Recent Advisories

Severity ID Title Vendor Product Date Type
NONE 8BAB742C-5C9E-

sharepoint-sqli-research_8BAB742C-5C9E-5401-B964-9E8F5ACD280A

SharePoint SQL Injection Research Analysis of SQL injection vulnerabilities affecting Microsoft SharePoint Server on-premises deployments — coverin...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 DF5C4368-B596-

Exploit for Untrusted Pointer Dereference in Microsoft_DF5C4368-B596-5A56-B3D2-A29063405520

Note The NTOKernelBase in exp.cpp needs to be set by yourself...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 MS:CVE-2026-12447

Chromium: CVE-2026-12447 Heap buffer overflow in WebRTC_MS:CVE-2026-12447

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 3.1 MS:CVE-2026-12458

Chromium: CVE-2026-12458 Incorrect security UI in Passwords_MS:CVE-2026-12458

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 7.1 CVE-2026-10658

Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS_CVE-2026-10658

A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/blue...

zephyrproject-rtos Zephyr * CVE
HIGH 7.1 CVE-2026-10651

Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read_CVE-2026-10651

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sd...

zephyrproject-rtos Zephyr * CVE
MEDIUM 4.9 CVE-2026-10645

fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal_CVE-2026-10645

Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversa...

zephyrproject-rtos Zephyr * CVE
HIGH 8.2 CVE-2026-11833

CVE-2026-11833_CVE-2026-11833

Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting inform...

Yokogawa Electric Corporation FAST/TOOLS R9.01 CVE
MEDIUM 6.8 068C9182-D370-

Exploit for Out-of-bounds Write in Samsung Android_068C9182-D370-5C64-B905-6227B13760CE

SveService Buffer Overflow --- Samsung SMR May 2026 SVE-2026-0478CVE-2026-21018 Affected versions: Android 14, 15, 16 Disclosure status: Privately ...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.5 MS:CVE-2026-12444

Chromium: CVE-2026-12444 Out of bounds read in Chromoting_MS:CVE-2026-12444

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE