Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2026-48611

CVE-2026-48611_CVE-2026-48611

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthor...

phpBB phpBB 3.3.0 CVE
HIGH 8.1 CVE-2026-48610

CVE-2026-48610_CVE-2026-48610

Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in cert...

Ubiquiti Inc UDM CVE
CRITICAL 9.9 CVE-2026-47370

CVE-2026-47370_CVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices r...

Ubiquiti Inc UniFi OS Server CVE
CRITICAL 9.9 CVE-2026-47369

CVE-2026-47369_CVE-2026-47369

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices r...

Ubiquiti Inc UniFi OS Server CVE
HIGH 8.6 CVE-2026-47368

CVE-2026-47368_CVE-2026-47368

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data ...

Ubiquiti Inc UniFi OS Server CVE
CRITICAL 9.9 CVE-2026-47367

CVE-2026-47367_CVE-2026-47367

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Ag...

Ubiquiti Inc UID Enterprise Agent CVE
HIGH 7.2 CVE-2026-47366

CVE-2026-47366_CVE-2026-47366

Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated admi...

phpBB phpBB 3.3.0 CVE
CRITICAL 9.9 CVE-2026-47365

CVE-2026-47365_CVE-2026-47365

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tena...

WebPros WordPress-Toolkit CVE
MEDIUM 6.3 CVE-2026-20746

PingDirectory copying of virtual attributes leads to memory exhaustion_CVE-2026-20746

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent...

Ping Identity PingDirectory 9.3.0.0 CVE
HIGH 8.7 CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing_CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Un...

CyberArk Software, a Palo Alto Networks Company PAM SH Vault 14.0 CVE