Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 7CCF82DA-9ED8-

Exploit for Generation of Predictable IV with CBC Mode in Redhat Enterprise_Linux_7CCF82DA-9ED8-5712-B61D-DF768142FF9C

CVE-2014-3566...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.3 CVE-2026-13482

skypilot-org skypilot User ID server.py username.encode weak hash_CVE-2026-13482

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the...

skypilot-org skypilot 0.1 CVE
MEDIUM 4.2 CVE-2026-10644

Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer_CVE-2026-10644

The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains an out-of-bounds write in i...

zephyrproject zephyr 4.4.0 CVE
MEDIUM 6.5 CVE-2026-10593

Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling_CVE-2026-10593

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_s...

zephyrproject zephyr 4.3.0 CVE
MEDIUM 6.5 CVE-2026-58058

Nmap – Integer Underflow in IPv6 Extension Header Parsing_CVE-2026-58058

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so th...

Nmap Nmap CVE
MEDIUM 5 CVE-2026-58057

Flowise – Custom MCP Environment Variable Denylist Bypass via Case Sensitivity_CVE-2026-58057

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where en...

Flowise Flowise CVE
MEDIUM 5.4 CVE-2026-58055

nghttp2 nghttpx – HTTP Request/Response Smuggling via Upgrade Request with Content-Length_CVE-2026-58055

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-a...

nghttp2 nghttp2 CVE
MEDIUM 6.5 CVE-2026-58051

libssh2 – Free of Uninitialized Pointer in publickey List Cleanup_CVE-2026-58051

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a pars...

libssh2 libssh2 CVE
MEDIUM 4.3 9A2D458D-9B05-

TLS1.2_Exploit-Scripts_9A2D458D-9B05-57CD-B884-F823B4CD8735

Breaking TLS 1.2 — Penetration Testing Lab & Exploit Scripts This repository is the companion lab to the Medium article: Breaking TLS 1.2: A Penetr...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CED4BCD6-8E56-

Exploit for CVE-2026-12432_CED4BCD6-8E56-5FF9-A68C-174EFA9EBB61

CVE-2026-12432: WP Full Stripe Free = 8.4.4 - Published: June 26, 2026 - Last Updated: June 27, 2026 - Researcher: Netwurm - VTDR e.V.i.G. Vulnerab...

N/A N/A GITHUBEXPLOIT