Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 F9427710-4336-

Exploit for Use After Free in Linux Linux_Kernel_F9427710-4336-50DA-9AC4-7D23886787E5

CVE-2024-1086 Root Cause & Exploitation Target kernels: Linux 6.8 netfilter nftables Novel angle: Logic confusion in nftverdictinit causes refcount...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 B5DED594-DA46-

fragnesia-python-exploit_B5DED594-DA46-566B-B4FE-60D7564C12EF

Fragnesia CVE-2026-46300 - Python Exploit Linux Kernel Local Privilege Escalation via ESP-in-TCP Page Cache Corruption --- ⚠️ WARNING – READ BEFORE...

N/A N/A GITHUBEXPLOIT
HIGH 7.3 FA08775C-6E51-

Exploit for Out-of-bounds Read in Apple Ipados_FA08775C-6E51-5C9C-9DFC-21E6FEE31DC0

CVE-2026-43655: AppleM2ScalerCSCDriver shared scheduler use-after-free Public technical disclosure for CVE-2026-43655, an AppleM2ScalerCSCDriver us...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 8368E8ED-03A4-

sslpwn_8368E8ED-03A4-58E7-BF10-DEA012DCAC12

sslpwn sslpwn is a security research tool for testing web applications against eight well-known SSL/TLS vulnerabilities: - BEAST CVE-2011-3389 - TL...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2026-12806

Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow_CVE-2026-12806

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSur...

Edimax BR-6478AC V2 1.23 CVE
HIGH 10 48CB0B24-8B26-

create-poc-template-skills_48CB0B24-8B26-5239-AC5C-FDFA59633797

create-poc-template 中文 A skill for AI coding agents, containing the full development reference for Pocsuite3 and Nuclei — so agents stop hallucin...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2026-56396

phpMyFAQ – Privilege Escalation via Missing Authorization in editUser() and updateUserRights()_CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated admini...

phpMyFAQ phpMyFAQ CVE
HIGH 7.1 CVE-2026-56394

Craft CMS – Authenticated Path Traversal in assets/icon Extension Parameter_CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not va...

craftcms cms 4.0.0-RC1 CVE
HIGH 8.6 CVE-2026-56382

Craft CMS – Remote Code Execution via Missing Config Sanitization in FieldsController_CVE-2026-56382

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and

craftcms cms 5.5.0 CVE
HIGH 8.7 CVE-2026-56253

Capgo – Unauthenticated Organization Member Email Disclosure via get_org_members RPC_CVE-2026-56253

Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated atta...

Capgo Capgo CVE