Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-54224

Denial of Service in UBB.threads_CVE-2026-54224

UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many regis...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54223

Remote Code Execution via arbitrary file read and write in UBB.threads_CVE-2026-54223

UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s se...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54222

Blind SQL Injection in UBB.threads_CVE-2026-54222

UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying da...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54220

Cross-Site Request Forgery in UBB.threads_CVE-2026-54220

uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authen...

UBB Systems UBB.threads CVE
HIGH 8.5 CVE-2026-56012

WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability_CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows ...

David Lingren Media LIbrary Assistant n/a CVE
HIGH 7.1 CVE-2026-50141

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation_CVE-2026-50141

Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any auth...

woodpecker-ci woodpecker >= 3.0.0, < 3.14.1 CVE
HIGH 8.1 CVE-2026-42488

x86: mismatched mapcache metadata_CVE-2026-42488

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between ...

Xen Xen consult Xen advisory XSA-494 CVE
HIGH 7.9 CVE-2026-42487

x86 HVM I/O port list traversal_CVE-2026-42487

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_...

Xen Xen consult Xen advisory XSA-491 CVE
HIGH 8.4 CVE-2026-46580

CVE-2026-46580_CVE-2026-46580

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could ...

Eclipse Foundation Eclipse Theia CVE
HIGH 8.4 CVE-2026-44691

CVE-2026-44691_CVE-2026-44691

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be execute...

Eclipse Foundation Eclipse Theia CVE