Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2026-55743

OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution_CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypass...

tinyhumansai OpenHuman CVE
CRITICAL 9.3 CVE-2026-54812

WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability_CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Inject...

StylemixThemes Motors n/a CVE
HIGH 7.5 CVE-2026-54810

WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability_CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

Nexi Payments Nexi XPay n/a CVE
HIGH 8.1 CVE-2026-54415

Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover_CVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authentica...

Azuriom Azuriom CMS CVE
HIGH 7.4 CVE-2026-49502

CVE-2026-49502_CVE-2026-49502

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent netwo...

Dell PowerFlex CVE
MEDIUM 4.8 CVE-2026-48142

NGINX ngx_http_charset_module vulnerability_CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location b...

F5 NGINX Open Source 1.13.10 CVE
MEDIUM 6.8 CVE-2026-48117

DroneAware’s Improper Account Activation in Registration and SSO Flows Leads to Account Takeover_CVE-2026-48117

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack...

fduflyer DroneAware-Node-Releases < server-2026-05-20 CVE
CRITICAL 9.3 CVE-2026-47103

Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection_CVE-2026-47103

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by s...

fgmacedo python-statemachine 3.0.0 CVE
HIGH 8.1 CVE-2026-42530

NGINX Open-Source ngx_http_v3_module vulnerability_CVE-2026-42530

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remot...

F5 NGINX Open Source 1.31.0 CVE
HIGH 8.1 CVE-2026-42055

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability_CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists w...

F5 NGINX Open Source 1.13.10 CVE