Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-34114

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php_CVE-2026-34114

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"p...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34113

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php_CVE-2026-34113

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php ...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34111

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php_CVE-2026-34111

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"p...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34110

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php_CVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"ph...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34108

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php_CVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/te...

guardian language-system CVE
CRITICAL 10 CVE-2026-50160

Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite_CVE-2026-50160

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated...

hoppscotch hoppscotch <= 2026.4.1 CVE
CRITICAL 9.8 PACKETSTORM:224887

📄 Control Web Panel 0.9.8.1224 SQL Injection_PACKETSTORM:224887

Control Web Panel versions 0.9.8.1224 and below suffer from a remote SQL injection vulnerability via the userRes POST parameter...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:224888

📄 Flowise CSV Agent Prompt Injection Remote Code Execution_PACKETSTORM:224888

This vulnerability allows remote attackers to execute arbitrary code on affected installations of FlowiseAI Flowise. Authentication is not required...

N/A N/A PACKETSTORM
CRITICAL 10 18A029E5-DC15-

Exploit for OS Command Injection in Ivanti Standalone_Sentry_18A029E5-DC15-55E3-8F96-74EF57438AD2

spryCVE-2026-10520...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 THN:B594E284DB7...

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic_THN:B594E284DB7F72F8A59DA8176E394344

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiP2LpF3s-oL3WaiHtAZ9N33J120bvGnWDoQ39eE1fyToERHmJgkAtMzarRyW9-gOG0N4U1_nOEQmwg-3krYI...

N/A N/A THN