Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.9 CVE-2026-43986

Tautulli vulnerable to unauthenticated SSRF in /image/ via attacker-seeded image hash replay_CVE-2026-43986

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/` route that resolv...

Tautulli Tautulli < 2.17.1 CVE
CRITICAL 9 CVE-2026-10868

MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification_CVE-2026-10868

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController...

misp misp CVE
CRITICAL 9.8 PACKETSTORM:222633

πŸ“„ WordPress ARMember Premium 7.3.1 Insecure Password Reset_PACKETSTORM:222633

WordPress ARMember Premium plugin versions 7.3.1 and below suffer from an insecure password reset mechanism that allows for administrative account ...

N/A N/A PACKETSTORM
CRITICAL 9.8 608C7C1A-97A1-

Exploit for Stack-based Buffer Overflow in Microsoft_608C7C1A-97A1-5E81-B84A-32A69CDBDD74

CVE-2026-41089 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•— β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•— β–ˆβ–ˆβ•— β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β• β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β•š...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 0741E52B-D558-

Exploit for Deserialization of Untrusted Data in Presstigers Simple_Job_Board_0741E52B-D558-58DC-BF9C-0A4B84B06668

CVE-2024-1813 - Simple Job Board ≀ 2.11.0 WordPress - Unauthenticated PHP Object Injection πŸŽ₯ Proof-of-Concept demo End-to-end: a guest stores a se...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.6 CVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF_CVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary c...

Progress Software LoadMaster V7.2.60.0 CVE
CRITICAL 10 34F15F9E-3DE3-

Exploit for CVE-2026-34234_34F15F9E-3DE3-5F98-9A00-51E6DAA3B16B

CVE-2026-34234 - CtrlPanel Installer RCE Lab Local Docker lab for demonstrating CVE-2026-34234 in CtrlPanel. This repository compares: - vuln: Ctrl...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-4104

SQLi in Akmer Informatics’ TeknoPass_CVE-2026-4104

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass al...

Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass 20210501 CVE
CRITICAL 9.6 CVE-2026-10840

Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to kueue and cert-manager resources_CVE-2026-10840

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group wri...

Red Hat Builds for Red Hat OpenShift CVE
CRITICAL 9.3 CVE-2026-50214

Shared Secret Quota Inflation_CVE-2026-50214

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost netw...

Acer Connect M6E 5G Portable WiFi Router * CVE