Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-56341

AVideo – Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php_CVE-2026-56341

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing Pay...

AVideo AVideo CVE
HIGH 8.7 CVE-2026-56340

vLLM – Denial of Service via Unvalidated Multimodal Embeddings_CVE-2026-56340

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tens...

vLLM vLLM 0.10.2 CVE
HIGH 8.2 90EC8998-FB96-

explotability_analysis_ebpf_90EC8998-FB96-54C8-B382-EB8D24257354

eBPF Verifier Exploit Research — s344024 Romano Simone Research project for the Security Verification and Testing SVT course — analysis and exploit...

N/A N/A GITHUBEXPLOIT
HIGH 8.6 3E4275D3-0547-

Exploit for Server-Side Request Forgery in Vercel Next.Js_3E4275D3-0547-519B-A6B4-38321844D41A

╔══════════════════════════════════════════════════════════════╗ ║ NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handle...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 THN:3C02EE8690F...

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys_THN:3C02EE8690F770FB334836241DFA97E7

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL1kN23KhnFjdjHcR0i-iySK1Zv-kkApPs6yBq11670ubXx0NiAbgDMoYSfwQNyq9asso5AG9KcPRXEL4LU8...

N/A N/A THN
HIGH 7.5 CVE-2026-11912

Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action_CVE-2026-11912

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up ...

eemitch Simple File List CVE
HIGH 7.5 CVE-2026-11911

Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter_CVE-2026-11911

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile...

eemitch Simple File List CVE
HIGH 8.7 CVE-2026-56216

Capgo – Scope Escalation via API Key Creation in /functions/v1/apikey_CVE-2026-56216

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint ...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56215

Capgo – Account Merge via Poisoned public.users.email in SSO Provisioning_CVE-2026-56215

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning end...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56214

Capgo – Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC_CVE-2026-56214

Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allo...

Capgo Capgo CVE