Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2026-25879

Langroid has Prompt to SQL Injection, Leading to RCE_CVE-2026-25879

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an L...

langroid langroid < 0.63.0 CVE
CRITICAL 10 CVE-2026-40965

CVE-2026-40965_CVE-2026-40965

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Ellipt...

Cloud Foundry Foundation uaa_release 76.12.0 CVE
CRITICAL 9.1 CVE-2026-9092

CVE-2026-9092_CVE-2026-9092

Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserB...

Casdoor Casdoor 2.362.0 CVE
CRITICAL 9 CVE-2026-9319

IBM WebSphere Application Server is affected by a remote code execution vulnerability_CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS ...

IBM WebSphere Application Server 9.0 CVE
CRITICAL 9 CVE-2026-9311

IBM WebSphere Application Server is affected by remote code execution_CVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

IBM WebSphere Application Server 9.0 CVE
CRITICAL 9.1 CVE-2026-8644

IBM WebSphere Application Server is affected by an identity spoofing vulnerability_CVE-2026-8644

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

IBM WebSphere Application Server 9.0 CVE
CRITICAL 9.2 CVE-2026-49121

AI Tensor Engine for ROCm (AITER) 0.1.14 Unauthenticated RCE via MessageQueue.recv() Pickle Deserialization_CVE-2026-49121

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() functio...

ROCm aiter 0.1.14 CVE
CRITICAL 10 CVE-2026-0072

CVE-2026-0072_CVE-2026-0072

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to loca...

Google Android XR 14 CVE
CRITICAL 10 PACKETSTORM:222403

📄 Mennekes Amtron Series and Smart-T PnC 5.22.3 Authentication Bypass / Privilege Escalation_PACKETSTORM:222403

Mennekes Amtron Series and Smart-T PnC version 5.22.3 suffers from authentication bypass and privilege escalation vulnerabilities...

N/A N/A PACKETSTORM
CRITICAL 9.8 EDB-ID:52608

Drupal Core 10.5.5 – Error-Based SQL Injection_EDB-ID:52608

Exploit Title: Drupal Core 10.5.5 - Error-Based SQL Injection Google Dork: N/A Date: 2026-05-31 Exploit Author: cardosource Vendor Homepage: https:...

N/A N/A EXPLOITDB