Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 CVE-2026-44089

Buffer Overflow in Totolink EX1200L router_CVE-2026-44089

Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be ex...

Totolink EX1200L 9.3.5u.6146_B20201023 CVE
CRITICAL 9 CVE-2026-11374

Account Takeover via Predictable SSO Ticket Generation_CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that sessi...

zohocorp manageengine_adselfservice_plus CVE
CRITICAL 9.9 0D199316-3A4E-

exploit-arsenal_0D199316-3A4E-538E-8E6B-0CDCCF55C354

CVE Proof-of-Concept Collection Clean, dependency-free Python 3 proof-of-concept exploits for recent CVEs — each with a concise write-up and a scre...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-12866

CVE-2026-12866_CVE-2026-12866

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by ...

silentmatt expr-eval CVE
CRITICAL 9.8 E92487F1-C41D-

Exploit for CVE-2020-11651_E92487F1-C41D-50E2-969D-FE49942DB8B4

This is an updated verison original git clone https://github.com/jasperla/CVE-2020-11651-poc.git cd CVE-2020-11651-poc when i was using original i ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 DF994407-02A8-

Exploit for Path Traversal in Apache Http_Server_DF994407-02A8-5D7C-9D23-8887B2A2951D

CVE-2021-41773 — PoC: Path Traversal + RCE via modcgi Solo para uso en entornos controlados y propios. No usar contra sistemas sin autorización. --...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 CVE-2026-48746

vLLM: OpenAI auth bypass_CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlett...

vllm-project vllm >= 0.3.0, < 0.22.0 CVE
CRITICAL 9.5 CVE-2026-49468

LiteLLM: Authentication Bypass via Host Header Injection_CVE-2026-49468

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0.

BerriAI litellm < 1.84.0 CVE
CRITICAL 9.2 CVE-2026-45034

PhpSpreadsheet: File::prohibitWrappers bypass_CVE-2026-45034

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::pro...

PHPOffice PhpSpreadsheet < 1.30.5 CVE
CRITICAL 9.3 CVE-2026-44727

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP_CVE-2026-44727

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored noteb...

jupyter-server jupyter_server < 2.20 CVE