Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-50879

CVE-2026-50879_CVE-2026-50879

An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted PO...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50878

CVE-2026-50878_CVE-2026-50878

An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted req...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50877

CVE-2026-50877_CVE-2026-50877

An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.

n/a n/a n/a CVE
HIGH 8.1 18C8CA41-20FF-

Exploit for CVE-2026-32488_18C8CA41-20FF-5A47-9496-2296CF723F12

CVE-2026-32488 UpdraftPlus Auto-Exploit & Mass Scanner Authorized Use Only — This tool is provided for authorized penetration testing, security res...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2026-12225

syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent_CVE-2026-12225

syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker wi...

syracom AG Secure Login (2FA) for Jira 3.4.0.0 CVE
HIGH 8.6 CVE-2026-10829

CVE-2026-10829_CVE-2026-10829

A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stem...

Moxa NPort W2150A-W4/W2250A-W4 Series 1.0 CVE
HIGH 8.1 CVE-2026-8442

WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter_CVE-2026-8442

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missi...

https://wpreviewslider.com/ WP Review Slider Pro CVE
HIGH 7.5 CVE-2026-8176

LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset_CVE-2026-8176

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ...

latepoint LatePoint – Calendar Booking Plugin for Appointments and Events CVE
HIGH 8.8 CVE-2026-5416

Command Injection via name parameter_CVE-2026-5416

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vu...

TURCK TBEN-LL-SE-M2 0.0.0 CVE
HIGH 7.1 CVE-2026-54198

WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-54198

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant

David Lingren Media LIbrary Assistant n/a CVE