Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-50225

Account Creation Exhaustion_CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.6 CVE-2026-49771

WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability_CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL...

10Web Photo Gallery by 10Web n/a CVE
HIGH 8.7 CVE-2026-50213

Bulk User Private Data Harvesting_CVE-2026-50213

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ide...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.1 CVE-2026-50212

Arbitrary Remote Device Unbinding_CVE-2026-50212

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe ...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50211

Exposed Factory Testing App Boundaries_CVE-2026-50211

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to i...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.5 CVE-2026-50207

Local Modem Manipulation via Binder Interfaces_CVE-2026-50207

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellu...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.2 CVE-2026-3820

Supermicro BMC’s SMTP service contains a command injection vulnerability_CVE-2026-3820

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inje...

SMCI AS-2115HS-TNR 01.08.01 CVE
HIGH 8.5 CVE-2026-49189

Broadcast Receiver Privilege Escalation_CVE-2026-49189

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49188

Elevated Root Command Execution via ai_cmd Sockets_CVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to exe...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49187

Hard-coded APK Resource Credentials & Scepters_CVE-2026-49187

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

Acer Connect M6E 5G Portable WiFi Router * CVE