Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 AE6219F6-F23B-

Exploit for CVE-2026-48907_AE6219F6-F23B-5FB3-886B-AFFE2FBDB4B1

CVE-2026-48907 CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2025-66391

CVE-2025-66391_CVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system...

n/a n/a n/a CVE
MEDIUM 6 CVE-2026-55748

CVE-2026-55748_CVE-2026-55748

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. ...

OpenStack Horizon 8.0.0 CVE
CRITICAL 9.6 CVE-2026-55743

OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution_CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypass...

tinyhumansai OpenHuman CVE
CRITICAL 9.3 CVE-2026-54812

WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability_CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Inject...

StylemixThemes Motors n/a CVE
HIGH 7.5 CVE-2026-54810

WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability_CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

Nexi Payments Nexi XPay n/a CVE
HIGH 8.1 CVE-2026-54415

Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover_CVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authentica...

Azuriom Azuriom CMS CVE
HIGH 7.4 CVE-2026-49502

CVE-2026-49502_CVE-2026-49502

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent netwo...

Dell PowerFlex CVE
MEDIUM 4.8 CVE-2026-48142

NGINX ngx_http_charset_module vulnerability_CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location b...

F5 NGINX Open Source 1.13.10 CVE
MEDIUM 6.8 CVE-2026-48117

DroneAware’s Improper Account Activation in Registration and SSO Flows Leads to Account Takeover_CVE-2026-48117

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack...

fduflyer DroneAware-Node-Releases < server-2026-05-20 CVE