Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-41053

Over-inclusive team membership expansion in GitHub App authentication provider for Rancher_CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal acces...

SUSE Rancher 2.14.0 CVE
HIGH 8.7 CVE-2026-14161

Advantech|Hospital Queuing Management – Sensitive Data Exposure_CVE-2026-14161

Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access...

Advantech Hospital Queuing Management CVE
HIGH 7.8 1A5AFF91-769E-

Exploit for CVE-2026-46331_1A5AFF91-769E-5D60-9467-A406F3FD6FD5

CVE-2026-46331 - "pedit COW" Vulnerability Assessment & Mitigation Guide Este repositorio contiene herramientas administrativas básicas para verifi...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 5CCC4D1D-CB00-

Exploit for CVE-2026-4020_5CCC4D1D-CB00-54EE-88B5-E103837659E0

No description provided...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 B1A34079-E8F9-

Exploit for CVE-2026-31694_B1A34079-E8F9-5174-9297-C9EF365CAE42

FUSE readdir cache out-of-bounds write PoC Local proof of concept for a missing bounds check in fs/fuse/readdir.c:fuseadddirenttocache. A FUSE serv...

N/A N/A GITHUBEXPLOIT
HIGH 7.2 CVE-2026-8141

Ajax Load More – Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field_CVE-2026-8141

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all...

Connekt Media Ajax Load More - Filters CVE
HIGH 7.7 CVE-2026-13149

CVE-2026-13149_CVE-2026-13149

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...

juliangruber brace-expansion CVE
HIGH 7 CVE-2026-10763

CVE-2026-10763_CVE-2026-10763

PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.

Hitachi Energy PROMOD V 1.0.0 CVE
HIGH 7.3 201DCF14-1AAA-

wp-exploit_201DCF14-1AAA-5BD3-BC87-3A8A7BBBCF54

🚀 FULLCVE-2026-6433 Advanced WordPress Exploitation Framework --- 📖 Overview FULLCVE-2026-6433 is a modular, high-performance toolkit designed to...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 54DE62F9-A0CE-

Exploit for Use After Free in Google Android_54DE62F9-A0CE-554B-A9D1-FCB05FE5250D

Root Sonim XP3800 Root access for the Sonim XP3800 XP3plus. Two paths are available — choose whichever fits your situation. Two paths to root Optio...

N/A N/A GITHUBEXPLOIT