Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 CVE-2026-8797

CVE-2026-8797_CVE-2026-8797

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary co...

NEC Corporation ExpressUpdate Agent for Windows 3.24 and prior CVE
HIGH 8.8 CVE-2026-50741

CVE-2026-50741_CVE-2026-50741

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by s...

Revive Adserver CVE
HIGH 7.5 CVE-2026-48933

CVE-2026-48933_CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability af...

nodejs node 22.22.3 CVE
HIGH 7.7 CVE-2026-48618

CVE-2026-48618_CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due t...

nodejs node 22.22.3 CVE
HIGH 8.8 921E88F8-3925-

Exploit for CVE-2026-43503_921E88F8-3925-519D-9067-4928D48E9B4D

CVE-2026-43503 — DirtyClone Linux local privilege escalation. A cloned skbuff loses the SKBFLSHAREDFRAG flag, so ESP in-place decryption writes int...

N/A N/A GITHUBEXPLOIT
HIGH 7.1 CVE-2026-40941

Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages_CVE-2026-40941

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass all...

Cacti cacti < 1.2.31 CVE
HIGH 7.2 CVE-2026-40083

Cacti: SQL Injection in managers.php_CVE-2026-40083

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+im...

Cacti cacti < 1.2.31 CVE
HIGH 8.7 CVE-2026-9221

Setracker2 Children’s Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algorithm_CVE-2026-9221

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating ...

Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker CVE
HIGH 8.7 CVE-2026-9220

Setracker2 Children’s Smartwatch Ecosystem Use of hard-coded cryptographic key_CVE-2026-9220

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hard...

Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker 3.1.5 CVE
HIGH 8.3 CVE-2026-9219

Setracker2 Children’s Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers_CVE-2026-9219

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment...

Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker CVE