Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 BD307E81-25CC-

Exploit for OS Command Injection in Tp-Link Tl-Wr802N_Firmware_BD307E81-25CC-59FA-B6D0-3D9C36E25857

CVE-2026-3227: TP-Link Router OS Command Injection For more Information see https://vulners.com/cve/CVE-2026-3227 A persistent, authenticated OS Co...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 A8E5D800-F075-

Exploit for Path Traversal in Gogs_A8E5D800-F075-509D-A604-E092148C4F7B

CVE-2025-8110 Gogs Repository Symlink Remote Code Execution Made by oguiii --- Table of Contents - Overview - Features - Requirements - Installatio...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2025-61028

CVE-2025-61028_CVE-2025-61028

An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-60474

CVE-2025-60474_CVE-2025-60474

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Den...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-60467

CVE-2025-60467_CVE-2025-60467

A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attac...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-9702

InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking_CVE-2026-9702

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce o...

Unknown InPost PL CVE
HIGH 8.8 CVE-2026-5305

Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Stored XSS_CVE-2026-5305

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email repla...

Unknown Email Address Encoder CVE
HIGH 7.5 CVE-2026-33612

ZoneToCache can poison the cache_CVE-2026-33612

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

PowerDNS Recursor 5.2.0 CVE
HIGH 8.7 CVE-2026-56122

Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths_CVE-2026-56122

Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sen...

rickknowles Winstone Servlet Container 0.9.10 CVE
HIGH 7.1 CVE-2026-56071

WordPress Forminator plugin <= 1.53.1 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56071

Unauthenticated Cross Site Scripting (XSS) in Forminator

WPMU DEV Forminator n/a CVE