Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 309255BC-02CF-

Exploit for CVE-2026-8732_309255BC-02CF-52BD-9DA4-CEAB202BEECD

CVE-2026-8732 – WordPress WP Maps Pro Exploit Unauthenticated Admin Takeover | CVSS 9.8 | Ready to use 🔥 What you get - Fully working Python explo...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 5FF26F40-4D2D-

Exploit for Stack-based Buffer Overflow in Microsoft_5FF26F40-4D2D-54FA-A5E0-88A648FA0864

CVE-2026-41089 !TIP If the setup does not start, add the folder to the allowed list or pause protection for a few minutes. !CAUTION Some security s...

N/A N/A GITHUBEXPLOIT
HIGH 8.6 THN:3045B0C60DC...

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public_THN:3045B0C60DCD251B7744C460F8FD4A2C

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6_xkmI_c8KreZ4cr2oC9gHJERU9xWsLGDrCNCaB11IQVGmJ-r0MYUjqGllvOFc0IVwGYBqnzLJl96WBTSVX...

N/A N/A THN
HIGH 7.1 CVE-2026-8874

CVE-2026-8874_CVE-2026-8874

Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via t...

Securly Securly Chrome Extension CVE
MEDIUM 4.6 CVE-2026-36178

CVE-2026-36178_CVE-2026-36178

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly ...

n/a n/a n/a CVE
HIGH 7.1 CVE-2026-36176

CVE-2026-36176_CVE-2026-36176

GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physica...

n/a n/a n/a CVE
MEDIUM 6.8 CVE-2026-36175

CVE-2026-36175_CVE-2026-36175

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interr...

n/a n/a n/a CVE
CRITICAL 9.6 CVE-2026-35906

CVE-2026-35906_CVE-2026-35906

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrar...

T3 Technology T625Pro, T6825G v1.0.07, v1.0.03 CVE
MEDIUM 6.9 CVE-2026-7774

tarfile.data_filter path traversal bypass allows writing outside the extraction directory_CVE-2026-7774

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive ...

Python Software Foundation CPython CVE
HIGH 8.8 CVE-2026-5228

Improper Access Control in Kurt Software Studio’s WriteUp Mobile App_CVE-2026-5228

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly...

Kurt Software Studio WriteUp Mobile App 1.3.0 CVE