Security Advisories
Disclosure bulletins
Dated advisories from research and client engagements — severity, affected products, technical root cause, and remediation guidance, published under coordinated disclosure.
49 advisories published
Critical RCE in iCagenda Joomla Extension Under Active Exploitation
An unrestricted file upload vulnerability (CVE-2026-48939) in iCagenda for Joomla allows unauthenticated remote code execution and is actively exploited.
Critical Balbooa Forms RCE: Unrestricted File Upload Vulnerability
A critical unrestricted file upload vulnerability in Balbooa Forms (CVE-2026-56291) allows unauthenticated RCE, demanding urgent remediation.
CRITICAL ADOBE COLDFUSION RCE (CVE-2026-48282) ACTIVELY EXPLOITED
A critical path traversal vulnerability in Adobe ColdFusion (CVE-2026-48282) is under active exploitation, enabling unauthenticated remote code execution.
Critical Joomlack Page Builder RCE via Improper Access Control
A critical improper access control vulnerability in Joomlack Page Builder (CVE-2026-56290) allows for unauthenticated remote code execution via arbitrary file…
JoomShaper SP Page Builder RCE: Critical Unauthenticated File Upload Actively Exploited
Critical CVE-2026-48908 in JoomShaper SP Page Builder allows unauthenticated RCE via unrestricted file upload, actively exploited in the wild.
Advisory: Langflow Authorization Bypass (CVE-2026-55255)
A critical authorization bypass vulnerability in Langflow (CVE-2026-55255) allows authenticated attackers to execute arbitrary flows belonging to other users.
Authentication Bypass via JWT alg=none in Solandra Commerce API
Solandra Commerce API versions up to 3.4.2 accept unsigned JWTs by honoring an attacker-controlled alg header, allowing full authentication bypass.
IDOR in Parcelhive File-Sharing Endpoint Exposes Private Documents
A predictable share-link identifier in Parcelhive's file-sharing API allowed enumeration of other tenants' private documents.
SSRF in Metadata Proxy Endpoint Allows Cloud Credential Theft
An unvalidated URL-fetch feature could be redirected at the cloud instance metadata service, exposing temporary IAM credentials.
No advisories match your search.