Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-27366

WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability_CVE-2026-27366

Unauthenticated Broken Access Control in MainWP Child

MainWP MainWP Child n/a CVE
HIGH 8.8 CVE-2026-57532

CVE-2026-57532_CVE-2026-57532

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the br...

pretix pretix CVE
HIGH 7.8 CVE-2026-46735

CVE-2026-46735_CVE-2026-46735

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command...

Dell Display and Peripheral Manager CVE
HIGH 8.6 CVE-2026-9717

CVE-2026-9717_CVE-2026-9717

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized executi...

Schneider Electric PowerLogic™ P7 Version V02.003.001.000 and prior CVE
HIGH 8.7 CVE-2026-9716

CVE-2026-9716_CVE-2026-9716

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration ...

Schneider Electric PowerLogic™ P7 Version V02.003.001.000 and prior CVE
HIGH 8.7 CVE-2026-9650

CVE-2026-9650_CVE-2026-9650

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthen...

Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Version 11.06.30 and prior CVE
HIGH 8.4 CVE-2026-57456

Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings_CVE-2026-57456

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the lega...

vim vim < 9.2.0699 CVE
HIGH 7.2 CVE-2026-55477

Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation_CVE-2026-55477

3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functiona...

MHSanaei 3x-ui < 3.3.1 CVE
HIGH 7.5 616C2155-98D5-

Exploit for Classic Buffer Overflow in Qualcomm Apq8097_Firmware_616C2155-98D5-5316-BB35-BF924B098C71

Katana A BootROM exploit for Qualcomm devices released within 2016 til 2019. Brief Explanation of the Exploit With the MSM8998 Nazgul SoC, the comm...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 42AB7263-83ED-

Exploit for Use After Free in Linux Linux_Kernel_42AB7263-83ED-599E-9DD2-2E97F2B90A99

CVE-2026-23111 PoC Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability Summary - CVE: CVE-2026-23111 - Type: Use-After-Fr...

N/A N/A GITHUBEXPLOIT