Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 CVE-2026-8797

CVE-2026-8797_CVE-2026-8797

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary co...

NEC Corporation ExpressUpdate Agent for Windows 3.24 and prior CVE
CRITICAL 9.8 967B93A1-932E-

Exploit for Missing Authentication for Critical Function in Oracle Peoplesoft_Enterprise_Peopletools_967B93A1-932E-5765-ABFF-5B9AE1C2F357

CVE-2026-35273-poc file clone the repo, cd into, run main.py file...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.8 CVE-2026-13282

CVE-2026-13282_CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via ...

Google Chrome 149.0.7827.201 CVE
MEDIUM 4.7 CVE-2026-50745

CVE-2026-50745_CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not fol...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-50744

CVE-2026-50744_CVE-2026-50744

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID ...

Revive Adserver CVE
MEDIUM 4.4 CVE-2026-50742

CVE-2026-50742_CVE-2026-50742

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issu...

Revive Adserver CVE
HIGH 8.8 CVE-2026-50741

CVE-2026-50741_CVE-2026-50741

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by s...

Revive Adserver CVE
MEDIUM 6.1 CVE-2026-50740

CVE-2026-50740_CVE-2026-50740

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged use...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-50739

CVE-2026-50739_CVE-2026-50739

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and tra...

Revive Adserver CVE
LOW 3.3 CVE-2026-48936

CVE-2026-48936_CVE-2026-48936

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. T...

nodejs node 26.3.0 CVE