SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ...
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attacker...
CVE-2026-49757 — AshAuthentication OAuth2/OIDC Account Takeover Proof of Concept for CVE-2026-49757 — a critical vulnerability in AshAuthentication...
CVE-2026-11561 — Apinizer SSTI / RCE Version Check Infra Nuclei template to detect Apinizer versions lower than 2026.04.6, which are vulnerable to ...
AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the targ...
No description provided...
Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage clas...
CVE-2026-4480-PoC...
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in P...
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker t...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.