Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.9 0D199316-3A4E-

exploit-arsenal_0D199316-3A4E-538E-8E6B-0CDCCF55C354

CVE Proof-of-Concept Collection Clean, dependency-free Python 3 proof-of-concept exploits for recent CVEs — each with a concise write-up and a scre...

N/A N/A GITHUBEXPLOIT
NONE THN:0860E9752FE...

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT_THN:0860E9752FEC58321D74A703FD67C25B

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiENcFC1DFPXKuRCT_WmSwq-wpzC8IcZUdZzu5IHi597n77W8LFs9qSUdDPCuMK9QzkRZEBMbBh4p2xhnI1OX...

N/A N/A THN
NONE F0B8487B-7038-

ziti-security-report_F0B8487B-7038-5842-89A4-BAAAD38F8053

Ziti Admin Console — Security Report Stored XSS via Role Attributes in Data Tables - Target: ZAC 4.3.0 / Controller 2.0.0 - Type: Stored Cross-Site...

N/A N/A GITHUBEXPLOIT
NONE C347D04E-3B60-

Stored-XSS-via-Role-Attributes_C347D04E-3B60-507D-B15A-514D6C26D589

Ziti Admin Console — Security Report Stored XSS via Role Attributes in Data Tables - Target: ZAC 4.3.0 / Controller 2.0.0 - Type: Stored Cross-Site...

N/A N/A GITHUBEXPLOIT
NONE C2262463-3C54-

AntiXSS_C2262463-3C54-520E-9C2B-2D6AF1BB4E37

No description provided...

N/A N/A GITHUBEXPLOIT
NONE C622C331-EC9E-

lab-keamanan-siber_C622C331-EC9E-5098-8B21-3E03392AC9F9

Lab Keamanan Siber Web Security Testing Lab 🚀 Cara Menjalankan bash 1. Clone repo git clone https://github.com/adpermana/lab-keamanan-siber.git cd...

N/A N/A GITHUBEXPLOIT
HIGH 8.6 CVE-2026-10521

Authenticated unintended access to critical program parameters_CVE-2026-10521

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program ...

MB connect line mbCONNECT24 0.0.0, 2.20.1 CVE
HIGH 7.5 MS:CVE-2026-12455

Chromium: CVE-2026-12455 Use after free in Tab Strip_MS:CVE-2026-12455

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
NONE THN:80BBBFC9095...

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool_THN:80BBBFC909526E3068FBECD0249D285F

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDqA3duB8U44C_MQ5PM061Wch2-j7uRvX_D52lK_2Dsm2lxcquuICTnFZ-dhQiQfxxKTnIJz4tf7ffCupdko...

N/A N/A THN
CRITICAL 9.8 CVE-2026-12866

CVE-2026-12866_CVE-2026-12866

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by ...

silentmatt expr-eval CVE