Recent Advisories

Severity ID Title Vendor Product Date Type
NONE QUALYSBLOG:A246...

CERT-In’s AI Vulnerability Blueprint: Why Indian CISOs Need Machine-Speed Risk Operations in the Post-Mythos Era_QUALYSBLOG:A2463FDB3F5DB3414AFD13F999ADEC69

__A Qualys India perspective on CERT-In 's blueprint, the post-Mythos threat landscape India faces, and why the operating model needs to change.__ ...

N/A N/A QUALYSBLOG
HIGH 7.9 CVE-2026-10745

CVE-2026-10745_CVE-2026-10745

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampe...

upKeeper Solutions upKeeper Instant Privilege Access CVE
CRITICAL 9.8 61C38206-1C85-

cve-research-agent_61C38206-1C85-5ACA-A29E-1B8B1036B563

CVE Research Agent A CVE research agent built on Claude Code + MCP. Give it a CVE ID and a vulnerable source tree — it fetches the metadata, analyz...

N/A N/A GITHUBEXPLOIT
NONE THN:8A575443D93...

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering_THN:8A575443D9371D36688DCC7A80A22639

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwWpkKj6KRX5Q7jeH07PFaANRRfRbl_CdrBEZ0cypjUg2UBsy49GSGNAOXF74dDez1H9xz_FXTMWh1lziO6f...

N/A N/A THN
HIGH 8.8 C5560A1B-5696-

Exploit for CVE-2026-8461_C5560A1B-5696-5AA7-9658-FAC21FF2EC4F

cve-id ⚡ Simple Usage Use this project only in safe and authorized environments such as: - Local virtual machines - Docker containers - Isolated l...

N/A N/A GITHUBEXPLOIT
MEDIUM 4.3 CVE-2026-9724

MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update_CVE-2026-9724

The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing ...

motordesk MotorDesk CVE
MEDIUM 4.3 CVE-2026-9721

Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update_CVE-2026-9721

The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is ...

chuhpl Book a Room Event Calendar CVE
HIGH 7.2 CVE-2026-9643

WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging_CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versio...

joomunited WP Meta SEO CVE
MEDIUM 6.4 CVE-2026-9620

WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripting via Post Content Image src Attribute_CVE-2026-9620

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions ...

joomunited WP Latest Posts CVE
MEDIUM 4.3 CVE-2026-9619

Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action_CVE-2026-9619

The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is...

berfect Reviews and Rating – Docplanner CVE