Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-35081

Arbitrary process termination vulnerability in method ugw-logstop_CVE-2026-35081

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-suppli...

MBS Single-A V1_0_0_0 CVE
HIGH 7.2 CVE-2026-35080

Arbitrary file delete vulnerability in method ugw-restoreinfo_CVE-2026-35080

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-con...

MBS Single-A V1_0_0_0 CVE
HIGH 7.2 CVE-2026-35079

Arbitrary file delete vulnerability in method ugw-restore_CVE-2026-35079

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-control...

MBS Single-A V1_0_0_0 CVE
HIGH 7.2 CVE-2026-35078

Arbitrary file delete vulnerability in method ugw-logstop_CVE-2026-35078

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-contro...

MBS Single-A V1_0_0_0 CVE
HIGH 7.2 CVE-2026-35077

Arbitrary file delete vulnerability in method ugw-delete-file_CVE-2026-35077

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-co...

MBS Single-A V1_0_0_0 CVE
HIGH 7.2 CVE-2026-35076

Arbitrary file delete vulnerability in method bac-scanresult_CVE-2026-35076

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-cont...

MBS Single-A V1_0_0_0 CVE
HIGH 7.3 CVE-2025-41259

SWUpdate Untrusted Script Execution via Signed Update TOCTOU_CVE-2025-41259

SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate pri...

sbabic SWUpdate CVE
HIGH 7.5 F60EDCA1-3AA0-

Wazuh-Deployment-Vulnerability-Monitoring-PoC_F60EDCA1-3AA0-58CC-8AFA-A4BA4188AE01

🛡️ Wazuh Deployment & Vulnerability Monitoring PoC Overview This Proof of Concept PoC demonstrates the deployment of a fresh Wazuh Manager instance...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 9E8F733F-521E-

Exploit for Write-what-where Condition in Linux Linux_Kernel_9E8F733F-521E-504B-886D-5E1C5BC369E4

Local privilege escalation / Container escape: CVE-2026-43284 / CVE-2026-43500 Usage: CGOENABLED=0; go build -ldflags="-s -w" -o dirtyfrag ../dirty...

N/A N/A GITHUBEXPLOIT
HIGH 7.1 CVE-2025-15654

WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability_CVE-2025-15654

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This...

Fox-themes Prague n/a CVE