Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-42450

OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser_CVE-2026-42450

OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with ...

AcademySoftwareFoundation OpenColorIO < 2.5.2 CVE
HIGH 8.6 CVE-2026-35025

ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR_CVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory AC...

ProFTPD Project ProFTPD 1.3.9b, 1.3.10rc2 CVE
HIGH 7.8 4BA3261D-2DE6-

Exploit for Incorrect Resource Transfer Between Spheres in Linux Linux_Kernel_4BA3261D-2DE6-5D66-AE25-4FA760E8F87D

rootpacket CVE-2026-31431 A Linux Docker-to-host cryptojacking toolkit captured from live attacks on Kinryū Labs honeypots. It breaks in through an...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 3F58B0E8-968C-

Exploit for Uncontrolled Search Path Element in Checkmk_3F58B0E8-968C-5526-9652-3C321B0F8C30

CVE-2024-0670 - CheckMK Agent MSI Repair Privilege Escalation NanoCorp HTB This repository contains a PowerShell script used to exploit CVE-2024-06...

N/A N/A GITHUBEXPLOIT
HIGH 7.9 CVE-2026-10745

CVE-2026-10745_CVE-2026-10745

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampe...

upKeeper Solutions upKeeper Instant Privilege Access CVE
HIGH 8.8 C5560A1B-5696-

Exploit for CVE-2026-8461_C5560A1B-5696-5AA7-9658-FAC21FF2EC4F

cve-id ⚡ Simple Usage Use this project only in safe and authorized environments such as: - Local virtual machines - Docker containers - Isolated l...

N/A N/A GITHUBEXPLOIT
HIGH 7.2 CVE-2026-9643

WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging_CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versio...

joomunited WP Meta SEO CVE
HIGH 7.5 CVE-2026-9179

WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter_CVE-2026-9179

The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint ...

hancock11 WP Forms Connector CVE
HIGH 7.5 CVE-2026-9178

WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint_CVE-2026-9178

The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers t...

hancock11 WP Forms Connector CVE
HIGH 7.5 CVE-2026-8705

ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection_CVE-2026-8705

The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJ...

clearsale ClearSale Total <= 3.4.2 CVE