Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 7F7749F6-023B-

Exploit for Authentication Bypass Using an Alternate Path or Channel in Traefik_7F7749F6-023B-5070-9A69-60448F7E541E

CVE-2026-48020 — Traefik StripPrefix Route-Level Auth Bypass PoC A self-contained proof of concept for CVE-2026-48020, a route-level authentication...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 449EB399-8D3C-

Exploit for Improper Access Control in Widgetfactorylimited Jce_449EB399-8D3C-5528-B03B-B58DC4645B9D

MASTA CVE-2026-48907 Scanner Joomla! JCE 2.9.99.5 Unauthenticated Remote Code Execution RCE Scanner --- 🚨 LEGAL DISCLAIMER & ETHICAL USE This tool...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-12415

Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter_CVE-2026-12415

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_accou...

pravel Invoice Generator CVE
CRITICAL 9.8 CVE-2026-28701

Daktronics Controller Firmware Path Traversal_CVE-2026-28701

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and ...

Daktronics VFC-DMP-5000 CVE
CRITICAL 9.8 A04B552D-BE53-

Exploit for Missing Authentication for Critical Function in Flowiseai Flowise_A04B552D-BE53-596B-87C1-62CAF8B1227A

CVE-2025-58434 Flowiseai Auth Bypass PoC...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.9 CVE-2026-52785

OpenProject: SQL injection in timestamps functionality_CVE-2026-52785

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality...

opf openproject < 17.3.3 CVE
CRITICAL 9.9 CVE-2026-52782

OpenProject: IDOR through /projects//settings/project_storages/ via PATCH parameter “storages_project_storage[project_folder_id]” leads to Access to Unauthorized Resources_CVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project...

opf openproject < 17.3.3 CVE
CRITICAL 9.6 CVE-2026-52780

OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)_CVE-2026-52780

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution...

opf openproject < 17.3.3 CVE
CRITICAL 9.9 CVE-2026-46386

OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`_CVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KE...

opf openproject >= 8.3.0, < 17.2.4 CVE
CRITICAL 9.6 CVE-2026-54352

Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload_CVE-2026-54352

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a...

Budibase budibase < 3.39.9 CVE