Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-11844

IEI Integration Corp|iVEC-IEI Virtualization Edge Computer – Arbitrary File Read_CVE-2026-11844

The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote att...

IEI Integration Corp iVEC TANK-XM811 CVE
MEDIUM 5.3 CVE-2026-12058

CVE-2026-12058_CVE-2026-12058

The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.

vivo PcSuite Versions below 6.2.0 CVE
MEDIUM 6.9 CVE-2026-12060

Hepta Platforms|Heptabase – Exposed Dangerous_CVE-2026-12060

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to lever...

Hepta Platforms Heptabase CVE
MEDIUM 6.3 CVE-2026-20746

PingDirectory copying of virtual attributes leads to memory exhaustion_CVE-2026-20746

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent...

Ping Identity PingDirectory 9.3.0.0 CVE
MEDIUM 4.3 8E7576F6-458D-

Exploit for CVE-2026-46645_8E7576F6-458D-5824-819E-FC7C2BCB6824

CVE-2026-46645 - SQLAdmin ajaxlookup Authorization Bypass Executive Summary This repository contains a local Docker lab for reproducing CVE-2026-46...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-12033

CVE-2026-12033_CVE-2026-12033

Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain...

Google Chrome 149.0.7827.115 CVE
MEDIUM 5.3 CVE-2026-12025

CVE-2026-12025_CVE-2026-12025

Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re...

Google Chrome 149.0.7827.115 CVE
MEDIUM 5.3 CVE-2026-12015

CVE-2026-12015_CVE-2026-12015

Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain po...

Google Chrome 149.0.7827.115 CVE
MEDIUM 6.4 CVE-2026-9125

The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute_CVE-2026-9125

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] sho...

2winfactor Presto Player CVE
MEDIUM 4.3 CVE-2026-49482

ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite_CVE-2026-49482

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wil...

MacWarrior clipbucket-v5 < 5.5.3 - #141 CVE