Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 MS:CVE-2026-47644

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability_MS:CVE-2026-47644

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unaut...

N/A N/A MSCVE
CRITICAL 10 MS:CVE-2026-48567

Azure HorizonDB Elevation of Privilege Vulnerability_MS:CVE-2026-48567

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
HIGH 7.7 MS:CVE-2026-45497

Microsoft M365 Copilot Remote Code Execution Vulnerability_MS:CVE-2026-45497

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute c...

N/A N/A MSCVE
CRITICAL 9.1 MS:CVE-2026-48579

Microsoft Exchange Online Information Disclosure Vulnerability_MS:CVE-2026-48579

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 8.1 82BACCCF-4973-

simplectf_82BACCCF-4973-500F-8B25-5714A0310B69

Simple CTF — TryHackMe Walkthrough Platform: TryHackMe | Difficulty: Easy | CVE: CVE-2019-9053 --- 1. Reconnaissance Port Scan bash nmap -p- --open...

N/A N/A GITHUBEXPLOIT
NONE QUALYSBLOG:0472...

From Operating Model to Product: How We Built the ROC for Detection-Speed Remediation_QUALYSBLOG:04729DC1A0A66FE61A5E92D6718FDCAE

In the first article in this series, we made the case for a prevention-led operating model. This article is about what happened next: the decision ...

N/A N/A QUALYSBLOG
HIGH 7.5 8A0044D6-4E23-

Exploit for CVE-2026-3180_8A0044D6-4E23-5EC1-9A9D-274941997A78

No description provided...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.5 CVE-2026-11322

Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass_CVE-2026-11322

Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlink...

nesquena Hermes WebUI CVE
HIGH 8.6 CVE-2026-10871

Shibby Tomato Web UI rc start_6rd_tunnel os command injection_CVE-2026-10871

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the com...

Shibby Tomato 1.28.0000 CVE
HIGH 7.5 CVE-2026-8888

CVE-2026-8888_CVE-2026-8888

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressio...

Securly Securly Chrome Extension CVE