Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CDA85394-5DE8-

Exploit for CVE-2026-41490_CDA85394-5DE8-526C-A69E-987959729784

CVE-2026-41490 — SQL Injection in Dagster database I/O managers via dynamic partition keys Severity: High CVSS 8.x — AV:N/AC:L/PR:L/UI:N + C:H/I:H/...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.4 6DC85E25-562C-

Exploit for Cross-Site Request Forgery (CSRF) in Jupyter Jupyterhub_6DC85E25-562C-5013-9637-8ECC82BB80F9

CVE-2026-40864 — JupyterHub XSRF bypass via cross-origin form POST Sec-Fetch-Mode: no-cors Severity: Moderate CWE: CWE-352 — Cross-Site Request For...

N/A N/A GITHUBEXPLOIT
NONE 83B29156-2E5B-

web-vuln-scanner_83B29156-2E5B-5DE8-A514-617EF308D8E8

Web Vulnerability Scanner Basic web application vulnerability scanner built in Python. Tests for common OWASP Top 10 issues — written as a learning...

N/A N/A GITHUBEXPLOIT
HIGH 9.3 29FDB8F1-C4A9-

AutoVAPT_29FDB8F1-C4A9-50FC-8CC7-D022D15622DD

█████╗ ██╗ ██╗████████╗ ██████╗ ██╗ ██╗ █████╗ ██████╗ ████████╗ ██╔══██╗██║ ██║╚══██╔══╝██╔═══██╗██║ ██║██╔══██╗██╔══██╗╚══██╔══╝ ███████║██║ ██║ ...

N/A N/A GITHUBEXPLOIT
NONE THN:DA6373D6ECA...

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals_THN:DA6373D6ECA2DC7F73EC335D7DCE6717

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitE4uRkPKzQw_uUTSEzPgbuTByOaSNQeEHcANQCdYOtD8HJxqjIy9e0TIkkYeMN5QQghbvb1Nc4RJdwpGUD4...

N/A N/A THN
MEDIUM 6.4 CVE-2026-11769

Operator – Namespaced User Path Traversal_CVE-2026-11769

We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escala...

Grafana Grafana Operator CVE
HIGH 7.5 2B7EC0E8-7984-

Exploit for CVE-2026-22356_2B7EC0E8-7984-5387-91E5-615EAC92E0E1

CVE-2026-22356 CVE-2026-22356: Jetpack CRM Path Traversal Vulnerability and RCE Kullanım Kılavuzu Aşağıdaki kullanım örneklerini yalnızca yetkili t...

N/A N/A GITHUBEXPLOIT
NONE 08DA759F-8360-

web-vulnerability-scanner_08DA759F-8360-516C-8014-413DE29094D7

No description provided...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 C2EB4AA1-0C70-

Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server_C2EB4AA1-0C70-5104-AF4C-BC274F5A5B7A

http2-bomb-detector HTTP/2 Bomb CVE-2026-49975 Non-destructive vulnerability detection tool — for Nginx / Apache httpd Vulnerability Background CVE...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-9848

WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter_CVE-2026-9848

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, ...

emarket-design Customer Support Ticket System & Helpdesk CVE