Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-45171

Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation_CVE-2026-45171

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14...

CyberArk Software, a Palo Alto Networks Company Privileged Session Manager, Vault 14.0 CVE
CRITICAL 9.8 CVE-2026-45060

ClipBucket: Blind SQL Injection in progress_video.php_CVE-2026-45060

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to bli...

MacWarrior clipbucket-v5 < 5.5.3 - #129 CVE
CRITICAL 9.8 CVE-2026-42846

ClipBucket: Remote Play URL Command Injection_CVE-2026-42846

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated us...

MacWarrior clipbucket-v5 < 5.5.3 - #140 CVE
CRITICAL 9.1 CVE-2026-50638

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections_CVE-2026-50638

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions suc...

PEVANS Metrics::Any::Adapter::DogStatsd CVE
CRITICAL 9.2 CVE-2026-49973

Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings_CVE-2026-49973

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initi...

nesquena hermes-webui CVE
CRITICAL 9 CVE-2026-41005

UAA accepts SAML Encrypted Assertions authentication bypass_CVE-2026-41005

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity...

Cloud Foundry UAA 2.0.0 CVE
CRITICAL 9.8 THN:752B90FA610...

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities_THN:752B90FA61064ECC5D562EA512CCEC15

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBpNcbfulhruio1VSh8OPKOjdx3gvP-Chg8OjSm7LZeVK2GaVR-osKeoQjO9e1_56Dtedmlisu76lYc70Wv5...

N/A N/A THN
CRITICAL 10 CVE-2026-49261

MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`_CVE-2026-49261

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11...

MariaDB server >= 10.6.1, < 10.6.27 CVE
CRITICAL 9.5 CVE-2026-47174

Duck Site: Untrusted pull request code can trigger privileged production deployment_CVE-2026-47174

In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pu...

duck-organization duck-site < 1.0.1 CVE
CRITICAL 9.5 CVE-2026-47172

Quest Bot: Untrusted pull request code can be built and deployed by privileged `workflow_run` deployment._CVE-2026-47172

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository has a privileged ...

duck-organization quest-bot < 1.0.3 CVE