Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.2 CVE-2026-3894

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers._CVE-2026-3894

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from...

RTI Connext Professional 7.4.0 CVE
CRITICAL 9.2 CVE-2026-2467

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags._CVE-2026-2467

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext...

RTI Connext Professional 7.4.0 CVE
CRITICAL 9.1 CVE-2026-20266

OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit_CVE-2026-20266

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Spl...

Splunk Splunk AI Toolkit 5.7 CVE
CRITICAL 9.1 CVE-2026-55196

Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass_CVE-2026-55196

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote a...

hermes-webui hermes-webui CVE
CRITICAL 9.1 PACKETSTORM:223728

📄 Grav CMS Remote Code Execution_PACKETSTORM:223728

This Python exploit targets a vulnerability in Grav CMS versions prior to 2.0.0-beta.2 by abusing the administrative Direct Install plugin feature ...

N/A N/A PACKETSTORM
CRITICAL 9.3 CVE-2026-53874

picklescan – Arbitrary Code Execution via Obfuscated eval Call_CVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval ca...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2026-53873

picklescan – Arbitrary Code Execution via profile.run() Blocklist Bypass_CVE-2026-53873

picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowi...

picklescan picklescan CVE
CRITICAL 10 CVE-2026-3490

picklescan – Universal Blocklist Bypass via pkgutil.resolve_name_CVE-2026-3490

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function ...

picklescan picklescan CVE
CRITICAL 9.1 CVE-2026-20181

Cisco Identity Services Engine Remote Code Execution Vulnerability_CVE-2026-20181

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating sy...

Cisco Cisco Identity Services Engine Software 3.1.0 CVE
CRITICAL 9.3 CVE-2025-71325

picklescan – Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw_CVE-2025-71325

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track argument...

picklescan picklescan CVE