Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 236C3334-CF38-

Exploit for CVE-2026-10795_236C3334-CF38-5100-98AA-1DF6189FF3D2

CVE-2026-10795 UpdraftPlus Auto-Exploit & Mass Scanner Authorized Use Only — This tool is provided for authorized penetration testing, security res...

N/A N/A GITHUBEXPLOIT
NONE 2777ACBF-D21B-

OSCP-PEN200_2777ACBF-D21B-5A7D-B555-B04B9386E9B2

🛡️ OSCP / PEN-200 Master Pentesting Database 📖 Overview This repository serves as my Master Study Database for the OffSec PEN-200 OSCP course. It ...

N/A N/A GITHUBEXPLOIT
NONE 158DF90B-E6C6-

network-intrusion-detector_158DF90B-E6C6-5560-AE00-C499B6DD4D07

network-intrusion-detector A Python tool that analyses web server access logs and flags suspicious activity. It looks for patterns that typically i...

N/A N/A GITHUBEXPLOIT
HIGH 7.1 CVE-2026-8406

openSIS Classic 9.3 – Insecure Direct Object Reference in Sent Mail_CVE-2026-8406

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the m...

OS4ED openSIS-Classic 9.3 CVE
MEDIUM 4.9 CVE-2026-6338

HTTP request smuggling in Kong Enteprise Gateway_CVE-2026-6338

A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vuln...

Kong Kong Enterprise Gateway 3.4.0.0 CVE
MEDIUM 5.8 CVE-2026-53723

guzzlehttp/guzzle-services’ XML Request Serialization Vulnerable to XML Injection via CDATA Terminator_CVE-2026-53723

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize ...

guzzle guzzle-services < 1.5.4 CVE
HIGH 8.8 CVE-2026-53661

boruta-server sent sensitive session cookies without the Secure attribute_CVE-2026-53661

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior ...

malach-it boruta-server < 0.9.1 CVE
HIGH 8.1 CVE-2026-11816

Path Traversal in keras-team/keras_CVE-2026-11816

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils....

keras-team keras-team/keras unspecified CVE
HIGH 7.8 CVE-2026-10847

Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS_CVE-2026-10847

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to exe...

checkpoint Identity Agent Versions prior to 81.087.0000 CVE
NONE HACKREAD:9C8DEF...

The Hidden Security Risks of Poor Software Testing_HACKREAD:9C8DEFCCD2BA49023129124F38E174AD

Poor Software Testing can expose hidden flaws, vulnerable dependencies and weak controls, increasing breach risks, downtime and costly fixes after ...

N/A N/A HACKREAD