
CVE-2026-28766
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)

A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

Post-quantum hybrid encryption library combining X25519 + ML-KEM-768 with AES-256-GCM


Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

HMAC Implementation Example and Explanation

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

WPQA < 5.5 - Unauthenticated Private Message Disclosure
