Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2026-55746

Cotonti stored XSS via PFS folder title_CVE-2026-55746

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder tit...

Cotonti Cotonti 1.0.0 CVE
HIGH 8.1 CVE-2026-55744

Cotonti CSRF in PFS allows forced arbitrary file upload_CVE-2026-55744

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pf...

Cotonti Cotonti 1.0.0 CVE
HIGH 8.8 CVE-2026-55741

Cotonti CSRF in admin.config.php allows unauthorized configuration changes_CVE-2026-55741

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/a...

Cotonti Cotonti 1.0.0 CVE
HIGH 7.2 CVE-2026-11395

CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host_CVE-2026-11395

The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_t...

mariovalney CF7 to Webhook CVE
HIGH 7.1 CVE-2026-8811

Path traversal in PDF generation module_CVE-2026-8811

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to cr...

SEPPmail AG Secure Email Gateway CVE
HIGH 8.8 CVE-2026-8461

Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder_CVE-2026-8461

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some ca...

FFmpeg FFmpeg CVE
HIGH 8.6 CVE-2026-40456

OS Command Injection in LMS_CVE-2026-40456

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to th...

LMS LMS CVE
HIGH 8.6 CVE-2026-40455

SQL Injection in LMS_CVE-2026-40455

An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient s...

LMS LMS CVE
HIGH 7.3 CVE-2026-11958

Local privilege escalation in ANSSI’s DFIR-ORC_CVE-2026-11958

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior...

ANSSI DFIR-ORC CVE
HIGH 8.6 CVE-2026-11719

CVE-2026-11719_CVE-2026-11719

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol hand...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.3.0 CVE