Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2026-53426

Atom-table exhaustion denial-of-service via JSON parse_document in MDEx_CVE-2026-53426

Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a ...

leandrocp mdex 0.4.3 CVE
HIGH 7.8 CVE-2026-57919

CVE-2026-57919_CVE-2026-57919

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ...

n/a n/a n/a CVE
CRITICAL 9.6 CVE-2026-57498

Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams’ Servers_CVE-2026-57498

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controll...

coollabsio coolify < 4.0.0-beta.474 CVE
CRITICAL 9.8 CVE-2026-13763

HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF_CVE-2026-13763

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF ma...

AWS AWS Application Load Balancer CVE
CRITICAL 9.8 CVE-2026-13762

HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF_CVE-2026-13762

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule b...

AWS Amazon CloudFront CVE
NONE THN:C8391FC028E...

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input_THN:C8391FC028E73E226BA3BA54EF61F2E4

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOcObOpyIQZzuiNoFu6Lv4jCDh64o1WYrC3stGdk58mMRg69RT56svVrXVwu618f6szk2lj_Tqbt6b7Rg25y...

N/A N/A THN
NONE 0E17DEF0-1222-

xss_writte_up_0E17DEF0-1222-52CC-A48C-346FDC06E436

Bug-Bounty-Writeups...

N/A N/A GITHUBEXPLOIT
NONE E6D0A451-B59B-

protection_E6D0A451-B59B-5672-A0DD-F0FAC9CFACFB

🛡️ protection Kernel-level abuse protection for container hosts One static Go binary that guards Pterodactyl/Wings nodes, Docker hosts and bare VPS...

N/A N/A GITHUBEXPLOIT
HIGH 8.3 CVE-2026-57960

Hi.Events 1.9.0 – Unauthenticated Attendee PII Exposure via Check-in List short_id_CVE-2026-57960

Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attend...

HiEventsDev Hi.Events CVE
HIGH 8.2 CVE-2026-57959

Hi.Events 1.9.0 – Promo Code Max-Usage Bypass via Asynchronous Job Race Condition_CVE-2026-57959

Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStati...

HiEventsDev Hi.Events CVE