Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 0C78AA8B-8510-

Exploit for External Control of File Name or Path in Microsoft_0C78AA8B-8510-5DE4-BDFD-0E73FE0B5C98

CVE-2025-24071: NTLM Hash Leak via .library-ms File Metasploit Module This repository contains a Metasploit module to exploit CVE-2025-24071, a vul...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.1 C90CEE4A-6BE7-

Exploit for Infinite Loop in Pypdf_Project Pypdf_C90CEE4A-6BE7-53CA-8B7A-A5DA2843514F

CVE-2026-24688 - pypdf - Circular Reference DoS Vulnerability This repo includes proof of concept code for triggering CVE-2026-24688. Summary Criti...

N/A N/A GITHUBEXPLOIT
MEDIUM 4.6 CVE-2026-56393

Craft CMS – Multiple Stored Cross-Site Scripting in Settings Names and Field Options_CVE-2026-56393

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities w...

craftcms cms 5.0.0-RC1 CVE
MEDIUM 5.3 CVE-2026-56385

Craft CMS – Authorization Bypass in assets/preview-file Endpoint_CVE-2026-56385

Craft CMS versions >= 5.0.0-RC1, = 4.0.0-RC1,

craftcms cms 5.0.0-RC1 CVE
MEDIUM 5.3 CVE-2026-56384

Craft CMS – Missing Authorization in assets/preview-thumb Endpoint_CVE-2026-56384

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a ta...

craftcms cms 4.0.0-RC1 CVE
MEDIUM 4.6 CVE-2026-56383

Craft CMS – Stored XSS in Table Field via Row Heading Column Type_CVE-2026-56383

Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. ...

craftcms cms 4.5.0-beta.1 CVE
MEDIUM 4.6 CVE-2026-56381

Craft CMS – Stored XSS via User Group Name in User Permissions Page_CVE-2026-56381

Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rende...

craftcms cms 5.0.0-RC1 CVE
MEDIUM 6.3 CVE-2026-56378

ImageMagick – Heap Out-of-Bounds Read in PCD Decoder_CVE-2026-56378

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file c...

ImageMagick ImageMagick CVE
MEDIUM 6.3 CVE-2026-56367

ImageMagick – Heap Out-of-Bounds Read in PSB RLE Decoding_CVE-2026-56367

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in cod...

ImageMagick ImageMagick CVE
MEDIUM 6.9 CVE-2026-56316

Cap-go – Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*_CVE-2026-56316

Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated ...

Cap-go capgo CVE