Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 1C0E4383-9787-

Exploit for CVE-2025-56399_1C0E4383-9787-58E2-A56F-70D9888E6255

Laravel FileManager Unrestricted File Upload CVE-2025-56399 CWE-434: Unrestricted Upload of File with Dangerous Type CVSS Score: 8.5 High --- 📋 De...

N/A N/A GITHUBEXPLOIT
NONE F6423E9A-0865-

Nexploit_F6423E9A-0865-54FE-9EDB-D006725C3F77

Nexploit Advanced Offensive Security Recon & Exploitation Framework Features - Reconnaissance - Web Scanning - Fuzzing - AI Analysis - Reporting De...

N/A N/A GITHUBEXPLOIT
NONE 8745BE4B-4A7D-

CVE_8745BE4B-4A7D-50BE-9B13-043C121DDC37

CVE Reports Security vulnerability reports and proof-of-concept code. Structure ├── reports/ Vulnerability reports ├── pocs/ Proof of Concept code ...

N/A N/A GITHUBEXPLOIT
NONE 1E46CB90-FFD8-

student-registration-rce-sqli-cve_1E46CB90-FFD8-54DE-90FF-8577C105192D

CVE-2026-XXXXX Unauthenticated Arbitrary File Upload RCE + SQL Injection in Student Registration System --- Advisory Information | Field | Value | ...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.5 CVE-2026-58058

Nmap – Integer Underflow in IPv6 Extension Header Parsing_CVE-2026-58058

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so th...

Nmap Nmap CVE
MEDIUM 5 CVE-2026-58057

Flowise – Custom MCP Environment Variable Denylist Bypass via Case Sensitivity_CVE-2026-58057

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where en...

Flowise Flowise CVE
HIGH 7.6 CVE-2026-58056

RustDesk – FileTransfer Session Authorization Scope Bypass_CVE-2026-58056

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer sessi...

RustDesk RustDesk CVE
MEDIUM 5.4 CVE-2026-58055

nghttp2 nghttpx – HTTP Request/Response Smuggling via Upgrade Request with Content-Length_CVE-2026-58055

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-a...

nghttp2 nghttp2 CVE
HIGH 7.2 CVE-2026-58054

MyBB – Privilege Escalation from Limited ACP User Management to Administrator_CVE-2026-58054

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers ...

MyBB MyBB CVE
CRITICAL 9.9 CVE-2026-58053

Gitea act_runner – Container Hardening Bypass via Workflow Container Options_CVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfi...

Gitea act_runner CVE