Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-44976

Frappe: IDOR in update_onboarding_step_CVE-2026-44976

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue...

frappe frappe < 16.17.4 CVE
MEDIUM 5.3 CVE-2026-44975

Frappe: Missing authorization on reset form tours_CVE-2026-44975

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users...

frappe frappe < 15.107.2 CVE
MEDIUM 5.3 CVE-2026-44967

opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response_CVE-2026-44967

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full ...

open-telemetry opentelemetry-cpp < 1.27.0 CVE
MEDIUM 6.9 CVE-2026-44208

Frappe: IDOR in `submit_discussion()`_CVE-2026-44208

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint...

frappe frappe < 15.107.0 CVE
MEDIUM 6.9 CVE-2026-44207

Frappe: Insecure Direct Object Reference for email accounts_CVE-2026-44207

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to acces...

frappe frappe < 15.107.0 CVE
MEDIUM 6.9 CVE-2026-44206

Frappe: DB Schema Enumeration via Frappe-Authorization-Source_CVE-2026-44206

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an e...

frappe frappe < 15.107.2 CVE
HIGH 7.7 CVE-2026-40677

CVE-2026-40677_CVE-2026-40677

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to ...

AMD AMD Management Console (AMC) 14.0.0 CVE
HIGH 7.8 505F1E52-4323-

Exploit for CVE-2022-38694_505F1E52-4323-5C51-843E-6F1628F070BF

ZTE Blade X1001 — Root con Magisk Android 15, Unisoc UMS9230 ⚠️ ADVERTENCIA: Rootear un dispositivo puede anular la garantía, brickear el dispositi...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 EF699315-4D7C-

Exploit for Deserialization of Untrusted Data in Jenkins_EF699315-4D7C-5726-948A-21FDB30656FD

CVE-2026-53435 — Jenkins Deserialization → Arbitrary File Read PoC First public proof-of-concept for CVE-2026-53435, built when only the advisory e...

N/A N/A GITHUBEXPLOIT
NONE HACKREAD:B83FE5...

The SpaceX Pre-IPO Market: How Crypto Rails Are Opening Synthetic Access_HACKREAD:B83FE57965A4CC17D33FDC54BCD5BB32

SpaceX Pre-IPO demand is growing as crypto exchanges offer synthetic exposure to its reported $1.75T valuation without direct equity ownership.

N/A N/A HACKREAD