Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.2 1EF4AA0B-45D8-

Exploit for CVE-2026-49757_1EF4AA0B-45D8-513E-B6D6-AF05E52ECFC6

CVE-2026-49757 — AshAuthentication OAuth2/OIDC Account Takeover Proof of Concept for CVE-2026-49757 — a critical vulnerability in AshAuthentication...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 FB774AC0-68D8-

Exploit for CVE-2026-11561_FB774AC0-68D8-53A1-A43B-0733FA9AF1BD

CVE-2026-11561 — Apinizer SSTI / RCE Version Check Infra Nuclei template to detect Apinizer versions lower than 2026.04.6, which are vulnerable to ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.2 CVE-2026-56345

AVideo – Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint_CVE-2026-56345

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the targ...

AVideo AVideo CVE
CRITICAL 9.8 B59AFB79-5EFF-

Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in Apache Tomcat_B59AFB79-5EFF-5CBE-9EBA-41DE2D90DCE9

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 CVE-2026-5366

Git Argument Injection in prefecthq/prefect_CVE-2026-5366

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage clas...

prefecthq prefecthq/prefect unspecified CVE
CRITICAL 9.8 51654478-7539-

Exploit for OS Command Injection in Redhat Openshift_Container_Platform_51654478-7539-5748-ADF6-E1E5CD131F2F

CVE-2026-4480-PoC...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 CVE-2026-48939

Joomla Extension – icagenda.com – Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15_CVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in P...

icagenda.com iCagenda extension for Joomla 1.0.0-3.9.14 CVE
CRITICAL 9.5 CVE-2026-48909

Joomla Extension – joomshaper.com – PHP Object injection in SP LMS extension for Joomla < 4.1.4_CVE-2026-48909

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker t...

joomshaper.net SP LMS extension for Joomla 1.0.0-4.1.3 CVE
CRITICAL 10 CVE-2026-48908

Joomla Extension – joomshaper.com – Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12_CVE-2026-48908

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code ...

joomshaper.net SP Page Builder extension for Joomla 1.0.0-6.6.1 CVE
CRITICAL 10 D4275D24-A482-

GumVulns_D4275D24-A482-561B-8402-1DE456184863

GumVulns A single-file PHP CLI that searches many vulnerability APIs in parallel and returns a normalized record for each hit: CVE id, description,...

N/A N/A GITHUBEXPLOIT