Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-36607

CVE-2026-36607_CVE-2026-36607

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (c...

Mercusys Mercusys AC12G AC12G(EU)_V1_200909 CVE
HIGH 7.1 CVE-2026-36606

CVE-2026-36606_CVE-2026-36606

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mod...

n/a n/a n/a CVE
HIGH 8.6 CVE-2026-20230

CVE-2026-20230_CVE-2026-20230

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified C...

Cisco Cisco Unified Communications Manager N/A CVE
HIGH 8.4 CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction._CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that la...

Concrete CMS Concrete CMS 5.0 CVE
HIGH 8.8 472EEC26-F9C7-

coruna_472EEC26-F9C7-50CA-A4D6-2E1879CAC2F3

iOS Orchestrator — Coruna Web server, C2 listener, and interactive shell for the Coruna exploit chain CVE-2024-23222. Targets Safari on iOS 13–17.2...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2026-30650

CVE-2026-30650_CVE-2026-30650

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD...

Vivotek Vivotek FD8136 FD8136-VVTK-0300a CVE
HIGH 7.5 CVE-2026-42504

Quadratic complexity in WordDecoder.DecodeHeader in mime_CVE-2026-42504

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

Go standard library mime CVE
HIGH 7 CVE-2026-44281

GLPI vulnerable to unauthorized reading of a specific asset object_CVE-2026-44281

GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user w...

glpi-project glpi >= 11.0.0, < 11.0.7 CVE
HIGH 8.4 CVE-2026-42321

GLPI has stored XSS in asset locks_CVE-2026-42321

GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS pay...

glpi-project glpi >= 10.0.4, < 10.0.25 CVE
HIGH 7 CVE-2026-42318

GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint_CVE-2026-42318

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users wi...

glpi-project glpi >= 11.0.0, < 11.0.7 CVE