Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 1C0E4383-9787-

Exploit for CVE-2025-56399_1C0E4383-9787-58E2-A56F-70D9888E6255

Laravel FileManager Unrestricted File Upload CVE-2025-56399 CWE-434: Unrestricted Upload of File with Dangerous Type CVSS Score: 8.5 High --- 📋 De...

N/A N/A GITHUBEXPLOIT
HIGH 7.6 CVE-2026-58056

RustDesk – FileTransfer Session Authorization Scope Bypass_CVE-2026-58056

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer sessi...

RustDesk RustDesk CVE
HIGH 7.2 CVE-2026-58054

MyBB – Privilege Escalation from Limited ACP User Management to Administrator_CVE-2026-58054

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers ...

MyBB MyBB CVE
HIGH 7 CVE-2026-58050

libssh2 – Integer Overflow in publickey Subsystem Attribute Allocation_CVE-2026-58050

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_at...

libssh2 libssh2 CVE
HIGH 8.6 CVE-2026-58049

FFmpeg – Out-of-Bounds Write in RASC Decoder decode_dlta()_CVE-2026-58049

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary...

FFmpeg FFmpeg CVE
HIGH 7.2 52E3EC4D-B3B2-

Exploit for Unrestricted Upload of File with Dangerous Type in Devcode Openstamanager_52E3EC4D-B3B2-5A5A-B602-597C9814297E

OpenSTAManager RCE Exploit CVE-2026-38751 Arbitrary File Upload leading to Remote Code Execution Full-featured proof-of-concept for CVE-2026-38751,...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2026-10643

Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)_CVE-2026-10643

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_co...

zephyrproject zephyr 3.6.0 CVE
HIGH 8.1 CVE-2026-8095

Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion_CVE-2026-8095

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. ...

nmedia Frontend File Manager Plugin CVE
HIGH 8.8 927189F5-055C-

pagecache-lpe-containment-kit_927189F5-055C-5E36-A2C8-0F7428A5314E

Page-Cache LPE Containment Kit Detect, contain, and verify defenses against two Linux page-cache-corruption local privilege escalations — DirtyClon...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 20557F2C-42AE-

Exploit for Incorrect Implementation of Authentication Algorithm in Google Android_20557F2C-42AE-5B1F-BCF0-6B6EBE49885A

CVE-2026-0073 – Android ADBD TLS Authentication Bypass EVPPKEYcmp Type Confusion → Unauthorized ADB Shell Access --- 🔥 Overview There is a critica...

N/A N/A GITHUBEXPLOIT