Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-20746

PingDirectory copying of virtual attributes leads to memory exhaustion_CVE-2026-20746

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent...

Ping Identity PingDirectory 9.3.0.0 CVE
HIGH 8.7 CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing_CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Un...

CyberArk Software, a Palo Alto Networks Company PAM SH Vault 14.0 CVE
HIGH 7.5 CVE-2026-44892

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size_CVE-2026-44892

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration ...

netty netty >= 4.2.0.Final, < 4.2.15.Final CVE
HIGH 10 640E6781-DC00-

ethical-hacking-security-labs_640E6781-DC00-5CC2-88A5-C12AFFCA478B

Ethical Hacking & Network Security Lab Portfolio A hands-on security lab portfolio demonstrating practical skills in network reconnaissance, vulner...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 01066642-42B4-

linux-privesc-linpeas_01066642-42B4-57AB-A419-1FB04F7914B5

🐧 linux-privesc-linpeas End-to-end Linux privilege escalation toolset — suitable for penetration testing, CTF challenges, and red team evaluations...

N/A N/A GITHUBEXPLOIT
NONE 6C8F2BDF-C903-

websec-skills_6C8F2BDF-C903-5D95-9EEA-4370317A8B23

websec-skills Web Security Vulnerability Testing Skills Set, including attack playbooks for 44 types of vulnerabilities, used for AI Agent-assisted...

N/A N/A GITHUBEXPLOIT
MEDIUM 4.3 8E7576F6-458D-

Exploit for CVE-2026-46645_8E7576F6-458D-5824-819E-FC7C2BCB6824

CVE-2026-46645 - SQLAdmin ajaxlookup Authorization Bypass Executive Summary This repository contains a local Docker lab for reproducing CVE-2026-46...

N/A N/A GITHUBEXPLOIT
HIGH 8.3 CVE-2026-12034

CVE-2026-12034_CVE-2026-12034

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who...

Google Chrome 149.0.7827.115 CVE
MEDIUM 5.3 CVE-2026-12033

CVE-2026-12033_CVE-2026-12033

Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain...

Google Chrome 149.0.7827.115 CVE
LOW 3.1 CVE-2026-12032

CVE-2026-12032_CVE-2026-12032

Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the ren...

Google Chrome 149.0.7827.115 CVE