Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 CVE-2026-49194

SCREEN_CLICK Authentication Bypass_CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive s...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.3 CVE-2026-49191

Exposed Hard-coded M3WebServer Backend API Key_CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.4 CVE-2026-49190

Missing Per-Instruction Authorization Checks_CVE-2026-49190

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application instal...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.8 021063E9-0EFC-

Exploit for SQL Injection in Wpdeveloper Notificationx_021063E9-0EFC-5BB3-A717-3C9223961E61

CVE-2024-1698 – NotificationX WordPress Plugin SQL Injection Time‑Based Blind Unauthenticated Time‑Based Blind SQL Injection → Extract admin userna...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 CVE-2026-49185

Instruction Injection via FieldX MDM_CVE-2026-49185

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.9 CVE-2026-41283

CVE-2026-41283_CVE-2026-41283

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, whi...

OpenStack Mistral 20.0.0 CVE
CRITICAL 9.2 A68A628E-AB61-

Exploit for CVE-2026-42945_A68A628E-AB61-551B-9ECD-769EA5A45A85

nginx-rift-scanner Dependency-free Python 3 scanner for CVE-2026-42945 "NGINX Rift" — a CVSS v4.0 9.2 CRITICAL heap-based buffer overflow CWE-122 i...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 3BCADBAC-E6C7-

Exploit for Prototype Pollution in Cure53 Dompurify_3BCADBAC-E6C7-5B3A-84E1-6938398220F9

DOMPurify re-clone bypass. Instead of relying on easily stripped source comments or version variables, this tool performs logic fingerprinting on m...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.2 8AD1A192-E34A-

Exploit for CVE-2026-42945_8AD1A192-E34A-5E8C-A3B9-4AAECCED2A20

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-38967

CVE-2026-38967_CVE-2026-38967

CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

CrowCpp CrowCpp Crow v1.3.1 CVE