Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-1836

Stored credentials in Redmine_CVE-2026-1836

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platf...

Redmine Redmine CVE
MEDIUM 6.9 CVE-2026-12066

PbootCMS Password MemberController.php retrieve password recovery_CVE-2026-12066

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/Mem...

n/a PbootCMS 3.2.0 CVE
MEDIUM 5.3 CVE-2026-49347

Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown_CVE-2026-49347

Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels....

duck-organization questbot < 1.1.8 CVE
MEDIUM 6.7 CVE-2026-48914

Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling_CVE-2026-48914

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before w...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.3 CVE-2026-11847

Integration Corp|iVEC-IEI Virtualization Edge Computer – Arbitrary File Deletion_CVE-2026-11847

The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote att...

IEI Integration Corp iVEC TANK-XM811 CVE
MEDIUM 6.9 CVE-2026-11844

IEI Integration Corp|iVEC-IEI Virtualization Edge Computer – Arbitrary File Read_CVE-2026-11844

The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote att...

IEI Integration Corp iVEC TANK-XM811 CVE
MEDIUM 5.3 CVE-2026-12058

CVE-2026-12058_CVE-2026-12058

The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.

vivo PcSuite Versions below 6.2.0 CVE
MEDIUM 6.9 CVE-2026-12060

Hepta Platforms|Heptabase – Exposed Dangerous_CVE-2026-12060

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to lever...

Hepta Platforms Heptabase CVE
MEDIUM 6.3 CVE-2026-20746

PingDirectory copying of virtual attributes leads to memory exhaustion_CVE-2026-20746

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent...

Ping Identity PingDirectory 9.3.0.0 CVE
MEDIUM 4.3 8E7576F6-458D-

Exploit for CVE-2026-46645_8E7576F6-458D-5824-819E-FC7C2BCB6824

CVE-2026-46645 - SQLAdmin ajaxlookup Authorization Bypass Executive Summary This repository contains a local Docker lab for reproducing CVE-2026-46...

N/A N/A GITHUBEXPLOIT