Recent Advisories

Severity ID Title Vendor Product Date Type
NONE E0E5A159-B9FC-

Exploit for CVE-2026-36425_E0E5A159-B9FC-5F80-8823-08B2D5FD8E7A

CVE-2026-36425 — OPSWAT AppRemover Driver ardrv.sys Improper Access Control | | | |---|---| | CVE ID | CVE-2026-36425 | | Vendor | OPSWAT, Inc. | |...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 5084DB54-3051-

Exploit for CVE-2026-49083_5084DB54-3051-5625-ADF2-00307974C4D8

CVE-2026-49083 CVE-2026-49083 LatePoint Calendar Booking Plugin Privilege Escalation Exploit 🎲🎲🎲...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 AE6219F6-F23B-

Exploit for CVE-2026-48907_AE6219F6-F23B-5FB3-886B-AFFE2FBDB4B1

CVE-2026-48907 CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2025-66391

CVE-2025-66391_CVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system...

n/a n/a n/a CVE
MEDIUM 6 CVE-2026-55748

CVE-2026-55748_CVE-2026-55748

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. ...

OpenStack Horizon 8.0.0 CVE
CRITICAL 9.6 CVE-2026-55743

OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution_CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypass...

tinyhumansai OpenHuman CVE
CRITICAL 9.3 CVE-2026-54812

WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability_CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Inject...

StylemixThemes Motors n/a CVE
HIGH 7.5 CVE-2026-54810

WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability_CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

Nexi Payments Nexi XPay n/a CVE
HIGH 8.1 CVE-2026-54415

Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover_CVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authentica...

Azuriom Azuriom CMS CVE
HIGH 7.4 CVE-2026-49502

CVE-2026-49502_CVE-2026-49502

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent netwo...

Dell PowerFlex CVE