Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-55223

c3p0 exposes a deserialization “sink” via JDBC DataSource bean properties_CVE-2026-55223

c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for des...

swaldman c3p0 < 0.14.0 CVE
CRITICAL 9.3 CVE-2026-50110

Use of Hard-coded Credentials in StoneFly Storage Concentrator_CVE-2026-50110

Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the cred...

StoneFly Storage Concentrator CVE
NONE MALWAREBYTES:76...

Watch out for “high paying, low effort” Amazon job texts_MALWAREBYTES:7664CEF9E63F1C210095EE36493FED6B

Remote, flexible, high‑paying work is a tempting prospect, and the holy grail for many people looking for a new role. But it's not just recruiters ...

N/A N/A MALWAREBYTES
NONE B201DF04-51B6-

redteam-threat-exploits_B201DF04-51B6-52D3-A8EA-718A6037086E

redteam-threat-exploits A Claude Code skill that turns OpenCTI threat intelligence into red team exercise material: rank top threats from OpenCTI, ...

N/A N/A GITHUBEXPLOIT
NONE 6701D9A4-CBB9-

ctf-poc_6701D9A4-CBB9-5F86-A45E-F2C7570CFA9B

Xerces-C++ PE Entity UAF RCE PoC Tiny proof harness for Apache Xerces-C++ at commit 53c0401812bfe5523594c1180f5ac7c758a2eaf7. The bug is a paramete...

N/A N/A GITHUBEXPLOIT
LOW 3.5 CVE-2026-9836

IBM DataStage Flow Designer application is affected by an information disclosure vulnerability_CVE-2026-9836

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

IBM InfoSphere Information Server 11.7.0.0 CVE
MEDIUM 6.5 CVE-2026-9002

IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabled_CVE-2026-9002

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the...

IBM WebSphere Extreme Scale 8.6.1.0 CVE
CRITICAL 9.1 CVE-2026-7874

Weak Cryptographic Key Derivation Exposed All Stored Credentials_CVE-2026-7874

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivat...

IBM Langflow OSS 1.0.0 CVE
CRITICAL 9.9 CVE-2026-7873

Code Injection Vulnerability in Code Validation Endpoint_CVE-2026-7873

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credential...

IBM Langflow OSS 1.0.0 CVE
CRITICAL 9.8 CVE-2026-7871

Insecure Deserialization in Redis Cache Backend_CVE-2026-7871

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all s...

IBM Langflow OSS 1.0.0 CVE