Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 783676F7-7FF1-

Exploit for Authentication Bypass by Spoofing in Alibaba Nacos_783676F7-7FF1-5239-9717-0FFAAC5D8271

CVE-2021-29441...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 0452174E-CA14-

Exploit for CVE-2026-48908_0452174E-CA14-5E07-832F-D7B7BBD5B889

🚨 CVE-2026-48908 — Full Server Compromise via Arbitrary File Upload Critical Unauthenticated File Upload → Remote Code Execution RCE A critical vu...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-39893

Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php_CVE-2026-39893

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated int...

Cacti cacti < 1.2.31 CVE
CRITICAL 9.8 CVE-2026-39938

Cacti: Unauthenticated RCE on Graph Image_CVE-2026-39938

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdt...

Cacti cacti < 1.2.31 CVE
CRITICAL 9.8 CVE-2026-39955

Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php_CVE-2026-39955

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored ...

Cacti cacti < 1.2.31 CVE
CRITICAL 9.3 CVE-2026-39948

Cacti has SQL Injection via rfilter parameter in RLIKE clauses_CVE-2026-39948

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via th...

Cacti cacti < 1.2.31 CVE
CRITICAL 9.9 1D800BD3-189F-

Exploit for CVE-2026-38526_1D800BD3-189F-5EE9-BFBA-BC99C4EB9527

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 D6143492-FDD6-

Exploit for Unrestricted Upload of File with Dangerous Type in Gvectors Wpdiscuz_D6143492-FDD6-5B65-991B-5C7A537B4D18

CVE-2020-24186 Exploit para RCE Remote Code Exec CVE de plugin vulnerable en Wordpress WP-Discuz en versión 7.0.4...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 CVE-2026-52806

Gogs: RCE via git rebase –exec argument injection in pull request merge_CVE-2026-52806

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the serv...

gogs gogs < 0.14.3 CVE
CRITICAL 10 CVE-2026-52813

Gogs: Path Traversal in organization name results in RCE through Git hooks_CVE-2026-52813

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs,...

gogs gogs < 0.14.3 CVE