Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2025-71322

PickleScan – Unsafe Globals Check Bypass via pty.spawn Function_CVE-2025-71322

PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypass security checks. Maliciou...

PickleScan PickleScan CVE
HIGH 8.6 PACKETSTORM:223698

📄 Discuz! X5.0 Local File Inclusion_PACKETSTORM:223698

This is a Metasploit auxiliary module targeting a local file inclusion vulnerability in Discuz! X5.0...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:223682

📄 Discuz! X5.0 Chained Remote Code Execution_PACKETSTORM:223682

This Metasploit module uses race condition and local file inclusion vulnerabilities in Discuz! X5.0 in order to achieve remote code execution...

N/A N/A PACKETSTORM
HIGH 7.5 5084DB54-3051-

Exploit for CVE-2026-49083_5084DB54-3051-5625-ADF2-00307974C4D8

CVE-2026-49083 CVE-2026-49083 LatePoint Calendar Booking Plugin Privilege Escalation Exploit 🎲🎲🎲...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2025-66391

CVE-2025-66391_CVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-54810

WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability_CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

Nexi Payments Nexi XPay n/a CVE
HIGH 8.1 CVE-2026-54415

Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover_CVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authentica...

Azuriom Azuriom CMS CVE
HIGH 7.4 CVE-2026-49502

CVE-2026-49502_CVE-2026-49502

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent netwo...

Dell PowerFlex CVE
HIGH 8.1 CVE-2026-42530

NGINX Open-Source ngx_http_v3_module vulnerability_CVE-2026-42530

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remot...

F5 NGINX Open Source 1.31.0 CVE
HIGH 8.1 CVE-2026-42055

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability_CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists w...

F5 NGINX Open Source 1.13.10 CVE