Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2025-66391

CVE-2025-66391_CVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system...

n/a n/a n/a CVE
MEDIUM 6 CVE-2026-55748

CVE-2026-55748_CVE-2026-55748

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. ...

OpenStack Horizon 8.0.0 CVE
CRITICAL 9.6 CVE-2026-55743

OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution_CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypass...

tinyhumansai OpenHuman CVE
CRITICAL 9.3 CVE-2026-54812

WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability_CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Inject...

StylemixThemes Motors n/a CVE
HIGH 7.5 CVE-2026-54810

WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability_CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

Nexi Payments Nexi XPay n/a CVE
HIGH 8.1 CVE-2026-54415

Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover_CVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authentica...

Azuriom Azuriom CMS CVE
HIGH 7.4 CVE-2026-49502

CVE-2026-49502_CVE-2026-49502

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent netwo...

Dell PowerFlex CVE
MEDIUM 4.8 CVE-2026-48142

NGINX ngx_http_charset_module vulnerability_CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location b...

F5 NGINX Open Source 1.13.10 CVE
MEDIUM 6.8 CVE-2026-48117

DroneAware’s Improper Account Activation in Registration and SSO Flows Leads to Account Takeover_CVE-2026-48117

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack...

fduflyer DroneAware-Node-Releases < server-2026-05-20 CVE
CRITICAL 9.3 CVE-2026-47103

Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection_CVE-2026-47103

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by s...

fgmacedo python-statemachine 3.0.0 CVE