Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-7574

Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use_CVE-2026-7574

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) val...

Anthropic Claude Desktop Cowork 1.1348.0 CVE
HIGH 7.2 CVE-2026-5818

MCU Firmware Update Authentication Bypass on Caliptra Core_CVE-2026-5818

Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Cor...

Caliptra Core Runtime Firmware 2.0.0 CVE
HIGH 8.8 CVE-2026-54639

Style Dictionary – Prototype Pollution in convertTokenData utility function_CVE-2026-54639

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to...

style-dictionary style-dictionary >= 4.3.0, < 5.4.4 CVE
HIGH 8.1 CVE-2026-39253

CVE-2026-39253_CVE-2026-39253

An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Se...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-54513

jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)_CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21....

FasterXML jackson-databind >= 2.10.0, < 2.18.8 CVE
HIGH 8.1 CVE-2026-54512

jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation_CVE-2026-54512

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21....

FasterXML jackson-databind >= 2.10.0, < 2.18.8 CVE
HIGH 8.8 CVE-2026-41862

CVE-2026-41862_CVE-2026-41862

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enfo...

Spring Spring Statemachine 4.0.0 CVE
HIGH 8.4 CVE-2026-56785

FlatPress – Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields_CVE-2026-56785

FlatPress versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and ...

FlatPress FlatPress CVE
HIGH 8.2 CVE-2026-11972

tarfile opened in streaming mode mishandles EOF_CVE-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, meaning an archi...

Python Software Foundation CPython CVE
HIGH 8.7 F3832E4F-76F3-

Exploit for CVE-2026-11834_F3832E4F-76F3-50B7-92A3-92EB0B582EB1

CVE-2026-11834 PoC TP-Link DHCP Option 66 Unauthenticated RCE CVE-2026-11834 Overview A command injection vulnerability CWE-78 in the DHCP Option 6...

N/A N/A GITHUBEXPLOIT