Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-42089

yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation_CVE-2026-42089

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 ...

yeoman environment >= 2.9.0, < 6.0.1 CVE
HIGH 7.8 CVE-2026-24228

CVE-2026-24228_CVE-2026-24228

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of thi...

NVIDIA NeMo Framework Versions 0.0 to 2.7.2 CVE
HIGH 7.8 CVE-2026-24155

CVE-2026-24155_CVE-2026-24155

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code exec...

NVIDIA NeMo Framework Versions 0.0 to 2.7.2 CVE
HIGH 8.6 CVE-2026-10649

Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression_CVE-2026-10649

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2025-71261

Harvester’s SUSE Virtualization Registration Client Vulnerable to MITM and DOS_CVE-2025-71261

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the ...

SUSE Harvester CVE
HIGH 8.8 PACKETSTORM:223514

📄 Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service_PACKETSTORM:223514

This script is a multi-mode security tool that triggers a denial of service against Apache HTTP Server version 2.4.66 related to a double-free cond...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:223502

📄 HotelDruid 3.0.x Credential Exposure / Stress Tester_PACKETSTORM:223502

Proof of concept denial of service and credential disclosure exploit for HotelDruid versions 3.0.0 and 3.0.7...

N/A N/A PACKETSTORM
HIGH 7.5 9349E804-9874-

Exploit for Improper Access Control in Vitejs Vite_9349E804-9874-5D40-A4D5-7FAE1725C5AA

CVE-2025-30208 Using a special raw import query string on a vite dev server, a attacker can read arbitrary files Summary of the CVE Vite dev server...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 A34D1BC1-7B69-

Exploit for Code Injection in Apache Nifi_A34D1BC1-7B69-5F1F-A6EF-D572FB2CA379

CVE-2023-34468 PoC for Apache NiFi Educational proof-of-concept PoC for CVE-2023-34468 affecting Apache NiFi versions prior to 1.22.0. This reposit...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-50885

CVE-2026-50885_CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints...

n/a n/a n/a CVE