Recent Advisories

Severity ID Title Vendor Product Date Type
NONE 1D2696A2-8C33-

web-security-lab-notes_1D2696A2-8C33-5878-869F-9FC45A3AA1D9

Common Web Vulnerabilities: Reproduction and Fixing Practices Project Description This repository is used to record the reproduction of common Web ...

N/A N/A GITHUBEXPLOIT
NONE THN:95BA2C853FC...

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns_THN:95BA2C853FC77B2F89B298EEB61CB43B

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhC1-4l_iOC19z96Q7C7O_dZSKwEvMnMLhHyb7kpt2rpOzQmn3gKpz6_BaZmSpzgvyhTJf8BBQmBTx0Nvymxk...

N/A N/A THN
HIGH 8.8 949595CB-7616-

Exploit for Improper Check for Unusual or Exceptional Conditions in Mozilla Firefox_949595CB-7616-5CAF-AA71-9F8FB7EA1FD8

🚨 CVE-2024-4367 - Universal PDF.js Vulnerability Scanner ⚠️ CRITICAL SECURITY TOOL | Detects CVE-2024-4367 CVSS 9.8 - PDF.js Remote Code Execution...

N/A N/A GITHUBEXPLOIT
HIGH 10 5D2DB41E-8DDC-

Ingram-Pro_5D2DB41E-8DDC-532D-87E6-D954A3D5D19B

Ingram-Pro Network Camera Vulnerability Scanner Enhanced Edition Based on the original Ingram framework, Ingram-Pro extends coverage with 40+ POCs ...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 0AE8E76C-CF25-

Exploit for CVE-2026-7574_0AE8E76C-CF25-54D7-B820-018A4B6FC60D

🚨 CVE-2026-7574 — Claude Desktop Cowork VM Integrity Bypass Anthropic Claude Desktop Cowork VM Image Integrity Bypass 🔥 Local Persistence Through...

N/A N/A GITHUBEXPLOIT
HIGH 8.2 CVE-2026-12490

Bypass of client certificate verification with transfer over TLS_CVE-2026-12490

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no...

NLnet Labs NSD 4.10.1 CVE
HIGH 7.2 CVE-2026-12246

Out of bounds stack write with crafted APL RR_CVE-2026-12246

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite...

NLnet Labs NSD 4.14.0 CVE
HIGH 8.7 CVE-2026-12245

Denial of DNS over TLS service by any DoT client_CVE-2026-12245

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be tri...

NLnet Labs NSD 4.13.0 CVE
HIGH 8.7 CVE-2026-12244

Heap overflow and crash with crafted SVCB RR_CVE-2026-12244

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted S...

NLnet Labs NSD 4.14.0 CVE
MEDIUM 5.5 CVE-2026-56129

CVE-2026-56129_CVE-2026-56129

Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A l...

Dynabook Inc. Generic IO & Memory Access driver all versions CVE