Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 PACKETSTORM:223316

📄 Check Point VPN IKE Logic Flaw_PACKETSTORM:223316

This is a Python script attempting to exploit a vulnerability in Check Point VPN by sending a malformed IKESAINIT packet to UDP port 500, detecting...

N/A N/A PACKETSTORM
CRITICAL 9.6 PACKETSTORM:223339

📄 WordPress Gravity Forms 2.10.0.1 File Deletion / Path Traversal_PACKETSTORM:223339

This Metasploit module exploits a vulnerability in the Gravity Forms WordPress plugin versions 2.10.0.1 and below where file URLs stored in form en...

N/A N/A PACKETSTORM
CRITICAL 10 PACKETSTORM:223364

📄 Paperclip AI Remote Code Execution_PACKETSTORM:223364

Paperclip is the operating system for your AI company. You set the goals, hire AI agents as employees, and watch them plan and execute work. Prior ...

N/A N/A PACKETSTORM
CRITICAL 9.6 CVE-2026-12027

CVE-2026-12027_CVE-2026-12027

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer proces...

Google Chrome 149.0.7827.115 CVE
CRITICAL 9.8 CVE-2026-6853

OTP Bypass in BaÅŸbelen Group’s Pause+ Mobile App_CVE-2026-6853

Improper restriction of excessive authentication attempts vulnerability in BaÅŸbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ M...

BaÅŸbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App v1.0.6 CVE
CRITICAL 9.8 CVE-2026-54133

jmespath.php has CompilerRuntime code injection via unescaped function names_CVE-2026-54133

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications ...

jmespath jmespath.php < 2.9.1 CVE
CRITICAL 9.3 CVE-2026-53787

Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload_CVE-2026-53787

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthentica...

Amasty Order Attributes for Magento 2 CVE
CRITICAL 9.8 CVE-2026-47210

vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass_CVE-2026-47210

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the...

patriksimek vm2 < 3.11.4 CVE
CRITICAL 10 CVE-2026-47208

vm2: Sandbox Breakout Using Promise Species_CVE-2026-47208

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to ...

patriksimek vm2 < 3.11.4 CVE
CRITICAL 10 CVE-2026-47140

vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution_CVE-2026-47140

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_thre...

patriksimek vm2 < 3.11.4 CVE