Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 E92487F1-C41D-

Exploit for CVE-2020-11651_E92487F1-C41D-50E2-969D-FE49942DB8B4

This is an updated verison original git clone https://github.com/jasperla/CVE-2020-11651-poc.git cd CVE-2020-11651-poc when i was using original i ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 DF994407-02A8-

Exploit for Path Traversal in Apache Http_Server_DF994407-02A8-5D7C-9D23-8887B2A2951D

CVE-2021-41773 — PoC: Path Traversal + RCE via modcgi Solo para uso en entornos controlados y propios. No usar contra sistemas sin autorización. --...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 CVE-2026-48746

vLLM: OpenAI auth bypass_CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlett...

vllm-project vllm >= 0.3.0, < 0.22.0 CVE
CRITICAL 9.5 CVE-2026-49468

LiteLLM: Authentication Bypass via Host Header Injection_CVE-2026-49468

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0.

BerriAI litellm < 1.84.0 CVE
CRITICAL 9.2 CVE-2026-45034

PhpSpreadsheet: File::prohibitWrappers bypass_CVE-2026-45034

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::pro...

PHPOffice PhpSpreadsheet < 1.30.5 CVE
CRITICAL 9.3 CVE-2026-44727

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP_CVE-2026-44727

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored noteb...

jupyter-server jupyter_server < 2.20 CVE
CRITICAL 9.2 CVE-2026-56266

Crawl4AI – Server-Side Request Forgery via Direct Crawl Endpoints_CVE-2026-56266

Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitra...

unclecode Crawl4AI 0.8.7 CVE
CRITICAL 9.3 4DC88245-D5D6-

Exploit for CVE-2026-49772_4DC88245-D5D6-582C-AA2B-EE9293E136F3

The Events Calendar SQL Injection CVE-2026-49772 PoC Description CVE-2026-49772 is an unauthenticated blind SQL injection in the WordPress plugin T...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.3 PACKETSTORM:224001

📄 Worksnaps.net Worksnaps Hardcoded Root Cloud Credentials_PACKETSTORM:224001

Silver Leaf Technologies - Worksnaps.net Worksnaps suffers from a hardcoded credential vulnerability. Several application binaries contained hardco...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:223999

📄 Sprecher Automation SPRECON-E-C/-E-P/-E-T3 Missing Secure-Boot / Static Passwords_PACKETSTORM:223999

Sprecher Automation SPRECON-E-C/-E-P/-E-T3 leaks the firmware signing private key, is missing a secure-boot mechanism, has unencrypted flash memory...

N/A N/A PACKETSTORM