Recent Advisories

Severity ID Title Vendor Product Date Type
NONE FA525CC7-835B-

security-disclosures-2026_FA525CC7-835B-51B6-9719-F6EE350F03DF

Security Disclosures 2026 Responsible vulnerability disclosures in open-source PHP web applications. Researcher: @abdurazzoqovjavohir700-dev Email:...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 78CF8AD6-3E6A-

ghost-bits-toolkit_78CF8AD6-3E6A-58B5-B3C4-2D259401D82F

Ghost Bits Toolkit Java Ghost Bits Vulnerability Detection and Exploitation Toolset. Vulnerability Background Ghost Bits is a security vulnerabilit...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 703A79DC-60E9-

Exploit for Improper Authorization in Apache Tomcat_703A79DC-60E9-5AC8-928B-96E9607FCF0C

CVE-2026-43515 — Apache Tomcat Security Constraint Bypass Exploitability verdict: confirmed exploitable. A POST request to a resource protected by ...

N/A N/A GITHUBEXPLOIT
NONE HACKREAD:8FE052...

Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse_HACKREAD:8FE05235876A6518DDB5C5AD824D1BA9

Nintendo America employee records were exposed via TinyPulse after Shadowbyt3 claimed theft of HR files, tax forms, bank data, and staff survey res...

N/A N/A HACKREAD
NONE HACKREAD:B8C2FC...

Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections_HACKREAD:B8C2FC2FFB391B581361B7B7294A172D

Luxembourg, Luxembourg, 19th June 2026, CyberNewswire

N/A N/A HACKREAD
NONE THN:317DE22F4DA...

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution_THN:317DE22F4DAC6034658E5E5B0FCABAED

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3wJOg5Y5vAn_dM0DcIB6SwV2B34iO0H-moeyuWLJ_DF1KgEEZMBGtKPDXYk0pL4wclWbnSmOB74sqReSZoG...

N/A N/A THN
MEDIUM 6.9 CVE-2026-55205

Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint_CVE-2026-55205

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that all...

nesquena hermes-webui CVE
HIGH 8.7 CVE-2026-55204

HAProxy – NULL Pointer Dereference in hpack_dht_insert Function_CVE-2026-55204

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c tha...

haproxy haproxy CVE
CRITICAL 9 CVE-2026-55203

HAProxy – Integer Overflow in FCGI Demux Record Length Field_CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffe...

haproxy haproxy CVE
MEDIUM 4.7 CVE-2026-54106

U.S. GAO EPDS and CBCA EDS network access control bypass_CVE-2026-54106

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE