Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-0088

CVE-2026-0088_CVE-2026-0088

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. Th...

Google Android 16-qpr2 CVE
HIGH 7.8 CVE-2026-40715

CVE-2026-40715_CVE-2026-40715

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local acc...

Dell ThinOS 10 CVE
HIGH 7.8 CVE-2026-24237

CVE-2026-24237_CVE-2026-24237

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vu...

NVIDIA NVTabular 0.0 to 5dd11f4 CVE
HIGH 7.8 CVE-2026-24221

CVE-2026-24221_CVE-2026-24221

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vu...

NVIDIA NVTabular 0.0 to 5dd11f4 CVE
HIGH 7.1 CVE-2026-1871

Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200_CVE-2026-1871

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header...

TP-Link Systems Inc. Tapo C200 v5 CVE
HIGH 7.5 C21DAAE1-B419-

Exploit for CVE-2026-45332_C21DAAE1-B419-5788-B35E-CE7E357E7438

CVE-2026-45332 — Broken Access Control in Automad CMS Proof of concept for CVE-2026-45332, a Broken Access Control vulnerability in Automad CMS tha...

N/A N/A GITHUBEXPLOIT
HIGH 10 11E67395-5053-

Exploit for OS Command Injection in Gnu Bash_11E67395-5053-59B0-976E-309242811528

HackTheBox: Shocker Writeup A structured and professional walkthrough showcasing the identification and manual exploitation of the critical Shellsh...

N/A N/A GITHUBEXPLOIT
HIGH 7.3 CVE-2026-45360

Apache Airflow: Arbitrary import in custom deadline-reference deserialization_CVE-2026-45360

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary cl...

Apache Software Foundation Apache Airflow CVE
HIGH 8.8 CVE-2026-42359

Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator_CVE-2026-42359

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on ...

Apache Software Foundation Apache Airflow 3.2.0 CVE
HIGH 7.5 CVE-2026-37233

CVE-2026-37233_CVE-2026-37233

FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/...

n/a n/a n/a CVE