Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9 CVE-2026-12045

pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution_CVE-2026-12045

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execut...

pgadmin.org pgAdmin 4 9.13 CVE
CRITICAL 9.1 CVE-2026-8713

Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value_CVE-2026-8713

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_dele...

themefusion Avada (Fusion) Builder CVE
CRITICAL 9.8 CVE-2026-7515

BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style_CVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter...

betterdocs BetterDocs Pro CVE
CRITICAL 9.8 CVE-2026-54414

FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover_CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbi...

error311 FileRise CVE
CRITICAL 9.6 CVE-2026-56142

CVE-2026-56142_CVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching a...

JetBrains Hub CVE
CRITICAL 9.8 CVE-2026-56141

CVE-2026-56141_CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable re...

JetBrains Hub CVE
CRITICAL 10 CVE-2026-50242

CVE-2026-50242_CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct da...

JetBrains Hub CVE
CRITICAL 9.4 CVE-2026-44939

Command injection through unsanitized YAML parameter in Rancher_CVE-2026-44939

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanit...

SUSE Rancher 2.14.0 CVE
CRITICAL 9.1 CVE-2026-9142

Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present_CVE-2026-9142

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopb...

NI grpc-device CVE
CRITICAL 9.1 CVE-2026-48137

Untrusted pointer dereference in NI grpc-device sideband streaming API_CVE-2026-48137

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitra...

NI grpc-device CVE