Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2025-14774

Communication analysis between the Card Reader and TP2CardReaderService daemon_CVE-2025-14774

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

ABB T-MAC Plus 4.0-24 CVE
HIGH 8 CVE-2025-14773

Stored Cross-Site Scripting in ABB T-MAC Plus web application_CVE-2025-14773

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plu...

ABB T-MAC Plus 4.0-24 CVE
HIGH 8.8 CVE-2025-14772

Broken Access Control in ABB T-MAC Plus web application_CVE-2025-14772

Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

ABB T-MAC Plus 4.0-24 CVE
HIGH 7.8 51E71640-84AB-

Exploit for Out-of-bounds Write in Linux Linux_Kernel_51E71640-84AB-5291-808C-C9A24ECBFBE4

本地提权 CVE-2026-46300 使用方式: CGOENABLED=0 go build -ldflags="-s -w" -o fragnesia . ./fragnesia 影响版本: Ubuntu 16.04 LTS RHEL 8,9 Rocky Linu...

N/A N/A GITHUBEXPLOIT
HIGH 10 AA65832E-F09E-

Exploit for CVE-2026-10187_AA65832E-F09E-592C-8B20-D503A9981614

No description provided...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-50031

CVE-2026-50031_CVE-2026-50031

ipmi-oem in FreeIPMI before 1.16.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) spe...

FreeIPMI FreeIPMI 0.7.12 CVE
HIGH 7.8 4844D9DA-C29D-

Exploit for CVE-2026-46243_4844D9DA-C29D-5877-9267-D476E4320671

cifswitch-check A shell script to check whether a Linux system is exposed to CIFSwitch CVE-2026-46243 — a local privilege escalation vulnerability ...

N/A N/A GITHUBEXPLOIT
HIGH 7.1 CVE-2026-31942

LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite other users’ API keys_CVE-2026-31942

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Refere...

danny-avila LibreChat < 0.8.3-rc1 CVE
HIGH 8.2 CVE-2026-25861

QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php_CVE-2026-25861

QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user cred...

QloApps QloApps CVE
HIGH 7.1 CVE-2026-40108

GLPI Vulnerable to Stored XSS in ITIL Costs_CVE-2026-40108

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. ...

glpi-project glpi >= 11.0.0, < 11.0.7 CVE