Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-49288

Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources_CVE-2026-49288

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view ...

statamic cms < 5.73.23 CVE
MEDIUM 5.3 CVE-2026-12238

WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation_CVE-2026-12238

The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. ...

wpgmaps WP Go Maps – Google Map, OpenStreetMap, Leaflet Map CVE
HIGH 7.5 CVE-2026-9375

Decompression Bomb Bypass via Negative max_length in Streaming API in urllib3_CVE-2026-9375

urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The is...

urllib3 urllib3/urllib3 unspecified CVE
HIGH 8.1 CVE-2026-49340

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host_CVE-2026-49340

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdat...

sentriz gonic < 0.21.0 CVE
HIGH 7.1 CVE-2026-49338

Subsonic API: any authenticated user can delete or read any other user’s playlist (IDOR)_CVE-2026-49338

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/de...

sentriz gonic < 0.21.0 CVE
MEDIUM 6.5 CVE-2026-27878

Tempo TraceQL query with exemplar hint could result in unbounded memory usage_CVE-2026-27878

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resultin...

Grafana Enterprise Traces (GET) 2.6.1 CVE
MEDIUM 6.3 CVE-2026-12726

Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential_CVE-2026-12726

A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.status...

Red Hat Red Hat Ansible Automation Platform 2 CVE
CRITICAL 10 A52A5B67-31DB-

Exploit for SQL Injection in Sangoma Freepbx_A52A5B67-31DB-5B86-B528-C2F4F2A57FB3

FreePBX 16 — Unauthenticated SQLi to RCE Proof-of-concept exploit chaining two FreePBX vulnerabilities to go from zero access to remote code execut...

N/A N/A GITHUBEXPLOIT
NONE EA26B6D2-E45A-

cortex-plugin-hexstrike_EA26B6D2-E45A-5D45-930B-37F1EE561AD6

Example Plugin Brief one-line description of what this plugin does. Installation bash From marketplace cortex plugin install marketplace:example-pl...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 B7F3888A-67A2-

Exploit for OS Command Injection in Ray_Project Ray_B7F3888A-67A2-5DAE-904A-1F178F5B69DD

CVE-2023-6019 - Anyscale Ray Dashboard Unauthenticated RCE PoC exploit for CVE-2023-6019 — Remote Code Execution via unauthenticated Ray Dashboard ...

N/A N/A GITHUBEXPLOIT