Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 80DB2B91-72D2-

Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft_80DB2B91-72D2-5072-AE04-E22E0DB8B481

CVE-2026-33829 - Security Vulnerability Quick Usage bash python3 exploit.py -t "C:\\Path\\To\\Target" -o demo.zip --data-file payload.exe Exploitat...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.9 CVE-2026-36610

CVE-2026-36610_CVE-2026-36610

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware con...

n/a n/a n/a CVE
MEDIUM 5.3 CVE-2026-22055

CVE-2026-22055_CVE-2026-22055

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauth...

NETAPP Active IQ OneCollect 2.7.3 CVE
MEDIUM 5.3 CVE-2026-22054

CVE-2026-22054_CVE-2026-22054

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform un...

NETAPP Active IQ Config Advisor 6.7.3 CVE
MEDIUM 6.9 CVE-2026-10771

crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery_CVE-2026-10771

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zb...

crmeb crmeb_java 1.4 CVE
MEDIUM 6.9 CVE-2026-10777

ealpha072 Student-Management-System Administrative Backend config.php improper authentication_CVE-2026-10777

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is som...

ealpha072 Student-Management-System 01451bd7a2f58cdda07bd0b86e3967582e3ecd08 CVE
MEDIUM 4.3 CVE-2026-36618

CVE-2026-36618_CVE-2026-36618

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-36604

CVE-2026-36604_CVE-2026-36604

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external...

n/a n/a n/a CVE
MEDIUM 4.8 CVE-2026-43924

FOSSBilling has an open redirect via administrator-configured redirect targets_CVE-2026-43924

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL sche...

FOSSBilling FOSSBilling < 0.8.0 CVE
MEDIUM 6.9 CVE-2026-40495

FOSSBilling version exposed via asset cache buster_CVE-2026-40495

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache ...

FOSSBilling FOSSBilling < 0.8.0 CVE