Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-10649

Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression_CVE-2026-10649

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2025-71261

Harvester’s SUSE Virtualization Registration Client Vulnerable to MITM and DOS_CVE-2025-71261

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the ...

SUSE Harvester CVE
HIGH 8.8 PACKETSTORM:223514

📄 Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service_PACKETSTORM:223514

This script is a multi-mode security tool that triggers a denial of service against Apache HTTP Server version 2.4.66 related to a double-free cond...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:223502

📄 HotelDruid 3.0.x Credential Exposure / Stress Tester_PACKETSTORM:223502

Proof of concept denial of service and credential disclosure exploit for HotelDruid versions 3.0.0 and 3.0.7...

N/A N/A PACKETSTORM
HIGH 7.5 9349E804-9874-

Exploit for Improper Access Control in Vitejs Vite_9349E804-9874-5D40-A4D5-7FAE1725C5AA

CVE-2025-30208 Using a special raw import query string on a vite dev server, a attacker can read arbitrary files Summary of the CVE Vite dev server...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 A34D1BC1-7B69-

Exploit for Code Injection in Apache Nifi_A34D1BC1-7B69-5F1F-A6EF-D572FB2CA379

CVE-2023-34468 PoC for Apache NiFi Educational proof-of-concept PoC for CVE-2023-34468 affecting Apache NiFi versions prior to 1.22.0. This reposit...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-50885

CVE-2026-50885_CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50882

CVE-2026-50882_CVE-2026-50882

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-50870

CVE-2026-50870_CVE-2026-50870

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive infor...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-39007

CVE-2026-39007_CVE-2026-39007

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.

n/a n/a n/a CVE