Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 9349E804-9874-

Exploit for Improper Access Control in Vitejs Vite_9349E804-9874-5D40-A4D5-7FAE1725C5AA

CVE-2025-30208 Using a special raw import query string on a vite dev server, a attacker can read arbitrary files Summary of the CVE Vite dev server...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 A34D1BC1-7B69-

Exploit for Code Injection in Apache Nifi_A34D1BC1-7B69-5F1F-A6EF-D572FB2CA379

CVE-2023-34468 PoC for Apache NiFi Educational proof-of-concept PoC for CVE-2023-34468 affecting Apache NiFi versions prior to 1.22.0. This reposit...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 CVE-2026-50887

CVE-2026-50887_CVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resou...

shlink shlink v5.0.1 CVE
CRITICAL 9.1 CVE-2026-50886

CVE-2026-50886_CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafte...

Project Firefly Project Firefly III v6.5.9 CVE
HIGH 7.5 CVE-2026-50885

CVE-2026-50885_CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints...

n/a n/a n/a CVE
CRITICAL 9.6 CVE-2026-50883

CVE-2026-50883_CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a cra...

matze matze wastebin v3.4.1 CVE
HIGH 7.5 CVE-2026-50882

CVE-2026-50882_CVE-2026-50882

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-50872

CVE-2026-50872_CVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sens...

fossar selfoss v2.20-SNAPSHOT CVE
CRITICAL 9.8 CVE-2026-50871

CVE-2026-50871_CVE-2026-50871

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers t...

kanishka-linux Reminiscence v0.3.0 CVE
HIGH 7.5 CVE-2026-50870

CVE-2026-50870_CVE-2026-50870

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive infor...

n/a n/a n/a CVE