Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-40961

Apache Airflow: Open Redirect Bypass Vulnerability_CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redir...

Apache Software Foundation Apache Airflow 3.0.0 CVE
HIGH 7.5 CVE-2026-37235

CVE-2026-37235_CVE-2026-37235

FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function vali...

n/a n/a n/a CVE
HIGH 7.8 CVE-2026-0088

CVE-2026-0088_CVE-2026-0088

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. Th...

Google Android 16-qpr2 CVE
HIGH 7.8 CVE-2026-40715

CVE-2026-40715_CVE-2026-40715

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local acc...

Dell ThinOS 10 CVE
HIGH 7.8 CVE-2026-24237

CVE-2026-24237_CVE-2026-24237

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vu...

NVIDIA NVTabular 0.0 to 5dd11f4 CVE
HIGH 7.8 CVE-2026-24221

CVE-2026-24221_CVE-2026-24221

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vu...

NVIDIA NVTabular 0.0 to 5dd11f4 CVE
HIGH 7.1 CVE-2026-1871

Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200_CVE-2026-1871

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header...

TP-Link Systems Inc. Tapo C200 v5 CVE
HIGH 7.5 C21DAAE1-B419-

Exploit for CVE-2026-45332_C21DAAE1-B419-5788-B35E-CE7E357E7438

CVE-2026-45332 — Broken Access Control in Automad CMS Proof of concept for CVE-2026-45332, a Broken Access Control vulnerability in Automad CMS tha...

N/A N/A GITHUBEXPLOIT
HIGH 10 11E67395-5053-

Exploit for OS Command Injection in Gnu Bash_11E67395-5053-59B0-976E-309242811528

HackTheBox: Shocker Writeup A structured and professional walkthrough showcasing the identification and manual exploitation of the critical Shellsh...

N/A N/A GITHUBEXPLOIT
HIGH 7.3 CVE-2026-45360

Apache Airflow: Arbitrary import in custom deadline-reference deserialization_CVE-2026-45360

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary cl...

Apache Software Foundation Apache Airflow CVE