Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-49434

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker_CVE-2026-49434

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or...

Apache Software Foundation Apache ActiveMQ Broker CVE
HIGH 8.6 CVE-2026-53691

Remote Code Execution in Redeight CMS_CVE-2026-53691

An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST ...

Redeight Redeight CMS 1.0 CVE
HIGH 8.8 CVE-2026-41053

Over-inclusive team membership expansion in GitHub App authentication provider for Rancher_CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal acces...

SUSE Rancher 2.14.0 CVE
HIGH 8.7 CVE-2026-14161

Advantech|Hospital Queuing Management – Sensitive Data Exposure_CVE-2026-14161

Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access...

Advantech Hospital Queuing Management CVE
HIGH 7.8 1A5AFF91-769E-

Exploit for CVE-2026-46331_1A5AFF91-769E-5D60-9467-A406F3FD6FD5

CVE-2026-46331 - "pedit COW" Vulnerability Assessment & Mitigation Guide Este repositorio contiene herramientas administrativas básicas para verifi...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 5CCC4D1D-CB00-

Exploit for CVE-2026-4020_5CCC4D1D-CB00-54EE-88B5-E103837659E0

No description provided...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 B1A34079-E8F9-

Exploit for CVE-2026-31694_B1A34079-E8F9-5174-9297-C9EF365CAE42

FUSE readdir cache out-of-bounds write PoC Local proof of concept for a missing bounds check in fs/fuse/readdir.c:fuseadddirenttocache. A FUSE serv...

N/A N/A GITHUBEXPLOIT
HIGH 7.2 CVE-2026-8141

Ajax Load More – Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field_CVE-2026-8141

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all...

Connekt Media Ajax Load More - Filters CVE
HIGH 7.7 CVE-2026-13149

CVE-2026-13149_CVE-2026-13149

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...

juliangruber brace-expansion CVE
HIGH 7 CVE-2026-10763

CVE-2026-10763_CVE-2026-10763

PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.

Hitachi Energy PROMOD V 1.0.0 CVE