Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.1 CVE-2026-4983

CVE-2026-4983_CVE-2026-4983

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml withou...

Eclipse Foundation Eclipse Open VSX 0.1.0 CVE
NONE H1:3817602

Node.js: Node –run POSIX positional argument escaping allows shell command injection_H1:3817602

# ## Summary Node.js `node --run -- ` attempts to append positional arguments to a package script after escaping each argument for the shell. ...

N/A N/A HACKERONE
NONE 2E49ED4C-95C2-

xss-popup_2E49ED4C-95C2-540D-893B-E9DF48B970B0

No description provided...

N/A N/A GITHUBEXPLOIT
NONE MALWAREBYTES:7C...

GTA 6 early access is nothing but a scam_MALWAREBYTES:7CB2ABF9358B2CC6AB7D7DF22F16C745

A new wave of scam websites is offering something millions of people want: a way to play Grand Theft Auto VI before it comes out. _" Get GTA 6 be...

N/A N/A MALWAREBYTES
CRITICAL 9 CVE-2026-11374

Account Takeover via Predictable SSO Ticket Generation_CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that sessi...

zohocorp manageengine_adselfservice_plus CVE
CRITICAL 9.9 0D199316-3A4E-

exploit-arsenal_0D199316-3A4E-538E-8E6B-0CDCCF55C354

CVE Proof-of-Concept Collection Clean, dependency-free Python 3 proof-of-concept exploits for recent CVEs — each with a concise write-up and a scre...

N/A N/A GITHUBEXPLOIT
NONE THN:0860E9752FE...

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT_THN:0860E9752FEC58321D74A703FD67C25B

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiENcFC1DFPXKuRCT_WmSwq-wpzC8IcZUdZzu5IHi597n77W8LFs9qSUdDPCuMK9QzkRZEBMbBh4p2xhnI1OX...

N/A N/A THN
NONE F0B8487B-7038-

ziti-security-report_F0B8487B-7038-5842-89A4-BAAAD38F8053

Ziti Admin Console — Security Report Stored XSS via Role Attributes in Data Tables - Target: ZAC 4.3.0 / Controller 2.0.0 - Type: Stored Cross-Site...

N/A N/A GITHUBEXPLOIT
NONE C347D04E-3B60-

Stored-XSS-via-Role-Attributes_C347D04E-3B60-507D-B15A-514D6C26D589

Ziti Admin Console — Security Report Stored XSS via Role Attributes in Data Tables - Target: ZAC 4.3.0 / Controller 2.0.0 - Type: Stored Cross-Site...

N/A N/A GITHUBEXPLOIT
NONE C2262463-3C54-

AntiXSS_C2262463-3C54-520E-9C2B-2D6AF1BB4E37

No description provided...

N/A N/A GITHUBEXPLOIT