Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security_CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from ...

wolfSSL wolfSSL 5.7.0 CVE
MEDIUM 6.3 1455C226-77CD-

Exploit for Improper Authentication in Google Android_1455C226-77CD-5803-A0CE-7D7BC815D6F6

BlueDucky Ver 2.1 Android 🦆 Thanks to all the people at HackNexus. Make sure you come join us on VC ! https://discord.gg/HackNexus NOTES: I will n...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 PACKETSTORM:224334

đź“„ Dalfox Found-Action Deserialization Remote Code Execution_PACKETSTORM:224334

When dalfox versions less than or equal to 2.12.0 is started in REST API server mode dalfox server, the server binds to 0.0.0.0:6664 by default and...

N/A N/A PACKETSTORM
NONE MSSECURE:9CD4AE...

Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms_MSSECURE:9CD4AE8F9F47AF1696C23F8E30078560

The endpoint management category is being redefined in real time. Organizations no longer need tools that only inventory devices or enforce configu...

N/A N/A MSSECURE
NONE SCHNEIER:241805...

AI and Liability_SCHNEIER:24180570FA25CD366F3C4BC1B6F703A6

Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like "users can check for themselves...

N/A N/A SCHNEIER
NONE HACKREAD:C879C0...

Fake GTA 6 Early Access Websites Target Gamers with Malware and Crypto Scams_HACKREAD:C879C04F7479896AF809D522E0B323F4

GTA 6 scams are luring fans with fake early access, crypto payments and malware downloads. Learn why PC and Android gamers face the biggest risks o...

N/A N/A HACKREAD
HIGH 7.5 CVE-2025-61027

CVE-2025-61027_CVE-2025-61027

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61023

CVE-2025-61023_CVE-2025-61023

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-48942

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

getk2.com K2 extension for Joomla 1.0-2.26 CVE
HIGH 8.1 CVE-2026-9800

Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison_CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role...

Red Hat Red Hat Build of Keycloak CVE