Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2025-71261

Harvester’s SUSE Virtualization Registration Client Vulnerable to MITM and DOS_CVE-2025-71261

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the ...

SUSE Harvester CVE
HIGH 8.8 PACKETSTORM:223514

📄 Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service_PACKETSTORM:223514

This script is a multi-mode security tool that triggers a denial of service against Apache HTTP Server version 2.4.66 related to a double-free cond...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:223502

📄 HotelDruid 3.0.x Credential Exposure / Stress Tester_PACKETSTORM:223502

Proof of concept denial of service and credential disclosure exploit for HotelDruid versions 3.0.0 and 3.0.7...

N/A N/A PACKETSTORM
HIGH 7.5 9349E804-9874-

Exploit for Improper Access Control in Vitejs Vite_9349E804-9874-5D40-A4D5-7FAE1725C5AA

CVE-2025-30208 Using a special raw import query string on a vite dev server, a attacker can read arbitrary files Summary of the CVE Vite dev server...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 A34D1BC1-7B69-

Exploit for Code Injection in Apache Nifi_A34D1BC1-7B69-5F1F-A6EF-D572FB2CA379

CVE-2023-34468 PoC for Apache NiFi Educational proof-of-concept PoC for CVE-2023-34468 affecting Apache NiFi versions prior to 1.22.0. This reposit...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-50885

CVE-2026-50885_CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50882

CVE-2026-50882_CVE-2026-50882

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50870

CVE-2026-50870_CVE-2026-50870

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive infor...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-39007

CVE-2026-39007_CVE-2026-39007

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.

n/a n/a n/a CVE
HIGH 8.8 CVE-2026-36670

CVE-2026-36670_CVE-2026-36670

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows...

OpenSIPS opensips-cp < 9.3.3 CVE