Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8 CVE-2026-35482

alf.io has an Authenticated RCE via Extension Script Sandbox Escape_CVE-2026-35482

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox es...

alfio-event alf.io < 2.0-M5-2606 CVE
HIGH 7.5 DB840F39-36DA-

System-Exploitation-Compromising_DB840F39-36DA-5995-B990-00BE364FFF5D

đŸ’€ System Exploitation & Compromising CAP 6135 – Cyber Lab | Mara Burnside | UCF | April 2026 --- đŸ“‹ Overview Four penetration testing exercises us...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2026-49443

authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API_CVE-2026-49443

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source...

goauthentik authentik < 2025.12.6 CVE
HIGH 7.1 CVE-2026-49144

BrowserStack Runner 0.9.5 Path Traversal via _default HTTP Handler_CVE-2026-49144

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated...

browserstack browserstack-runner CVE
HIGH 8.7 CVE-2026-49143

BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler_CVE-2026-49143

BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adja...

browserstack browserstack-runner CVE
HIGH 8.5 CVE-2026-47201

authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user_CVE-2026-47201

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnera...

goauthentik authentik < 2025.12.5 CVE
HIGH 8.2 CVE-2026-8936

Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM_CVE-2026-8936

Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted h...

Docker Docker Desktop 4.33.0 CVE
HIGH 7 CVE-2025-15653

Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation_CVE-2025-15653

Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized i...

Dräger Zeus IE CVE
HIGH 7.5 40F8D208-F71D-

Exploit for Path Traversal in Grafana_40F8D208-F71D-51CF-9EFB-BEE62A4FBF14

CVE-2021-43798 - Grafana Arbitrary File Read Python toolkit for authorized testing of CVE-2021-43798, a Grafana path traversal vulnerability that c...

N/A N/A GITHUBEXPLOIT
HIGH 8.2 CVE-2026-10622

CVE-2026-10622_CVE-2026-10622

Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/re...

Collibra Collibra Platform (on-prem) 2026.03 CVE