Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 FC87C5D8-8FE4-

Exploit for Deserialization of Untrusted Data in Facebook React_FC87C5D8-8FE4-516F-8C86-FF2150B1A826

Mô phỏng khai thác React2Shell CVE-2025-55182 Lưu ý: - Tài liệu này chỉ phục vụ mục đích học tập và nghiên cứu bảo mật. - Không sử dụng để tấn công...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 CVE-2026-12537

Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows_CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub A...

Google Cloud Gemini CLI CVE
CRITICAL 10 SECURELIST:25DF...

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader_SECURELIST:25DF27E139AF4557190EDA740DEAB957

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/24085803/SL-StrikeShark-featured-990x400.jpg) ## Introduction Durin...

N/A N/A SECURELIST
CRITICAL 10 776C9ED4-3841-

Exploit for Code Injection in Craftcms Craft_Cms_776C9ED4-3841-5FC1-B7D1-370CEAB62FAB

PoCCVE-2025-32432 CraftCMS CVE-2025-32432 - Clean PoC Version nettoyée et améliorée du PoC original. Crédits - Recherche originale : Orange Cyberde...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 61C38206-1C85-

cve-research-agent_61C38206-1C85-5ACA-A29E-1B8B1036B563

CVE Research Agent A CVE research agent built on Claude Code + MCP. Give it a CVE ID and a vulnerable source tree — it fetches the metadata, analyz...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-12417

SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover_CVE-2026-12417

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in v...

pravel SignUp & SignIn CVE
CRITICAL 9.8 CVE-2026-12416

Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter_CVE-2026-12416

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This i...

pravel Invoice Generator CVE
CRITICAL 10 59505BC0-DE3A-

MCATester_59505BC0-DE3A-56CF-96BF-33C4639271E6

MCATester — AI-Powered OSINT & Vulnerability Discovery Platform Built during a security research internship at the National e-Governance Division N...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 CVE-2026-12851

GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability_CVE-2026-12851

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted netwo...

GeoVision Inc. GV-I/O Box 4E V2.09 CVE
CRITICAL 9.1 CVE-2026-12850

GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability_CVE-2026-12850

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted netwo...

GeoVision Inc. GV-I/O Box 4E V2.09 CVE