Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:223627

📄 CMSsiam 2 SQL Injection_PACKETSTORM:223627

CMSsiam version 2 suffers from a remote SQL injection vulnerability that allows for login bypass...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:223698

📄 Discuz! X5.0 Local File Inclusion_PACKETSTORM:223698

This is a Metasploit auxiliary module targeting a local file inclusion vulnerability in Discuz! X5.0...

N/A N/A PACKETSTORM
NONE PACKETSTORM:223619

📄 CMS SINDEHOTÉIS 1.2.4 Cross Site Request Forgery_PACKETSTORM:223619

CMS SINDEHOT�IS version 1.2.4 suffers from a cross site request forgery vulnerability...

N/A N/A PACKETSTORM
CRITICAL 9.4 PACKETSTORM:223657

📄 dedoc/scramble 0.13.2 Remote Code Execution_PACKETSTORM:223657

This is a Metasploit exploit module for CVE-2026-44262, an unauthenticated remote code execution vulnerability in the Laravel-based tool dedoc/scra...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:223682

📄 Discuz! X5.0 Chained Remote Code Execution_PACKETSTORM:223682

This Metasploit module uses race condition and local file inclusion vulnerabilities in Discuz! X5.0 in order to achieve remote code execution...

N/A N/A PACKETSTORM
NONE E0E5A159-B9FC-

Exploit for CVE-2026-36425_E0E5A159-B9FC-5F80-8823-08B2D5FD8E7A

CVE-2026-36425 — OPSWAT AppRemover Driver ardrv.sys Improper Access Control | | | |---|---| | CVE ID | CVE-2026-36425 | | Vendor | OPSWAT, Inc. | |...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 5084DB54-3051-

Exploit for CVE-2026-49083_5084DB54-3051-5625-ADF2-00307974C4D8

CVE-2026-49083 CVE-2026-49083 LatePoint Calendar Booking Plugin Privilege Escalation Exploit 🎲🎲🎲...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 AE6219F6-F23B-

Exploit for CVE-2026-48907_AE6219F6-F23B-5FB3-886B-AFFE2FBDB4B1

CVE-2026-48907 CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2025-66391

CVE-2025-66391_CVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system...

n/a n/a n/a CVE
MEDIUM 6 CVE-2026-55748

CVE-2026-55748_CVE-2026-55748

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. ...

OpenStack Horizon 8.0.0 CVE