Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-27868

PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT_CVE-2026-27868

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has t...

Teldat Regesta Smart HD-PLC - TLDPH16D2 11.02.05.10.02 CVE
HIGH 8.8 CVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter_CVE-2026-12165

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all vers...

contest-gallery Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe CVE
MEDIUM 6.6 CVE-2026-12115

Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection via Import_CVE-2026-12115

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions...

wpcalc Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress CVE
CRITICAL 10 06D35475-E02D-

Exploit for Improper Input Validation in Siemens 6Bk1602-0Aa12-0Tp0_Firmware_06D35475-E02D-543B-8D0C-C2472D8AE7A8

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.3 C05A4F3C-033F-

Exploit for CVE-2026-49952_C05A4F3C-033F-5533-8A5C-19976624584B

setup pip3 install Pillow torch torchvision run $ python3 exploit.py http://localhost/discuz5/ +---------------------------------------------------...

N/A N/A GITHUBEXPLOIT
NONE 187ED3AF-60BD-

CVE_187ED3AF-60BD-53B1-B54D-B5110190CA98

CVE Request Disclosure Document Executive Summary A Prototype Pollution → Stored DOM-based Cross-Site Scripting XSS vulnerability exists in the Has...

N/A N/A GITHUBEXPLOIT
NONE 1EF2C6EE-A7AF-

kage_1EF2C6EE-A7AF-573F-A48E-4C1275F9AD4F

kage The preview above is a clip. Click it for the full video. A Claude Code plugin that runs a full pentest engagement from inside your coding age...

N/A N/A GITHUBEXPLOIT
NONE THN:6332B5691B3...

144 Mastra npm Packages Compromised via Hijacked Contributor Account_THN:6332B5691B35A537EE5C97922CFDCCDE

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKLWn0zHFuJ8rkb2bqILIyAGxt_-VJ13Ytmv1TRWtGJkI6Rva5Oag5LdLasE2rmenokuRvoEI2wH0Ayfe_P4...

N/A N/A THN
MEDIUM 6.4 CVE-2026-8607

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute_CVE-2026-8607

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cro...

saadiqbal Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred CVE
MEDIUM 6.4 CVE-2026-8494

Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title_CVE-2026-8494

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in a...

mbis Permalink Manager Lite CVE