Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.7 CVE-2026-34592

Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure_CVE-2026-34592

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and pro...

coollabsio coolify < 4.0.0-beta.471 CVE
HIGH 7.5 CVE-2026-8023

Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read_CVE-2026-8023

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYS...

zephyrproject zephyr 4.0.0 CVE
HIGH 8.1 CVE-2026-7656

Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack_CVE-2026-7656

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expr...

zephyrproject zephyr 1.14.0 CVE
HIGH 7.8 B815CF61-2540-

Exploit for Out-of-bounds Write in Netapp Bootstrap_Os_B815CF61-2540-5E4D-AAB8-F3976D79DF34

Security Notice: This repository contains working exploit code for educational and research purposes. Use responsibly and only on systems you own o...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 CVE-2026-49416

Integer overflow in vt(4) CONS_HISTORY ioctl_CVE-2026-49416

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size...

FreeBSD FreeBSD 15.0-RELEASE CVE
HIGH 7.5 CVE-2026-36848

CVE-2026-36848_CVE-2026-36848

Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

n/a n/a n/a CVE
HIGH 8.7 CVE-2026-58000

luci-proto-openvpn – Command Injection via cl_meta Parameter in generateKey_CVE-2026-58000

luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_...

openwrt luci 0.11.1 CVE
HIGH 7.7 CVE-2026-57999

luci-app-tailscale-community – Command Injection via tailscale.do_login RPC_CVE-2026-57999

luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to exe...

openwrt luci CVE
HIGH 8.2 CVE-2026-53426

Atom-table exhaustion denial-of-service via JSON parse_document in MDEx_CVE-2026-53426

Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a ...

leandrocp mdex 0.4.3 CVE
HIGH 7.8 CVE-2026-57919

CVE-2026-57919_CVE-2026-57919

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ...

n/a n/a n/a CVE