Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 F2E78F8B-FFD9-

Exploit for OS Command Injection in Redhat Openshift_Container_Platform_F2E78F8B-FFD9-57F2-B246-315C95294897

Usage: For anonymos login: python3 exploit.py --lhost --lport -t -N it is for anonymous login Login via credentials: python3 exploit.py --lhost --l...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.3 1887B5CB-F35E-

Exploit for Improper Authentication in Checkpoint Gaia_Os_1887B5CB-F35E-509F-992F-1B55A688FF1D

CVE-2026-50751 Scanner Multi-target detection scanner for CVE-2026-50751 -- Check Point IKEv1 Remote Access VPN certificate-authentication bypass. ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 CVE-2026-40750

WordPress Kids Online Store theme <= 0.8.9 - Arbitrary File Upload vulnerability_CVE-2026-40750

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This ...

themagnifico52 Kids Online Store n/a CVE
CRITICAL 9.3 CVE-2026-52715

WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability_CVE-2026-52715

Unauthenticated SQL Injection in GEO my WordPress

Eyal Fitoussi GEO my WordPress n/a CVE
CRITICAL 9.9 CVE-2026-49774

WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability_CVE-2026-49774

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects...

Filipe Nasc RD Station n/a CVE
CRITICAL 9.3 CVE-2026-49772

WordPress The Events Calendar plugin 6.15.12-6.16.2 – SQL Injection vulnerability_CVE-2026-49772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar al...

Liquid Web / StellarWP The Events Calendar 6.15.12 CVE
CRITICAL 9.3 CVE-2026-39574

WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability_CVE-2026-39574

Unauthenticated SQL Injection in InPost Gallery

RealMag777 InPost Gallery n/a CVE
CRITICAL 10 5773EA35-AE6F-

Exploit for Deserialization of Untrusted Data in Facebook React_5773EA35-AE6F-5F32-8C58-AE355FF2E15B

CVE-2025-55182 — React2Shell Critical pre-authentication Remote Code Execution vulnerability in React Server Components RSC, Next.js, and related f...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.6 MS:CVE-2026-11652

Chromium: CVE-2026-11651 Use after free in Network_MS:CVE-2026-11652

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
CRITICAL 9.6 MS:CVE-2026-11654

Chromium: CVE-2026-11653 Insufficient validation of untrusted input in Extensions_MS:CVE-2026-11654

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE