Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-33560

Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type_CVE-2026-33560

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users t...

Daktronics VFC-DMP-5000 CVE
HIGH 8.8 A4F1D39D-10D1-

Exploit for CVE-2026-43503_A4F1D39D-10D1-581E-84B1-21CD3BF8EF3D

No description provided...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 030DAD67-A828-

Exploit for Deserialization of Untrusted Data in Splunk_030DAD67-A828-5EBE-BC28-DC3BB6C406CE

CVE-2026-20251 — Splunk Secure Gateway jsonpickle Deserialization RCE Researcher: Fady Oueslati · ReactiveZero Security Research Reference: 2026FO-...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 CVE-2026-45195

GPU DDK – rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted_CVE-2026-45195

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the...

Imagination Technologies Graphics DDK 1.18 RTM CVE
HIGH 7.7 CVE-2026-21734

GPU DDK – libusc OOB write at TreeRemove during WebGPU shader compilation_CVE-2026-21734

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the G...

Imagination Technologies Graphics DDK 1.18 RTM CVE
HIGH 7.2 CVE-2026-13372

CVE-2026-13372_CVE-2026-13372

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allo...

Devolutions Remote Desktop Manager 2026.2.5 CVE
HIGH 8.8 CVE-2026-52784

OpenProject: CSRF on TARGET through /users/:id via POST parameter “user[admin]”_CVE-2026-52784

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POS...

opf openproject < 17.3.3 CVE
HIGH 8.2 CVE-2026-52783

OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others “storage..httpx_access_token” leads to Sensitive Data Exposure_CVE-2026-52783

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/Sh...

opf openproject < 17.3.3 CVE
HIGH 7.5 CVE-2026-47193

OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks_CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historica...

opf openproject < 17.3.3 CVE
HIGH 7.7 CVE-2026-55189

RustFS: FTP frontend skips IAM authorization on object reads_CVE-2026-55189

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read ...

rustfs rustfs >= 1.0.0-alpha.1, <= 1.0.0-beta.8 CVE