Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2026-50084

Aqara API cross-account access_CVE-2026-50084

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an in...

Aqara Cloud Production API 2026-04-20 CVE
CRITICAL 9.1 CVE-2026-50083

Aqara hardcoded OAuth client credentials_CVE-2026-50083

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Cred...

Aqara Aquara IAM/SSO Gateway 2026-04-20 CVE
CRITICAL 9.4 CVE-2026-45833

CVE-2026-45833_CVE-2026-45833

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on ...

Chroma ChromaDB 0.4.17 CVE
CRITICAL 9.3 6F97F4B7-80CC-

Exploit for Improper Authentication in Checkpoint Gaia_Os_6F97F4B7-80CC-50A6-87D2-6C3340B5EB76

CVE-2026-50751 — Check Point IKEv1 Authentication Bypass Standalone proof-of-concept for CVE-2026-50751 — a critical Check Point IKEv1 authenticati...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.3 CVE-2026-11849

IEI Integration Corp|iRM-IEI Remote Management – Hard-coded Credentials_CVE-2026-11849

The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attacke...

IEI Integration Corp iRM-TSi410X CVE
CRITICAL 9.8 18B3A832-3857-

Exploit for CVE-2026-35273_18B3A832-3857-553E-8B25-344C7CE9BA37

🚨 CVE-2026-35273 - Oracle PeopleSoft PeopleTools Unauthenticated Remote Code Execution --- ⚠️ Critical Unauthenticated RCE in Oracle PeopleSoft Pe...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 34F810C9-3E08-

Exploit for CVE-2026-48907_34F810C9-3E08-5B0C-A381-8848015036B6

🚨 CVE-2026-48907 - JCE Joomla Content Editor Unauthenticated Remote Code Execution --- ⚠️ Critical Unauthenticated RCE in JCE Joomla Content Edito...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 C0C41549-A96F-

Exploit for CVE-2026-49777_C0C41549-A96F-54F9-85D8-1A24CFAE99BD

CVE-2026-49777 CVE-2026-49777 - ShapedPlugin Product Slider Pro for WooCommerce Backdoor RCE In-Depth Technical Analysis: Product Slider Pro Backdo...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 8A02EE6F-39EF-

Exploit for CVE-2026-8809_8A02EE6F-39EF-56A6-B360-BF2E4D44DF48

CVE-2026-8809 Advanced Custom Fields: Extended = 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to 'acfpostid' Parameter This...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-48611

CVE-2026-48611_CVE-2026-48611

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthor...

phpBB phpBB 3.3.0 CVE