Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12811

kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting_CVE-2026-12811

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/f...

kortix-ai suna 0.8.0 CVE
MEDIUM 5.3 CVE-2026-12814

Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection_CVE-2026-12814

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_...

Comfast CF-WR631AX V3 2.7.0.0 CVE
MEDIUM 5.3 CVE-2026-12813

activepieces File URL file.ts handleUrlFile server-side request forgery_CVE-2026-12813

A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/eng...

n/a activepieces 0.1 CVE
MEDIUM 5.3 CVE-2026-12821

FlowiseAI Flowise S3 Document Loader S3.ts path traversal_CVE-2026-12821

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/...

FlowiseAI Flowise 3.1.0 CVE
MEDIUM 5.3 CVE-2026-12815

coollabsio coolify Image Name os command injection_CVE-2026-12815

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation ...

coollabsio coolify 4.0.0 CVE
HIGH 7.8 F9427710-4336-

Exploit for Use After Free in Linux Linux_Kernel_F9427710-4336-50DA-9AC4-7D23886787E5

CVE-2024-1086 Root Cause & Exploitation Target kernels: Linux 6.8 netfilter nftables Novel angle: Logic confusion in nftverdictinit causes refcount...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 8E435453-9D49-

Exploit for CVE-2026-39676_8E435453-9D49-528A-A043-03CC8664AC49

Cve-2026-39676 Wordpress Version: Download Manager 3.3.5.2 Title: Missing Authorization - Unauthenticated IDOR Exploit...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 B5DED594-DA46-

fragnesia-python-exploit_B5DED594-DA46-566B-B4FE-60D7564C12EF

Fragnesia CVE-2026-46300 - Python Exploit Linux Kernel Local Privilege Escalation via ESP-in-TCP Page Cache Corruption --- ⚠️ WARNING – READ BEFORE...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 9884B1E8-28B5-

Exploit for Improper Control of Dynamically-Managed Code Resources in N8N_9884B1E8-28B5-5EF2-85C0-874B02C19650

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.5 63040014-95CF-

Exploit for CVE-2026-48909_63040014-95CF-53D4-BB60-351E8E8012A4

CVE-2026-48909 — SP LMS PHP Object Injection → RCE Unauthenticated Remote Code Execution via PHP Object Injection in JoomShaper SP LMS comsplms ≤ 4...

N/A N/A GITHUBEXPLOIT