Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 0D5ACD84-8796-

Exploit for Cross-site Scripting in Docmost_0D5ACD84-8796-5644-A05C-46FADC4B35D4

CVE-2026-34212 Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a ...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.4 0A738D4C-E642-

Exploit for Authorization Bypass Through User-Controlled Key in Docmost_0A738D4C-E642-58D3-988B-4E964946EC66

CVE-2026-34213 A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored ...

N/A N/A GITHUBEXPLOIT
HIGH 7.6 E61DF141-B3A8-

Exploit for CVE-2026-34207_E61DF141-B3A8-537B-8845-233051D12F82

CVE-2026-34207 The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook...

N/A N/A GITHUBEXPLOIT
HIGH 8.3 22CFEBF4-738A-

Exploit for Missing Authorization in Plane_22CFEBF4-738A-52AD-B1A9-E066D3D33C80

CVE-2026-46558 Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one auth...

N/A N/A GITHUBEXPLOIT
NONE 2DE71726-382B-

web-security-auditor_2DE71726-382B-5653-8780-93100257F741

Web Security Auditor Auditor automático de seguridad web desarrollado en Python. Esta herramienta está diseñada para ayudar a administradores y des...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 712DBDD2-D55C-

Exploit for CVE-2026-54807_712DBDD2-D55C-55CD-96E6-3E6BD0518E8D

CVE-2026-54807 CVE-2026-54807 WooCommerce Privilege Escalation ║ ║ Unauthenticated Admin Role Assignment via Reg. Form PRİV8 TOOLS AND EXPLOİT CANA...

N/A N/A GITHUBEXPLOIT
NONE 48329317-B6F8-

CSP-Exploitation_48329317-B6F8-5615-9745-63DAED1542EF

No description provided...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CF7939CB-77F8-

Exploit for CVE-2026-43503_CF7939CB-77F8-5507-B35A-608D578D47B0

No description provided...

N/A N/A GITHUBEXPLOIT
NONE 805FCFAF-D9DD-

vuln-scanner-agent_805FCFAF-D9DD-5870-AE2C-44FA673CCB8B

vuln-scanner-agent A multi-agent vulnerability scanner for GitHub repositories, Docker images, and web applications. Combines CVE detection, static...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 BECF4517-38B6-

Exploit for Authentication Bypass Using an Alternate Path or Channel in Nvidia Triton_Inference_Server_BECF4517-38B6-5DC3-97A0-FDF34F1763C0

CVE-2026-24207 / 24206 — NVIDIA Triton Inference Server SageMaker & Vertex AI auth bypass Unauthenticated attackers can reach the model-management ...

N/A N/A GITHUBEXPLOIT