Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 F3832E4F-76F3-

Exploit for CVE-2026-11834_F3832E4F-76F3-50B7-92A3-92EB0B582EB1

CVE-2026-11834 PoC TP-Link DHCP Option 66 Unauthenticated RCE CVE-2026-11834 Overview A command injection vulnerability CWE-78 in the DHCP Option 6...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 C3D90422-8858-

Exploit for Use After Free in Microsoft_C3D90422-8858-5EAC-A8E5-588AF315EA86

CVE-2026-42978 PoC & Research Windows Push Notifications Use-After-Free Race condition in Windows Push Notifications service WpnService that runs a...

N/A N/A GITHUBEXPLOIT
HIGH 8.2 MSF:AUXILIARY-SCANNER-

Audiobookshelf Unauthenticated API Authentication Bypass Scanner_MSF:AUXILIARY-SCANNER-HTTP-AUDIOBOOKSHELF_AUTH_BYPASS-

This module detects Audiobookshelf servers affected by CVE-2025-25205, an unauthenticated authentication bypass. Affected versions 2.17.0 through 2...

N/A N/A METASPLOIT
NONE D00ABD7F-A3B6-

web-exploitation-lab_D00ABD7F-A3B6-5F61-A944-65E5960AB87E

🌐 Web Exploitation Lab Payloads, techniques et cheatsheet web — SQLi, XSS, LFI, SSRF — by @ibramoha2 --- 💉 SQL Injection sql -- Test basique ' OR...

N/A N/A GITHUBEXPLOIT
NONE HACKREAD:40BF5A...

LastPass Confirms Customer Data Breach After Klue OAuth Token Theft_HACKREAD:40BF5AE34923B51723CA316715EF181B

LastPass has confirmed it was affected by the Klue supply chain incident, saying an unauthorised actor used stolen…

N/A N/A HACKREAD
CRITICAL 9.8 IMPERVABLOG:CC2...

CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised_IMPERVABLOG:CC22F53AF67610E01435FC711BB2B03F

## **Introduction** On May 24, 2026, Imperva observed exploitation attempts against Laravel Livewire applications, blocked by the Imperva Cloud WA...

N/A N/A IMPERVABLOG
NONE WIRED:97C27F256...

Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed_WIRED:97C27F256D0F2D95C8FBD8F9552B9208

The private events group, cofounded by Peter Thiel, says a “criminal” hacker is behind a breach that exposed members’ personal details. WIRED found...

N/A N/A WIRED
NONE HACKREAD:B18ECD...

Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity_HACKREAD:B18ECD3BC16D6012AA85453F7891373F

DC, United States, 23rd June 2026, CyberNewswire

N/A N/A HACKREAD
MEDIUM 5.9 CVE-2026-55736

Private action arguments can be set by user input in Ash_CVE-2026-55736

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a...

ash-project ash 3.0.0 CVE
MEDIUM 6.3 CVE-2026-55249

@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync Template String_CVE-2026-55249

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rew...

rtk-ai rtk 1.0.0 CVE