Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-10872

Shibby Tomato Web UI rc start_vpnserver os command injection_CVE-2026-10872

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI....

Shibby Tomato 1.28.0000 CVE
MEDIUM 5.3 CVE-2026-10875

projectworlds Online Art Gallery Shop Project adminHome.ph sql injection_CVE-2026-10875

A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /...

projectworlds Online Art Gallery Shop Project 1.0 CVE
MEDIUM 5.3 CVE-2026-10874

projectworlds Online Art Gallery Shop Project adminHome.php sql injection_CVE-2026-10874

A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin...

projectworlds Online Art Gallery Shop Project 1.0 CVE
HIGH 7.5 CVE-2025-8873

Arista EOS Dataplane Denial of Service via Malformed IPsec Packet_CVE-2025-8873

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec tra...

Arista Networks EOS 4.33.0M CVE
MEDIUM 5.3 CVE-2026-10876

SourceCodester Ship Ferry Ticket Reservation System admin improper authorization_CVE-2026-10876

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. Th...

SourceCodester Ship Ferry Ticket Reservation System 1.0 CVE
HIGH 7.2 CVE-2026-10586

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery_CVE-2026-10586

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in ...

wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns CVE
MEDIUM 5.3 CVE-2026-50589

CVE-2026-50589_CVE-2026-50589

In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RP...

OpenStack Ironic 32.0.0 CVE
MEDIUM 5.3 CVE-2026-10878

D-Link DWR-M920 formSmsManage sub_41C8E8 command injection_CVE-2026-10878

A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a ...

D-Link DWR-M920 1.1.50 CVE
MEDIUM 6.9 CVE-2026-10877

SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection_CVE-2026-10877

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of th...

SourceCodester Ship Ferry Ticket Reservation System 1.0 CVE
MEDIUM 6.5 MS:CVE-2026-47655

Microsoft Graph Information Disclosure Vulnerability_MS:CVE-2026-47655

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

N/A N/A MSCVE