Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 D76E3BC5-2C10-

Exploit for Improper Access Control in Getgrav Grav-Plugin-Admin_D76E3BC5-2C10-52DE-8FE2-24C1C9C72D09

this is my version i found a lot in internet but those are too bad USAGE python3 exploit.py -u http://IP/grav-admin/ --lhost YOUR TUN0 IP --lport 4...

N/A N/A GITHUBEXPLOIT
HIGH 8.1 CVE-2026-39253

CVE-2026-39253_CVE-2026-39253

An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Se...

n/a n/a n/a CVE
MEDIUM 5.3 CVE-2026-54517

jackson-databind: @JsonView bypass for setterless creator properties_CVE-2026-54517

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3....

FasterXML jackson-databind >= 2.21.0, < 2.21.4 CVE
MEDIUM 5.3 CVE-2026-54516

jackson-databind: Renamed @JsonIgnore’d setters can deserialize via private fields_CVE-2026-54516

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3....

FasterXML jackson-databind >= 2.21.0, < 2.21.4 CVE
MEDIUM 5.3 CVE-2026-54515

jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties_CVE-2026-54515

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5...

FasterXML jackson-databind >= 2.8.0, < 2.18.9 CVE
MEDIUM 5.3 CVE-2026-54514

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)_CVE-2026-54514

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4...

FasterXML jackson-databind >= 2.0.0, < 2.18.8 CVE
HIGH 8.1 CVE-2026-54513

jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)_CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21....

FasterXML jackson-databind >= 2.10.0, < 2.18.8 CVE
HIGH 8.1 CVE-2026-54512

jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation_CVE-2026-54512

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21....

FasterXML jackson-databind >= 2.10.0, < 2.18.8 CVE
MEDIUM 6.3 CVE-2026-50193

jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()_CVE-2026-50193

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a pot...

FasterXML jackson-databind >= 2.10.0, < 2.14.0 CVE
MEDIUM 5.3 CVE-2026-47382

NocoDB: Server-Side Request Forgery via Database Connection Host_CVE-2026-47382

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-sup...

nocodb nocodb < 2026.05.1 CVE