Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-10737

SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function_CVE-2026-10737

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file func...

smartypants SP Project & Document Manager CVE
HIGH 7.1 CVE-2026-41860

CVE-2026-41860_CVE-2026-41860

CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_end...

Cloud Foundry Foundation BOSH CVE
HIGH 7.1 CVE-2026-41859

CVE-2026-41859_CVE-2026-41859

A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and...

Cloud Foundry Foundation BOSH CVE
HIGH 8.7 CVE-2026-41011

CVE-2026-41011_CVE-2026-41011

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['n...

Cloud Foundry Foundation BOSH CVE
HIGH 7.7 86F57F94-F26C-

Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Tuzitio Camaleon_Cms_86F57F94-F26C-5EF7-904A-939B135AA64E

HTB Facts — Full Writeup Difficulty: Medium OS: Linux Tags: Web, MinIO, Camaleon CMS, Path Traversal, SSTI, Privilege Escalation --- Table of Conte...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 CVE-2025-22424

CVE-2025-22424_CVE-2025-22424

In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation ...

Google Android 16-qpr2 CVE
HIGH 7.3 CVE-2026-36611

CVE-2026-36611_CVE-2026-36611

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction ...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-36609

CVE-2026-36609_CVE-2026-36609

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the s...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-50033

CVE-2026-50033_CVE-2026-50033

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9...

Acronis Acronis DeviceLock DLP unspecified CVE
HIGH 7.3 CVE-2026-44682

CVE-2026-44682_CVE-2026-44682

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9...

Acronis Acronis DeviceLock DLP unspecified CVE