Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-54889

Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)_CVE-2026-54889

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL s...

leandrocp mdex 0.8.3 CVE
MEDIUM 6.9 CVE-2026-54888

Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex_CVE-2026-54888

Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex converts between an Elixir ...

leandrocp mdex 0.3.0 CVE
MEDIUM 6.9 CVE-2026-53429

Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service_CVE-2026-53429

Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker who controls a rendered docum...

leandrocp mdex 0.11.0 CVE
HIGH 8.2 CVE-2026-53426

Atom-table exhaustion denial-of-service via JSON parse_document in MDEx_CVE-2026-53426

Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a ...

leandrocp mdex 0.4.3 CVE
HIGH 7.8 CVE-2026-57919

CVE-2026-57919_CVE-2026-57919

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ...

n/a n/a n/a CVE
CRITICAL 9.6 CVE-2026-57498

Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams’ Servers_CVE-2026-57498

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controll...

coollabsio coolify < 4.0.0-beta.474 CVE
CRITICAL 9.8 CVE-2026-13763

HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF_CVE-2026-13763

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF ma...

AWS AWS Application Load Balancer CVE
CRITICAL 9.8 CVE-2026-13762

HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF_CVE-2026-13762

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule b...

AWS Amazon CloudFront CVE
NONE THN:C8391FC028E...

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input_THN:C8391FC028E73E226BA3BA54EF61F2E4

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOcObOpyIQZzuiNoFu6Lv4jCDh64o1WYrC3stGdk58mMRg69RT56svVrXVwu618f6szk2lj_Tqbt6b7Rg25y...

N/A N/A THN
NONE 0E17DEF0-1222-

xss_writte_up_0E17DEF0-1222-52CC-A48C-346FDC06E436

Bug-Bounty-Writeups...

N/A N/A GITHUBEXPLOIT