
CVE-2021-3030
Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx

Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx

Tozed ZLT X300 5G CPE — Remote Root Code Execution via SDR Rogue Base Station (CVE-2026-2035703, CWE-78, CVSS 9.8) — Coordinated Disclosure

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

Stored XSS in ReNgine <= 2.2.0 — public disclosure

CVE-2026-22849 - Saleor lacks proper HTML sanitization in rich text fields

Security Advisory: Out-of-Bounds Read in facil.io MIME Parser leads to Server crash

Security Advisory: Infinite Loop DoS in facil.io MIME Parser (Partial Boundary)

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field



A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including…

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms…

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

CVE-2026-22692 - Critical Twig Sandbox Bypass via collect()->mapInto() allowing RCE/LFI/XXE in October CMS

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

CVE-2026-23500 - OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration in Dolibarr

CVE-2026-24419 - OpenSTAManager has a SQL Injection in the Prima Nota module