Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 7A2BFD33-83FB-

Exploit for OS Command Injection in Devcode Openstamanager_7A2BFD33-83FB-5B33-86D9-0CC82F7A488C

CVE-2025-69212 PoC - OpenSTAManager P7M Command Injection RCE Exploit Proof of Concept PoC exploit for CVE-2025-69212, an authenticated OS command ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 CVE-2026-58053

Gitea act_runner – Container Hardening Bypass via Workflow Container Options_CVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfi...

Gitea act_runner CVE
CRITICAL 9.4 46CC1A3B-E288-

Exploit for OS Command Injection in Devcode Openstamanager_46CC1A3B-E288-5D6F-BB8A-C0B2ECAF3AD9

CVE-2025-69212 — OpenSTAManager P7M Command Injection PoC OpenSTAManager = 2.9.8 — OS Command Injection via malicious .p7m filename in ZIP upload. ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 14E7A500-B823-

vuln-corpus_14E7A500-B823-50F2-82DC-3F9AB6556A14

Exploitarium Vulnerability Corpus Structured vulnerability dataset extracted from 23 proof-of-concept exploits. Methodology: Structured Research Re...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 2188B2BD-305E-

Exploit for CVE-2026-5366_2188B2BD-305E-5039-8E88-798A5265A54D

PoC: CVE-2026-5366 - Git Argument Injection in Prefect GitRepository - Vulnerability: git argument injection leading to RCE via commitsha plus argu...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 DE5C5932-5273-

Exploit for CVE-2026-5366_DE5C5932-5273-5F56-9465-2C4CB0B31BAF

CVE-2026-5366 PoC: CVE-2026-5366 — Git Argument Injection in Prefect GitRepository...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 7F7749F6-023B-

Exploit for Authentication Bypass Using an Alternate Path or Channel in Traefik_7F7749F6-023B-5070-9A69-60448F7E541E

CVE-2026-48020 — Traefik StripPrefix Route-Level Auth Bypass PoC A self-contained proof of concept for CVE-2026-48020, a route-level authentication...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 449EB399-8D3C-

Exploit for Improper Access Control in Widgetfactorylimited Jce_449EB399-8D3C-5528-B03B-B58DC4645B9D

MASTA CVE-2026-48907 Scanner Joomla! JCE 2.9.99.5 Unauthenticated Remote Code Execution RCE Scanner --- 🚨 LEGAL DISCLAIMER & ETHICAL USE This tool...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-12415

Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter_CVE-2026-12415

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_accou...

pravel Invoice Generator CVE
CRITICAL 9.8 CVE-2026-28701

Daktronics Controller Firmware Path Traversal_CVE-2026-28701

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and ...

Daktronics VFC-DMP-5000 CVE