Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 MS:CVE-2026-48567

Azure HorizonDB Elevation of Privilege Vulnerability_MS:CVE-2026-48567

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
CRITICAL 9.1 MS:CVE-2026-48579

Microsoft Exchange Online Information Disclosure Vulnerability_MS:CVE-2026-48579

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
CRITICAL 9.8 CVE-2025-67446

CVE-2025-67446_CVE-2025-67446

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cook...

Neterbit NW-431F Router 20241014-IR03 and before CVE
CRITICAL 9.1 CVE-2026-50076

Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass_CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a re...

Apache Software Foundation Apache Fory CVE
CRITICAL 9.3 CVE-2026-25550

Seagull Software BarTender Unauthenticated RCE via .NET Remoting Service_CVE-2026-25550

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed...

Seagull Software, LLC. BarTender 2010 CVE
CRITICAL 9.8 CVE-2026-10880

Unauthenticated SQL Injection in Osnexus Quantastor_CVE-2026-10880

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being inco...

Osnexus QuantaStor 5.9 CVE
CRITICAL 9.8 CVE-2025-67447

CVE-2025-67447_CVE-2025-67447

The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does...

Neterbit Neterbit NW-431F Router 20241014-IR03 and before CVE
CRITICAL 9.8 CVE-2025-71316

SQLite sqldiff remote code execution via argument injection_CVE-2025-71316

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker c...

SQLite sqldiff CVE
CRITICAL 9.8 18D066FB-7925-

Exploit for Stack-based Buffer Overflow in Microsoft_18D066FB-7925-51D0-8F62-50C464096DBA

CVE-2026-41089 !TIP If the setup does not start, add the folder to the allowed list or pause protection for a few minutes. !CAUTION Some security s...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 309255BC-02CF-

Exploit for CVE-2026-8732_309255BC-02CF-52BD-9DA4-CEAB202BEECD

CVE-2026-8732 – WordPress WP Maps Pro Exploit Unauthenticated Admin Takeover | CVSS 9.8 | Ready to use 🔥 What you get - Fully working Python explo...

N/A N/A GITHUBEXPLOIT