Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 FBFF27F7-8ED1-

Exploit for CVE-2026-56121_FBFF27F7-8ED1-5776-9326-EF2D07BF0586

CVE-2026-56121 — Feast Unauthenticated RCE via gRPC Registry Deserialization The Feast function of an OnDemandFeatureView as soon as a spec arrives...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.4 8276B0B0-A504-

Exploit for OS Command Injection in Devcode Openstamanager_8276B0B0-A504-5BFB-96EF-E9535076655D

CVE-2025-69212-PoC https://github.com/advisories/GHSA-25fp-8w8p-mx36 A critical OS Command Injection vulnerability exists in the P7M signed XML fil...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 2EC91A8F-3FD4-

CVE-2026-XXXX-silverpeak-webgms-9.5.6-exposed-admin_2EC91A8F-3FD4-54B9-8741-6AC2418907A9

CVE-2026-XXXX: NVIDIA/SilverPeak SD-WAN webGMS - Exposed Admin Interface Product NVIDIA SilverPeak SD-WAN webGMS Global Management System - Version...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 A372C56F-D8B3-

Exploit for CVE-2026-10580_A372C56F-D8B3-5DAE-BD3F-1EB6467679D8

CVE-2026-10580 - WordPress - Hippoo Mobile App for WooCommerce 1.9.4. Additionally: - Regularly audit user accounts for unauthorized changes - Moni...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-12349

Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions_CVE-2026-12349

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and includi...

octagonwebstudio Premium Addons for KingComposer CVE
CRITICAL 9.8 CVE-2026-12073

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite_CVE-2026-12073

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...

metagauss ProfileGrid – User Profiles, Groups and Communities CVE
MEDIUM 6.5 CVE-2026-11367

PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter_CVE-2026-11367

The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the...

andrasweb PixMagix – WordPress Image Editor CVE
MEDIUM 6.1 CVE-2026-56809

CVE-2026-56809_CVE-2026-56809

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerab...

Ricoh Company, Ltd. Multiple laser printers and MFPs which implement Ricoh Web Image Monitor see the information provided by the vendor CVE
HIGH 7.2 CVE-2026-56808

CVE-2026-56808_CVE-2026-56808

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution wi...

AVTECH Security Corporation DGM3103SCT firmware version 3.2.5.4 and prior CVE
HIGH 7.8 CVE-2026-56137

CVE-2026-56137_CVE-2026-56137

RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-fi...

Gotcha Gotcha Games Inc. RPG MAKER MV 1.6.3 and earlier CVE