Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2026-11972

tarfile opened in streaming mode mishandles EOF_CVE-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, meaning an archi...

Python Software Foundation CPython CVE
HIGH 8.7 F3832E4F-76F3-

Exploit for CVE-2026-11834_F3832E4F-76F3-50B7-92A3-92EB0B582EB1

CVE-2026-11834 PoC TP-Link DHCP Option 66 Unauthenticated RCE CVE-2026-11834 Overview A command injection vulnerability CWE-78 in the DHCP Option 6...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 C3D90422-8858-

Exploit for Use After Free in Microsoft_C3D90422-8858-5EAC-A8E5-588AF315EA86

CVE-2026-42978 PoC & Research Windows Push Notifications Use-After-Free Race condition in Windows Push Notifications service WpnService that runs a...

N/A N/A GITHUBEXPLOIT
HIGH 8.2 MSF:AUXILIARY-SCANNER-

Audiobookshelf Unauthenticated API Authentication Bypass Scanner_MSF:AUXILIARY-SCANNER-HTTP-AUDIOBOOKSHELF_AUTH_BYPASS-

This module detects Audiobookshelf servers affected by CVE-2025-25205, an unauthenticated authentication bypass. Affected versions 2.17.0 through 2...

N/A N/A METASPLOIT
HIGH 7.7 CVE-2026-54322

Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org’s roles_CVE-2026-54322

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organizatio...

daytonaio daytona < 0.185.0 CVE
HIGH 7 CVE-2026-54321

Daytona: Public sandbox previews remain accessible for up to one hour after being made private_CVE-2026-54321

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox pre...

daytonaio daytona >= 0.101.0, < 0.184.0 CVE
HIGH 8.4 CVE-2026-54320

Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified email_CVE-2026-54320

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitati...

daytonaio daytona < 0.184.0 CVE
HIGH 8.6 CVE-2026-53755

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check_CVE-2026-53755

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the craw...

unclecode crawl4ai < 0.8.9 CVE
HIGH 7.5 CVE-2026-53754

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)_CVE-2026-53754

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / vali...

unclecode crawl4ai < 0.8.8 CVE
HIGH 7.8 CVE-2026-54555

rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separators_CVE-2026-54555

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively spli...

rtk-ai rtk < 0.42.2 CVE