Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-12161

CVE-2026-12161_CVE-2026-12161

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permi...

Devolutions Remote Desktop Manager 2026.2.7 CVE
HIGH 8.3 CVE-2025-14272

Rockwell Automation FactoryTalk Analytics PavilionX_CVE-2025-14272

A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorize...

Rockwell Automation FactoryTalk Analytics PavilionX 7.0 CVE
CRITICAL 9.2 CVE-2025-13036

Rockwell Automation FactoryTalk Historian Site Edition – Authentication Bypass_CVE-2025-13036

An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an...

Rockwell Automation FactoryTalk Historian SE v11 CVE
HIGH 8.7 CVE-2025-11694

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities_CVE-2025-11694

A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP p...

Rockwell Automation CompactLogix 5370 V36 CVE
CRITICAL 9.8 CVE-2026-50880

CVE-2026-50880_CVE-2026-50880

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted r...

YouTransfer Team YouTransfer v1.0.6 CVE
HIGH 7.5 CVE-2026-50879

CVE-2026-50879_CVE-2026-50879

An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted PO...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50878

CVE-2026-50878_CVE-2026-50878

An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted req...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50877

CVE-2026-50877_CVE-2026-50877

An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-50873

CVE-2026-50873_CVE-2026-50873

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uplo...

flatnotes flatnotes v5.5.4 CVE
MEDIUM 5.5 CVE-2026-12162

CVE-2026-12162_CVE-2026-12162

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose store...

Devolutions Remote Desktop Manager 2026.2.0 CVE