Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-48703

Warp: Command Injection via Warp code search tool arguments_CVE-2026-48703

Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution...

warpdotdev warp >= 0.2025.04.09.08.11.stable_00, < 0.2026.05.13.09.15.stable_01 CVE
HIGH 7.5 CVE-2026-44020

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend_CVE-2026-44020

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2....

docling-project docling >= 2.13.0, < 2.74.0 CVE
HIGH 7.5 CVE-2026-44017

Docling: Unsafe Zip Extraction in EasyOCR Model Download_CVE-2026-44017

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the...

docling-project docling < 2.91.0 CVE
HIGH 8.2 CVE-2026-44016

Docling: Unsafe Playwright-based HTML Rendering_CVE-2026-44016

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82...

docling-project docling >= 2.82.0, < 2.91.0 CVE
HIGH 7.5 PACKETSTORM:224227

📄 HTTP.sys HTTP/2 Denial of Service_PACKETSTORM:224227

This advisory provides simple proof of concept details to trigger the HTTP/2 denial of service condition related to malformed Accept-Encoding heade...

N/A N/A PACKETSTORM
HIGH 10 DC8CF54B-5E0D-

pentest-metasploit_DC8CF54B-5E0D-55F4-B5C1-920406A0FF9F

Penetration Testing with Metasploit A structured penetration testing automation framework developed by Aadarsh Bonthula as part of a cybersecurity ...

N/A N/A GITHUBEXPLOIT
HIGH 7.6 CVE-2025-71361

picklescan – Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip_CVE-2025-71361

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attacke...

picklescan picklescan CVE
HIGH 7.1 CVE-2026-57303

CVE-2026-57303_CVE-2026-57303

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to ...

Jenkins Project Jenkins Assembla Plugin CVE
HIGH 8.8 CVE-2026-57301

CVE-2026-57301_CVE-2026-57301

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers w...

Jenkins Project Jenkins OWASP ZAP Plugin 1.0.7 CVE
HIGH 8.8 CVE-2026-57296

CVE-2026-57296_CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the e...

Jenkins Project Jenkins External Workspace Manager Plugin 1.3.2 CVE