Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 D039E607-9443-

Exploit for Use After Free in Linux Linux_Kernel_D039E607-9443-53D4-AA20-578FC0282FE1

CVE-2026-23111 nftables LPE: exposure check and safe lab Defensive tooling and a reproducible virtual-machine lab for CVE-2026-23111, the nftables ...

N/A N/A GITHUBEXPLOIT
HIGH 8.1 236C3334-CF38-

Exploit for CVE-2026-10795_236C3334-CF38-5100-98AA-1DF6189FF3D2

CVE-2026-10795 UpdraftPlus Auto-Exploit & Mass Scanner Authorized Use Only — This tool is provided for authorized penetration testing, security res...

N/A N/A GITHUBEXPLOIT
NONE 2777ACBF-D21B-

OSCP-PEN200_2777ACBF-D21B-5A7D-B555-B04B9386E9B2

🛡️ OSCP / PEN-200 Master Pentesting Database 📖 Overview This repository serves as my Master Study Database for the OffSec PEN-200 OSCP course. It ...

N/A N/A GITHUBEXPLOIT
NONE 158DF90B-E6C6-

network-intrusion-detector_158DF90B-E6C6-5560-AE00-C499B6DD4D07

network-intrusion-detector A Python tool that analyses web server access logs and flags suspicious activity. It looks for patterns that typically i...

N/A N/A GITHUBEXPLOIT
HIGH 7.1 CVE-2026-8406

openSIS Classic 9.3 – Insecure Direct Object Reference in Sent Mail_CVE-2026-8406

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the m...

OS4ED openSIS-Classic 9.3 CVE
MEDIUM 4.9 CVE-2026-6338

HTTP request smuggling in Kong Enteprise Gateway_CVE-2026-6338

A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vuln...

Kong Kong Enterprise Gateway 3.4.0.0 CVE
MEDIUM 5.8 CVE-2026-53723

guzzlehttp/guzzle-services’ XML Request Serialization Vulnerable to XML Injection via CDATA Terminator_CVE-2026-53723

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize ...

guzzle guzzle-services < 1.5.4 CVE
HIGH 8.8 CVE-2026-53661

boruta-server sent sensitive session cookies without the Secure attribute_CVE-2026-53661

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior ...

malach-it boruta-server < 0.9.1 CVE
HIGH 8.1 CVE-2026-11816

Path Traversal in keras-team/keras_CVE-2026-11816

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils....

keras-team keras-team/keras unspecified CVE
HIGH 7.8 CVE-2026-10847

Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS_CVE-2026-10847

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to exe...

checkpoint Identity Agent Versions prior to 81.087.0000 CVE