Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 D04820D4-9F40-

Exploit for Deserialization of Untrusted Data in Facebook React_D04820D4-9F40-5C85-B772-704D0DA3D09B

react2shell-exploit React2Shell: CVE-2025-55182 POST / HTTP/1.1 Host: localhost:3000 User-Agent: Mozilla/5.0 Windows NT 10.0; Win64; x64 AppleWebKi...

N/A N/A GITHUBEXPLOIT
LOW 2 CVE-2026-13502

antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou_CVE-2026-13502

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main...

antlr ANTLR4 4.13.0 CVE
MEDIUM 4.8 CVE-2026-13501

antlr ANTLR4 gofmt GoTarget.java GoTarget command injection_CVE-2026-13501

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/s...

antlr ANTLR4 4.13.0 CVE
MEDIUM 6.9 CVE-2026-13498

yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection_CVE-2026-13498

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php o...

yashpokharna2555 restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 CVE
MEDIUM 5.3 CVE-2026-13497

itsourcecode Hospital Management System appointment.php sql injection_CVE-2026-13497

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-13499

yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting_CVE-2026-13499

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.p...

yashpokharna2555 restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 CVE
MEDIUM 6.9 CVE-2026-13500

antlr ANTLR4 Grammar Action Block OutputFile.java code injection_CVE-2026-13500

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/Output...

antlr ANTLR4 4.13.0 CVE
HIGH 7.8 BB4649D8-A88F-

dirtyclone-exploit_BB4649D8-A88F-5CB7-A1EA-78182D4C96A8

DirtyClone Exploit Framework CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels...

N/A N/A GITHUBEXPLOIT
NONE 443EE359-CE13-

XFinder_443EE359-CE13-5055-94BC-ADC9E389907C

XFinder External Attack Surface Management EASM — a lightweight, production-ready Python CLI that continuously discovers, monitors, enriches, and t...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 9B9009B8-AC90-

Exploit for Missing Authentication for Critical Function in Rclone_9B9009B8-AC90-5EE8-BA73-9ADB1ADB091D

CVE-2026-41179 — rclone RC API Unauthenticated RCE ⚠️ EDUCATIONAL PURPOSES ONLY This repository is intended strictly for security research, educati...

N/A N/A GITHUBEXPLOIT