Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-41011

CVE-2026-41011_CVE-2026-41011

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['n...

Cloud Foundry Foundation BOSH CVE
MEDIUM 6.9 CVE-2026-10597

ITPison|OMICARD EDM – Insecure Direct Object Reference_CVE-2026-10597

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specif...

ITPison OMICARD EDM 5.8 CVE
MEDIUM 4.3 80DB2B91-72D2-

Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft_80DB2B91-72D2-5072-AE04-E22E0DB8B481

CVE-2026-33829 - Security Vulnerability Quick Usage bash python3 exploit.py -t "C:\\Path\\To\\Target" -o demo.zip --data-file payload.exe Exploitat...

N/A N/A GITHUBEXPLOIT
HIGH 7.7 86F57F94-F26C-

Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Tuzitio Camaleon_Cms_86F57F94-F26C-5EF7-904A-939B135AA64E

HTB Facts — Full Writeup Difficulty: Medium OS: Linux Tags: Web, MinIO, Camaleon CMS, Path Traversal, SSTI, Privilege Escalation --- Table of Conte...

N/A N/A GITHUBEXPLOIT
NONE 703E10A3-ED31-

wined_703E10A3-ED31-56A2-9A78-122264BCF6E9

Windows Exploitation wined Tools The following scripts were used to automate Windows x86 32-bit / x8664 64-bit Exploitation Development. Feel free ...

N/A N/A GITHUBEXPLOIT
LOW 2 CVE-2026-10783

gradio-app gradio Audio Cache Key save_audio_to_cache weak hash_CVE-2026-10783

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Han...

gradio-app gradio 6.14.0 CVE
HIGH 7.8 CVE-2025-22424

CVE-2025-22424_CVE-2025-22424

In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation ...

Google Android 16-qpr2 CVE
MEDIUM 5.9 CVE-2026-36610

CVE-2026-36610_CVE-2026-36610

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware con...

n/a n/a n/a CVE
MEDIUM 5.3 CVE-2026-22055

CVE-2026-22055_CVE-2026-22055

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauth...

NETAPP Active IQ OneCollect 2.7.3 CVE
MEDIUM 5.3 CVE-2026-22054

CVE-2026-22054_CVE-2026-22054

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform un...

NETAPP Active IQ Config Advisor 6.7.3 CVE