Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-11367

PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter_CVE-2026-11367

The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the...

andrasweb PixMagix – WordPress Image Editor CVE
MEDIUM 6.1 CVE-2026-56809

CVE-2026-56809_CVE-2026-56809

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerab...

Ricoh Company, Ltd. Multiple laser printers and MFPs which implement Ricoh Web Image Monitor see the information provided by the vendor CVE
HIGH 7.2 CVE-2026-56808

CVE-2026-56808_CVE-2026-56808

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution wi...

AVTECH Security Corporation DGM3103SCT firmware version 3.2.5.4 and prior CVE
HIGH 7.8 CVE-2026-56137

CVE-2026-56137_CVE-2026-56137

RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-fi...

Gotcha Gotcha Games Inc. RPG MAKER MV 1.6.3 and earlier CVE
HIGH 7.5 CVE-2026-14164

Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()_CVE-2026-14164

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer m...

Red Hat Red Hat Enterprise Linux 10 CVE
CRITICAL 9.3 CVE-2026-12819

DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability_CVE-2026-12819

Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticat...

deltaww DVP-12SE * CVE
CRITICAL 9.3 CVE-2026-12818

DVP-12SE Exposure of Sensitive Information Vulnerability_CVE-2026-12818

Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TC...

deltaww DVP-12SE * CVE
HIGH 8 CVE-2026-12240

Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field_CVE-2026-12240

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize func...

qlstudio Export User Data CVE
MEDIUM 6.6 CVE-2026-45822

CVE-2026-45822_CVE-2026-45822

decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decod...

SamVerschueren decode-uri-component 0.1.0 CVE
HIGH 8.4 CVE-2026-12578

DTMSoft – Deserialization of Untrusted Data Vulnerability_CVE-2026-12578

The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.

deltaww DTMSoft * CVE