Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-12048

pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser_CVE-2026-12048

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messa...

pgadmin.org pgAdmin 4 6.0 CVE
CRITICAL 9 CVE-2026-12046

pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution_CVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/ and POST /sqleditor/initialize/sqleditor/update_connec...

pgadmin.org pgAdmin 4 6.9 CVE
CRITICAL 9 CVE-2026-12045

pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution_CVE-2026-12045

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execut...

pgadmin.org pgAdmin 4 9.13 CVE
CRITICAL 9.1 CVE-2026-8713

Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value_CVE-2026-8713

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_dele...

themefusion Avada (Fusion) Builder CVE
CRITICAL 9.8 CVE-2026-7515

BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style_CVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter...

betterdocs BetterDocs Pro CVE
CRITICAL 9.8 CVE-2026-54414

FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover_CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbi...

error311 FileRise CVE
CRITICAL 9.6 CVE-2026-56142

CVE-2026-56142_CVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching a...

JetBrains Hub CVE
CRITICAL 9.8 CVE-2026-56141

CVE-2026-56141_CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable re...

JetBrains Hub CVE
CRITICAL 10 CVE-2026-50242

CVE-2026-50242_CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct da...

JetBrains Hub CVE
CRITICAL 9.4 CVE-2026-44939

Command injection through unsanitized YAML parameter in Rancher_CVE-2026-44939

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanit...

SUSE Rancher 2.14.0 CVE