Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 82BACCCF-4973-

simplectf_82BACCCF-4973-500F-8B25-5714A0310B69

Simple CTF — TryHackMe Walkthrough Platform: TryHackMe | Difficulty: Easy | CVE: CVE-2019-9053 --- 1. Reconnaissance Port Scan bash nmap -p- --open...

N/A N/A GITHUBEXPLOIT
NONE QUALYSBLOG:0472...

From Operating Model to Product: How We Built the ROC for Detection-Speed Remediation_QUALYSBLOG:04729DC1A0A66FE61A5E92D6718FDCAE

In the first article in this series, we made the case for a prevention-led operating model. This article is about what happened next: the decision ...

N/A N/A QUALYSBLOG
HIGH 7.5 8A0044D6-4E23-

Exploit for CVE-2026-3180_8A0044D6-4E23-5EC1-9A9D-274941997A78

No description provided...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.5 CVE-2026-11322

Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass_CVE-2026-11322

Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlink...

nesquena Hermes WebUI CVE
HIGH 8.6 CVE-2026-10871

Shibby Tomato Web UI rc start_6rd_tunnel os command injection_CVE-2026-10871

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the com...

Shibby Tomato 1.28.0000 CVE
HIGH 7.5 CVE-2026-8888

CVE-2026-8888_CVE-2026-8888

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressio...

Securly Securly Chrome Extension CVE
HIGH 7.5 CVE-2026-8881

CVE-2026-8881_CVE-2026-8881

Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been b...

Securly Securly Chrome Extension CVE
MEDIUM 6.5 CVE-2026-8722

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections_CVE-2026-8722

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes...

TEAM Net::Async::Statsd::Client CVE
CRITICAL 9.8 CVE-2025-67446

CVE-2025-67446_CVE-2025-67446

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cook...

Neterbit NW-431F Router 20241014-IR03 and before CVE
HIGH 7.4 CVE-2026-50292

CVE-2026-50292_CVE-2026-50292

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary roo...

freedesktop libinput CVE