Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MSF:PAYLOAD-LINUX-

Linux Execute Command_MSF:PAYLOAD-LINUX-LOONGARCH64-EXEC-

Execute an arbitrary command. Module Options msf use payload/linux/loongarch64/exec msf payloadexec show actions ...actions... msf payloadexec set ...

N/A N/A METASPLOIT
NONE 047D7143-EABB-

pwn-grind_047D7143-EABB-5F2A-A688-499B4431F3D6

Description Daddy, teach me how to use random value in programming! This challenge demonstrates that rand without a seed is deterministic. Its outp...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 E7B8F6E4-E610-

0-day-PoC-Repo_E7B8F6E4-E610-5834-9597-E054A9B69439

If you wish to collaborate/discuss with me, contact me on discord @ashdfrkl Sharing this repo keeps me motivated to continue dropping 0-days for yo...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 CVE-2026-49416

Integer overflow in vt(4) CONS_HISTORY ioctl_CVE-2026-49416

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size...

FreeBSD FreeBSD 15.0-RELEASE CVE
HIGH 7.5 CVE-2026-36848

CVE-2026-36848_CVE-2026-36848

Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

n/a n/a n/a CVE
HIGH 8.7 CVE-2026-58000

luci-proto-openvpn – Command Injection via cl_meta Parameter in generateKey_CVE-2026-58000

luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_...

openwrt luci 0.11.1 CVE
HIGH 7.7 CVE-2026-57999

luci-app-tailscale-community – Command Injection via tailscale.do_login RPC_CVE-2026-57999

luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to exe...

openwrt luci CVE
MEDIUM 6.9 CVE-2026-53428

Unbounded memory allocation in highlight_lines range expansion in mdex_CVE-2026-53428

Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through...

leandrocp mdex 0.11.0 CVE
LOW 2.3 CVE-2026-53427

Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute_CVE-2026-53427

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cro...

leandrocp mdex 0.11.3 CVE
MEDIUM 6.2 CVE-2026-13757

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing_CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_va...

Red Hat Red Hat Enterprise Linux 10 CVE