Security Intelligence
Feed

Real-time CVE tracking, exploit analysis, and vulnerability intelligence curated for security professionals.

56 New today
64,208 Total advisories
Live Monitoring

Daily Security Trends (Last 14 Days)

32
Jun 7
255
Jun 8
658
Jun 9
351
Jun 10
245
Jun 11
336
Jun 12
60
Jun 13
68
Jun 14
443
Jun 15
630
Jun 16
464
Jun 17
3
Jun 18
352
Jun 19
47
Jun 20
Critical
High
Medium
Low

Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-56347

AVideo TopMenu Plugin – Stored Cross-Site Scripting via Unescaped Menu Item Fields_CVE-2026-56347

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encodi...

WWBN AVideo CVE
MEDIUM 6.9 CVE-2026-56346

AVideo – Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint_CVE-2026-56346

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated use...

AVideo AVideo CVE
CRITICAL 9.2 CVE-2026-56345

AVideo – Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint_CVE-2026-56345

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the targ...

AVideo AVideo CVE
MEDIUM 6.1 CVE-2026-56342

AVideo – Server-Side Request Forgery in Live/test.php via statsURL Parameter_CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators t...

AVideo AVideo CVE
HIGH 8.7 CVE-2026-56341

AVideo – Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php_CVE-2026-56341

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing Pay...

AVideo AVideo CVE
HIGH 8.7 CVE-2026-56340

vLLM – Denial of Service via Unvalidated Multimodal Embeddings_CVE-2026-56340

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tens...

vLLM vLLM 0.10.2 CVE
MEDIUM 5.3 CVE-2025-71379

vllm – Regular Expression Denial of Service in Multiple Components_CVE-2025-71379

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/...

vllm vllm 0.6.3 CVE
NONE 79718F65-1042-

flowise-mcp-env-case-bypass-poc_79718F65-1042-5245-B81E-B6A037118E89

Flowise 3.1.2 Custom MCP Environment Variable Case Bypass PoC This repository documents and validates an authenticated Windows ACE/RCE-class issue ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 B59AFB79-5EFF-

Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in Apache Tomcat_B59AFB79-5EFF-5CBE-9EBA-41DE2D90DCE9

No description provided...

N/A N/A GITHUBEXPLOIT