CVE-2026-54597 — ITFlow Time-Based Blind SQL Injection Severity: High Advisory: GHSA-m63v-j7fw-hq2h Affected: ITFlow agent/ajax.php — expires param...
CVE-2026-54596 - Authenticated SQL Injection via recurringinvoicefrequency Parameter Enables Full Database Exfiltration Severity: High Advisory: GH...
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any oth...
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issu...
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurati...
Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory all...
An attacker could cooperatively pass data from one secure GPU process to another secure GPU process through shared secure memory allocations in the...
Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of bounds write in the kernel....
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metach...
A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Ser...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.