Recent Advisories

Severity ID Title Vendor Product Date Type
NONE 27DB8220-5954-

xss-cheatsheet_27DB8220-5954-5EDF-96EC-A9636942C1FD

⚡ XSS Cheatsheet — Cross-Site Scripting Reference The most comprehensive XSS reference on GitHub. Reflected · Stored · DOM · Blind XSS — payloads,...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 8213BCAE-4E79-

Exploit for CVE-2026-46331_8213BCAE-4E79-5E25-9642-230C8D3F7823

CVE-2026-46331 pedit COW – Linux LPE Validation and auditd/AppArmor Detection Defensive validation report for CVE-2026-46331, focused on Linux kern...

N/A N/A GITHUBEXPLOIT
NONE 2F4AD28B-0185-

Exploit for CVE-2025-40271_2F4AD28B-0185-5E6A-97A3-F946B6EE5612

CVE-2025-40271 — procreaddirde rb-tree UAF LPE Proof-of-concept for a local privilege escalation vulnerability in the Linux kernel proc filesystem....

N/A N/A GITHUBEXPLOIT
HIGH 8.8 6210915C-9723-

Exploit for XML Injection (aka Blind XPath Injection) in Samlify_Project Samlify_6210915C-9723-542E-AAB3-1FFADF0E92C4

CVE-2026-46490 — samlify SAML AttributeValue XML Injection → Privilege Escalation samlify contexts. A user-controlled value e.g. email / name place...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-44948

Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler_CVE-2026-44948

A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0...

SUSE Rancher 0.12.0 CVE
MEDIUM 4.3 CVE-2026-13455

PostgreSQL Anonymizer: Unrestricted function can leak the secret salt_CVE-2026-13455

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed...

DALIBO PostgreSQL Anonymizer 1 CVE
MEDIUM 6.5 CVE-2026-9263

Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets_CVE-2026-9263

The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO...

zephyrproject zephyr 3.3.0 CVE
HIGH 7.3 CVE-2026-8864

HP Fan Control App – Potential Escalation of Privilege_CVE-2026-8864

The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mit...

HP Inc. HP Fan Control App CVE
HIGH 8.1 CVE-2026-58377

JeecgBoot 3.9.2 – Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys_CVE-2026-58377

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, ...

jeecgboot JeecgBoot CVE
HIGH 7.6 CVE-2026-58376

Dolibarr – SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints_CVE-2026-58376

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrar...

Dolibarr dolibarr CVE