Recent Advisories

Severity ID Title Vendor Product Date Type
NONE C3D0F122-BC3F-

Grimoire_C3D0F122-BC3F-5AAC-9F18-FA8CB3F96BF4

書 — The Pentesterʼs Spellbook Answer the questions. Unleash the test cases. --- What is Grimoire? A grimoire is a spellbook — a compendium of know...

N/A N/A GITHUBEXPLOIT
HIGH 7.7 THN:C70D8BC2816...

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting_THN:C70D8BC28161A5329790CE84AF7C8F85

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpiAGZTnvo43enaVYkna4ZSp217mwwW5kW8kZOhaSiLAxicjvHQY-3d8rdLN47bsRvxUIj6R0h_Ttr8NcIJr...

N/A N/A THN
MEDIUM 6.5 CVE-2026-50892

CVE-2026-50892_CVE-2026-50892

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obta...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-50891

CVE-2026-50891_CVE-2026-50891

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-50881

CVE-2026-50881_CVE-2026-50881

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator ...

n/a n/a n/a CVE
MEDIUM 5.4 CVE-2026-50876

CVE-2026-50876_CVE-2026-50876

A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-50875

CVE-2026-50875_CVE-2026-50875

Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or d...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-50874

CVE-2026-50874_CVE-2026-50874

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arb...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-39197

CVE-2026-39197_CVE-2026-39197

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted req...

n/a n/a n/a CVE
HIGH 8.4 CVE-2026-39118

CVE-2026-39118_CVE-2026-39118

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restric...

n/a n/a n/a CVE