Recent Advisories

Severity ID Title Vendor Product Date Type
NONE JAKEARCHIBALD:0...

The Goldilocks customizable select height_JAKEARCHIBALD:097FA566D8C7BEEB98D0851DF5C8AE8E

I recently gave a talk on customizable (as in fully-stylable) ``, and as I was building demos I realised there's a sizing 'pattern' that's almost a...

N/A N/A JAKEARCHIBALD
CRITICAL 9.8 THN:7CA247FF7A5...

⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More_THN:7CA247FF7A5A4532948A0B8472403FAD

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFXmUW2VYnBd5oSyq6V328rZOIdanacqm-k4Wae2x53iAvPb7YvO7rqDcfWTklR_skhgLDVTThASQvf4UATg...

N/A N/A THN
NONE THN:AC85ADACAC8...

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks_THN:AC85ADACAC83FA5BD2439FA2B651A2E8

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4479X60pqma2HNkNzrVQuQlGImd-48w4eYTTW-wylTLfK7XfLPtmNOMi79oy48LNiFg-4a_vqF378ZobR2D...

N/A N/A THN
CRITICAL 9.4 AAF2A134-2B57-

Exploit for CVE-2026-28496_AAF2A134-2B57-5561-9F7C-FCB30165A305

CVE-2026-28496 - FOSSBilling Server-Side Template Injection in Twig Rendering Executive Summary This repository contains a local Docker lab for rep...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 D6BE3E6D-83D1-

Exploit for Improper Authentication in Oracle Concurrent_Processing_D6BE3E6D-83D1-5B93-B9FA-A5D29193B757

markdown CVE-2025-61882 – Oracle E-Business Suite Remote Code Execution Unauthenticated Eksploitasi zero-click, pre-authentication pada Oracle E-Bu...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.5 CVE-2026-39031

CVE-2026-39031_CVE-2026-39031

Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character pref...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-38641

CVE-2026-38641_CVE-2026-38641

An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted share...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-38639

CVE-2026-38639_CVE-2026-38639

An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a ...

n/a n/a n/a CVE
MEDIUM 4.3 CVE-2026-56457

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information_CVE-2026-56457

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an at...

HCLSoftware HCL DevOps Deploy / HCL Launch 7.3-7.3.2.18, 8.0-8.0.1.13, 8.1-8.1.2.6, 8.2-8.2.1.0 CVE
HIGH 8.4 CVE-2026-54371

attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr_CVE-2026-54371

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate...

acl project acl CVE