Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 8C0976A0-3F8E-

Exploit for Authentication Bypass Using an Alternate Path or Channel in Nvidia Triton_Inference_Server_8C0976A0-3F8E-508D-8CD5-6A5A5D01F118

CVE-2026-24207 / 24206 — NVIDIA Triton Inference Server SageMaker & Vertex AI auth bypass Unauthenticated attackers can reach the model-management ...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 0AEC5CEA-1ACD-

Exploit for Path Traversal in Rarlab Winrar_0AEC5CEA-1ACD-55C4-80FC-250F80922CE5

Amaranth Project A multi-stage backdoor implantation attack chain is implemented using CVE-2025-8088 WinRAR path traversal vulnerability, ≤ 7.11. F...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 75D8AF60-1BE7-

Exploit for Use After Free in Google Chrome_75D8AF60-1BE7-5841-A5AC-CC59A30D14EB

CVE-2026-13036 — Use-After-Free in Blink WidgetBase::UpdateSurfaceAndScreenInfo A use-after-free vulnerability in Google Chrome's Blink rendering e...

N/A N/A GITHUBEXPLOIT
NONE D5ADB7F6-7152-

offensive-craft_D5ADB7F6-7152-5D68-81DA-EFE5FF60F5AF

offensive-craft 🛠️ A forge for offensive security research — exploit development, tooling, tradecraft, and proof-of-concept work across the red tea...

N/A N/A GITHUBEXPLOIT
HIGH 8.5 CVE-2026-8797

CVE-2026-8797_CVE-2026-8797

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary co...

NEC Corporation ExpressUpdate Agent for Windows 3.24 and prior CVE
CRITICAL 9.8 967B93A1-932E-

Exploit for Missing Authentication for Critical Function in Oracle Peoplesoft_Enterprise_Peopletools_967B93A1-932E-5765-ABFF-5B9AE1C2F357

CVE-2026-35273-poc file clone the repo, cd into, run main.py file...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.8 CVE-2026-13282

CVE-2026-13282_CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via ...

Google Chrome 149.0.7827.201 CVE
MEDIUM 4.7 CVE-2026-50745

CVE-2026-50745_CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not fol...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-50744

CVE-2026-50744_CVE-2026-50744

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID ...

Revive Adserver CVE
MEDIUM 4.4 CVE-2026-50742

CVE-2026-50742_CVE-2026-50742

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issu...

Revive Adserver CVE