Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-48681

CVE-2026-48681_CVE-2026-48681

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

OpenStack Ironic 17.0.0 CVE
MEDIUM 4.9 CVE-2026-44917

CVE-2026-44917_CVE-2026-44917

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_temp...

OpenStack Ironic 17.0.0 CVE
MEDIUM 6.5 CVE-2026-8653

MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter_CVE-2026-8653

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and inc...

StylemixThemes MasterStudy LMS Pro CVE
MEDIUM 6.5 CVE-2026-41858

CVE-2026-41858_CVE-2026-41858

Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network a...

Cloud Foundry Foundation windows-utilities-release CVE
MEDIUM 6.9 CVE-2026-10597

ITPison|OMICARD EDM – Insecure Direct Object Reference_CVE-2026-10597

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specif...

ITPison OMICARD EDM 5.8 CVE
MEDIUM 4.3 80DB2B91-72D2-

Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft_80DB2B91-72D2-5072-AE04-E22E0DB8B481

CVE-2026-33829 - Security Vulnerability Quick Usage bash python3 exploit.py -t "C:\\Path\\To\\Target" -o demo.zip --data-file payload.exe Exploitat...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.9 CVE-2026-36610

CVE-2026-36610_CVE-2026-36610

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware con...

n/a n/a n/a CVE
MEDIUM 5.3 CVE-2026-22055

CVE-2026-22055_CVE-2026-22055

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauth...

NETAPP Active IQ OneCollect 2.7.3 CVE
MEDIUM 5.3 CVE-2026-22054

CVE-2026-22054_CVE-2026-22054

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform un...

NETAPP Active IQ Config Advisor 6.7.3 CVE
MEDIUM 6.9 CVE-2026-10771

crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery_CVE-2026-10771

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zb...

crmeb crmeb_java 1.4 CVE