Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-8379

Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download_CVE-2026-8379

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing una...

Unknown Frontend File Manager Plugin CVE
HIGH 7.4 CVE-2026-56815

CVE-2026-56815_CVE-2026-56815

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

rasta-mouse pwnlift CVE
HIGH 8.7 CVE-2026-35018

NetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection_CVE-2026-35018

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated...

NetComm Wireless Pty Ltd NF20MESH R6B031 and earlier CVE
HIGH 7.1 CVE-2026-56695

OpenHarness – Cross-Session Disclosure via /resume and /summary Commands_CVE-2026-56695

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and lo...

HKUDS OpenHarness CVE
HIGH 7.1 CVE-2026-56402

NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler_CVE-2026-56402

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role au...

nanocoai nanoclaw CVE
HIGH 7.2 CVE-2026-54312

n8n: Microsoft SQL Node Prototype Pollution_CVE-2026-54312

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achi...

n8n-io n8n < 2.24.0 CVE
HIGH 8.8 CVE-2026-54309

n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions_CVE-2026-54309

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoi...

n8n-io n8n >= 2.26.0, < 2.26.2 CVE
HIGH 7.1 CVE-2025-62180

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs._CVE-2025-62180

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain...

Pegasystems Pega Infinity 8.3.0 CVE
HIGH 7.1 CVE-2026-8172

Simple Basic Contact Form <= 20250114 - Reflected XSS_CVE-2026-8172

The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form outp...

Unknown Simple Basic Contact Form CVE
HIGH 8.8 CVE-2026-8163

Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter_CVE-2026-8163

The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, lead...

Unknown Infility Global CVE