Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.9 CVE-2026-50551

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content_CVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in...

siyuan-note siyuan < 3.7.0 CVE
CRITICAL 9.1 75711BFE-8B18-

Exploit for CVE-2026-56111_75711BFE-8B18-55AC-A70F-7ACF021EFAE2

CVE-2026-56111 - Marlin M421 Out-of-bounds Write Proof of concept for CVE-2026-56111, an out-of-bounds write in the M421 G-code handler of Marlin F...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 MSF:AUXILIARY-SCANNER-

Next.js Middleware Authorization Bypass Scanner_MSF:AUXILIARY-SCANNER-HTTP-NEXTJS_MIDDLEWARE_AUTH_BYPASS-

This module detects self-hosted Next.js applications affected by CVE-2025-29927, an authorization bypass in the middleware layer. Next.js tags its ...

N/A N/A METASPLOIT
CRITICAL 9.8 MSF:AUXILIARY-SCANNER-

BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner_MSF:AUXILIARY-SCANNER-HTTP-LITELLM_PROXY_SQLI-

This module detects BerriAI LiteLLM proxy servers affected by CVE-2026-42208, an unauthenticated SQL injection. During API-key verification the pro...

N/A N/A METASPLOIT
CRITICAL 9.6 CVE-2026-53943

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header_CVE-2026-53943

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being ...

TryGhost Ghost >= 4.0.0, < 6.37.0 CVE
CRITICAL 9.8 CVE-2026-49980

Rclone: Unauthenticated command execution in `rclone rcd –rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix_CVE-2026-49980

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd ...

rclone rclone >= 1.46.0, < 1.74.3 CVE
CRITICAL 9.6 CVE-2026-13032

CVE-2026-13032_CVE-2026-13032

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a...

Google Chrome 149.0.7827.197 CVE
CRITICAL 9.6 CVE-2026-13028

CVE-2026-13028_CVE-2026-13028

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a...

Google Chrome 149.0.7827.197 CVE
CRITICAL 10 THN:36AE22FA31D...

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited_THN:36AE22FA31D6D2AC6781F7FB8DEED534

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjZtIkR9YS2fMY5MvIzgyEShmJAP1bgHqhBdU115iSY7WZ2EcBAbFKb1OQP6Nq8hoF4HlnRifxW890ztCcne...

N/A N/A THN
CRITICAL 9.3 CVE-2026-56121

Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization_CVE-2026-56121

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code e...

feast-dev feast CVE