Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2026-13028

CVE-2026-13028_CVE-2026-13028

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a...

Google Chrome 149.0.7827.197 CVE
CRITICAL 10 THN:36AE22FA31D...

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited_THN:36AE22FA31D6D2AC6781F7FB8DEED534

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjZtIkR9YS2fMY5MvIzgyEShmJAP1bgHqhBdU115iSY7WZ2EcBAbFKb1OQP6Nq8hoF4HlnRifxW890ztCcne...

N/A N/A THN
CRITICAL 9.3 CVE-2026-56121

Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization_CVE-2026-56121

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code e...

feast-dev feast CVE
CRITICAL 9.8 9FE7E8BC-4FDD-

Exploit for Out-of-bounds Write in Fortinet Fortiproxy_9FE7E8BC-4FDD-5C40-A866-41D14FB4E0CD

CVE-2024-21762 - FortiOS SSL VPN Out-of-Bounds Write Overview | Field | Value | |-------|-------| | CVE | CVE-2024-21762 | | Advisory | FG-IR-24-01...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 313C0238-45FD-

Exploit for CVE-2026-12416_313C0238-45FD-59C7-9A09-F1668F7DFE47

CVE-2026-12416-CVE-2026-12417 Unauthenticated Account Takeover via Weak Password Reset Validation via 'resetuserid' Parameter | Unauthenticated Pri...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.3 CVE-2026-56237

Capgo – Unauthenticated API Key Generation via Client-Side Parameter Manipulation_CVE-2026-56237

Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests...

Capgo Capgo CVE
CRITICAL 9.3 CVE-2026-56223

Capgo – Account Takeover via Cross-Domain SSO Email Assertion in provision-user_CVE-2026-56223

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbi...

Capgo Capgo CVE
CRITICAL 9.8 2DEFD2D9-CD2E-

Exploit for OS Command Injection in Fortinet Fortiweb_2DEFD2D9-CD2E-5E1B-BEAB-3A15FD3493B4

Mô phỏng khai thác FortiWeb CVE-2025-64446 & CVE-2025-58034 Lưu ý: - Tài liệu này chỉ phục vụ mục đích học tập và nghiên cứu bảo mật. - Không sử dụ...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 FC87C5D8-8FE4-

Exploit for Deserialization of Untrusted Data in Facebook React_FC87C5D8-8FE4-516F-8C86-FF2150B1A826

Mô phỏng khai thác React2Shell CVE-2025-55182 Lưu ý: - Tài liệu này chỉ phục vụ mục đích học tập và nghiên cứu bảo mật. - Không sử dụng để tấn công...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 CVE-2026-12537

Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows_CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub A...

Google Cloud Gemini CLI CVE