Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 9B9009B8-AC90-

Exploit for Missing Authentication for Critical Function in Rclone_9B9009B8-AC90-5EE8-BA73-9ADB1ADB091D

CVE-2026-41179 — rclone RC API Unauthenticated RCE ⚠️ EDUCATIONAL PURPOSES ONLY This repository is intended strictly for security research, educati...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.3 CVE-2026-13491

78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service_CVE-2026-13491

A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/pro...

78 xiaozhi-esp32 2.2.0 CVE
MEDIUM 6.3 CVE-2026-13490

glpi-project glpi Document document.send.php canViewFile authorization_CVE-2026-13490

A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file f...

glpi-project glpi 11.0.5 CVE
LOW 2.3 CVE-2026-13489

78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization_CVE-2026-13489

A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc ...

78 xiaozhi-esp32 2.2.0 CVE
MEDIUM 5.3 CVE-2026-13496

itsourcecode Hospital Management System ajaxmedicine.php sql injection_CVE-2026-13496

A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.1 CVE-2026-13495

itsourcecode Hospital Management System adminprofile.php sql injection_CVE-2026-13495

A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The m...

itsourcecode Hospital Management System 1.0 CVE
LOW 2.3 CVE-2026-13493

AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection_CVE-2026-13493

A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversati...

AIDC-AI ComfyUI-Copilot 2.0.0 CVE
MEDIUM 6.9 CVE-2026-13486

SourceCodester Class and Exam Timetabling System preview6.php sql injection_CVE-2026-13486

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview...

SourceCodester Class and Exam Timetabling System 1.0 CVE
MEDIUM 6.9 CVE-2026-13485

SourceCodester Class and Exam Timetabling System preview.php sql injection_CVE-2026-13485

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Perfo...

SourceCodester Class and Exam Timetabling System 1.0 CVE
MEDIUM 6.9 CVE-2026-13488

SourceCodester Class and Exam Timetabling System preview7.php sql injection_CVE-2026-13488

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown fun...

SourceCodester Class and Exam Timetabling System 1.0 CVE