Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7 CVE-2026-58050

libssh2 – Integer Overflow in publickey Subsystem Attribute Allocation_CVE-2026-58050

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_at...

libssh2 libssh2 CVE
HIGH 8.6 CVE-2026-58049

FFmpeg – Out-of-Bounds Write in RASC Decoder decode_dlta()_CVE-2026-58049

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary...

FFmpeg FFmpeg CVE
HIGH 7.2 52E3EC4D-B3B2-

Exploit for Unrestricted Upload of File with Dangerous Type in Devcode Openstamanager_52E3EC4D-B3B2-5A5A-B602-597C9814297E

OpenSTAManager RCE Exploit CVE-2026-38751 Arbitrary File Upload leading to Remote Code Execution Full-featured proof-of-concept for CVE-2026-38751,...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2026-10643

Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)_CVE-2026-10643

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_co...

zephyrproject zephyr 3.6.0 CVE
HIGH 8.1 CVE-2026-8095

Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion_CVE-2026-8095

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. ...

nmedia Frontend File Manager Plugin CVE
HIGH 8.8 927189F5-055C-

pagecache-lpe-containment-kit_927189F5-055C-5E36-A2C8-0F7428A5314E

Page-Cache LPE Containment Kit Detect, contain, and verify defenses against two Linux page-cache-corruption local privilege escalations — DirtyClon...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 20557F2C-42AE-

Exploit for Incorrect Implementation of Authentication Algorithm in Google Android_20557F2C-42AE-5B1F-BCF0-6B6EBE49885A

CVE-2026-0073 – Android ADBD TLS Authentication Bypass EVPPKEYcmp Type Confusion → Unauthorized ADB Shell Access --- 🔥 Overview There is a critica...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 ECD48805-B674-

Exploit for Use After Free in Linux Linux_Kernel_ECD48805-B674-5D15-9640-7AE6AB574266

CVE-2026-43499 — Linux Kernel Futex PI Use-After-Free Bug removewaiter in kernel/locking/rtmutex.c is used by the slowlock paths but also for proxy...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 7D0D67E6-AAE8-

Exploit for CVE-2026-46331_7D0D67E6-AAE8-52CC-B577-3C66E3ECB231

cve-id ⚡ Simple Usage Use this project only in safe and authorized environments such as: - Local virtual machines - Docker containers - Isolated l...

N/A N/A GITHUBEXPLOIT
HIGH 8.3 MS:CVE-2026-50521

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability_MS:CVE-2026-50521

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

N/A N/A MSCVE