Security Advisories
150 advisoriesCVE-2026-22327
2026-08-23
Critical Vulnerability in Restaurt Allows Arbitrary File Upload (CVE-2026-22327)
A critical vulnerability in Restaurt versions up to 1.0.4 allows attackers to perform arbitrary file uploads. This poses a significant risk to systems using the affected software.
Read full advisory →CVE-2026-46854
2026-08-23
Critical Vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46854)
A critical vulnerability (CVE-2026-46854) allows low-privileged attackers to take over Oracle Enterprise Manager Base Platform via HTTP. Affects versions 13.5 and 24.1. CVSS 9.9. Immediate patching advised.
Read full advisory →CVE-2025-60218
2026-08-23
Critical Vulnerability in PT Luxa Addons Allows Arbitrary File Upload (CVE-2025-60218)
A critical vulnerability (CVE-2025-60218) allows attackers to upload arbitrary files via the PT Luxa Addons plugin for WordPress, affecting versions up to 1.2.2. This poses a high risk of remote code execution and data compromise.
Read full advisory →CVE-2026-40746
2026-08-23
Critical Vulnerability in Restaurant Zone Allows Arbitrary File Upload (CVE-2026-40746)
A critical vulnerability in restaurant_zone platform versions <= 0.7.8 allows attackers to perform arbitrary file uploads via subscriber features. CVSS 9.9. Immediate patching required to prevent remote code execution and data compromise.
Read full advisory →CVE-2026-49252
2026-08-23
Critical Vulnerability in deepstream Platform Allows Privilege Escalation (CVE-2026-49252)
A critical prototype pollution vulnerability in deepstream versions prior to 10.0.5 allows authenticated users to escalate privileges. This issue has a CVSS score of 9.9 and affects all versions before the patched release.
Read full advisory →CVE-2026-52785
2026-08-23
Critical SQL Injection Vulnerability in OpenProject (CVE-2026-52785)
A critical SQL injection vulnerability in OpenProject versions prior to 17.3.3 and 17.4.1 allows attackers to exploit timestamps functionality. This issue is resolved in the latest releases.
Read full advisory →CVE-2026-25446
2026-08-23
Critical Vulnerability in WishList Member X Plugin (CVE-2026-25446)
A critical vulnerability in WishList Member X plugin for WordPress allows attackers to upload arbitrary files, leading to potential remote code execution. Affected versions are 3.29.0 and below.
Read full advisory →CVE-2026-55115
2026-08-23
Critical SSRF Vulnerability in UniFi Protect Application (CVE-2026-55115)
A critical Server-Side Request Forgery (SSRF) vulnerability in UniFi Protect allows privilege escalation. CVSS 9.9. Affected users should apply patches immediately to prevent unauthorized access and system compromise.
Read full advisory →CVE-2026-46907
2026-08-23
Critical Vulnerability in JD Edwards EnterpriseOne Order Promising (CVE-2026-46907)
A critical vulnerability (CVE-2026-46907) affects JD Edwards EnterpriseOne Order Promising, allowing low-privileged attackers to take over the system via HTTP. CVSS 9.9. Immediate patching advised.
Read full advisory →CVE-2026-7873
2026-08-23
Critical Vulnerability in IBM Langflow OSS Allows Command Execution and File Access (CVE-2026-7873)
A critical vulnerability in IBM Langflow OSS allows authenticated attackers to execute arbitrary OS commands and access sensitive files, leading to system compromise. Affected versions: 1.0.0 to 1.10.0.
Read full advisory →CVE-2026-46900
2026-08-23
Critical Vulnerability in Oracle Enterprise Command Center Framework (CVE-2026-46900)
A critical vulnerability (CVE-2026-46900) allows low-privileged attackers to take over Oracle Enterprise Command Center Framework via HTTPS. Affects Oracle E-Business Suite versions V15 and V16. CVSS score 9.9.
Read full advisory →CVE-2026-46908
2026-08-23
Critical Vulnerability in JD Edwards EnterpriseOne Accounts Payable (CVE-2026-46908)
A critical vulnerability (CVE-2026-46908) affects JD Edwards EnterpriseOne Accounts Payable version 9.2, allowing low-privileged attackers to take over the system via HTTP. CVSS score 9.9. Immediate patching is required.
Read full advisory →Get These Delivered to Your Inbox
Subscribe to receive advisories as soon as they are published — filtered to your environment.