Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 2DA57135-57BB-

Exploit for SQL Injection in Litellm_2DA57135-57BB-597F-8C0D-BCCBAEE544E5

CVE-2026-42208 — LiteLLM Pre-Authentication SQL Injection A lab environment for reproducing and detecting CVE-2026-42208, a critical pre-authentica...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 9A2F776F-62A6-

Exploit for CVE-2026-8732_9A2F776F-62A6-58BF-BE46-69B82EED9DCC

CVE-2026-8732 — WP Maps Pro ≤ 6.1.0 ♡ Unauthenticated Privilege Escalation via Administrator Account Creation ♡ === shadow ♡ & friska === --- 📋 Vu...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 PACKETSTORM:222218

📄 WordPress Quick Playground 1.3.1 Shell Upload_PACKETSTORM:222218

Quick Playground for WordPress plugin versions 1.3.1 and below suffers from a remote shell upload vulnerability...

N/A N/A PACKETSTORM
CRITICAL 10 25B4314F-857E-

Exploit for CVE-2026-22557_25B4314F-857E-50A3-8FD2-33252F85B49A

CVE-2026-22557 Vulnerability Assessment Tool Safely detect whether a UniFi Network Application controller is vulnerable to CVE-2026-22557 without c...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 IMPERVABLOG:E4E...

Imperva Customers Protected Against CVE-2026-45247 in Mirasvit Full Page Cache Warmer for Magento_IMPERVABLOG:E4E2C1D23C9CF8EE01C3B384B9B152C9

**_TL;DR:_** _CVE-2026-45247_ _is a critical unauthenticated remote code execution (RCE) vulnerability affecting Mirasvit Full Page Cache Warmer fo...

N/A N/A IMPERVABLOG
CRITICAL 9.1 CVE-2026-9090

CVE-2026-9090_CVE-2026-9090

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing cer...

Casdoor Casdoor CVE
CRITICAL 9.8 CVE-2026-45697

Formie: Pre-authenticated server-side template injection in Hidden fields_CVE-2026-45697

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (...

verbb formie < 2.2.20 CVE
CRITICAL 9.9 CVE-2026-45372

cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection_CVE-2026-45372

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming req...

yhirose cpp-httplib < 0.44.0 CVE
CRITICAL 9.8 CVE-2026-7786

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded Credentials_CVE-2026-7786

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credential...

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter 7.03T.07 CVE
CRITICAL 9.1 CVE-2026-5386

KMW CCTV Security Cameras Unverified Password Change_CVE-2026-5386

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset ...

KMW KM-IP521 4.04.91.230307 CVE