8.6 CVE-2026-11719

CVE-2026-11719_CVE-2026-11719

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol hand...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.3.0 CVE
CRITICAL 9.3 CVE-2026-11718

CVE-2026-11718_CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When th...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.0.0 CVE
CRITICAL 9.3 CVE-2026-11717

CVE-2026-11717_CVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When ve...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.0.0 CVE
HIGH 7.1 CVE-2026-54224

Denial of Service in UBB.threads_CVE-2026-54224

UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many regis...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54223

Remote Code Execution via arbitrary file read and write in UBB.threads_CVE-2026-54223

UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s se...

UBB Systems UBB.threads CVE