// psirt.com
PSIRT
Product Security Incident Response Team
Vulnerability intelligence and regulatory resources for security teams navigating NIS2, the Cyber Resilience Act, and coordinated disclosure.
View vulnerabilities →394,962CVEs indexed
2,147,446Security advisories
1,726CISA KEV entries
Vulnerabilities
CVE — Common Vulnerabilities
CVE — Common VulnerabilitiesBrowse all →
CVE-2026-90970CRITICAL 9.9
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2…CVE-2026-39717MEDIUM 4.3
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…CVE-2026-5782MEDIUM 5.2
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS.
This issue…CVE-2026-39601LOW 3.7
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveragi…CVE-2026-39439MEDIUM 6.5
Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…CVE-2026-32584MEDIUM 5.3
Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click…CVE-2026-39444MEDIUM 5.4
Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Acc…CVE-2026-39600MEDIUM 4.7
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects A…CVE-2026-104638MEDIUM 5.3
A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is…CVE-2026-32585MEDIUM 6.5
Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This…CVE-2026-104637HIGH 7.3
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function…CVE-2026-104625MEDIUM 6.3
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a…CVE-2026-104026HIGH 7.8
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if clon…CVE-2026-94422HIGH 8.8
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-B…CVE-2026-93875HIGH 7.2
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5…CVE-2026-85215HIGH 7.1
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injec…CVE-2026-104721NONE
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an
MDC-ba…CVE-2026-19652CRITICAL 9.8
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_ha…CVE-2026-104614MEDIUM 6.3
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/p…CVE-2026-104613MEDIUM 6.3
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/prod…
Advisories — OSV Database
Advisories — OSV DatabaseBrowse all →
No summary available.
No summary available.
GHSA-c9xm-49cp-xcr9CRITICAL
rmcp OAuth client fetches server-controlled resource_metadata URLsNo summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
No summary available.
KEV — Known Exploited Vulnerabilities
CISA
CVE-2026-102489EXPLOITED
Zammad GmbH — Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the…CVE-2026-102490EXPLOITED
Zammad GmbH — All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.CVE-2026-104286EXPLOITED
Fortinet — An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8…CVE-2026-76504EXPLOITED
Cisco — A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unau…CVE-2026-86950EXPLOITED
Apple — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS…CVE-2026-88772EXPLOITED
Citrix — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before…CVE-2026-88771EXPLOITED
Citrix — Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC:…CVE-2026-67279EXPLOITED
MikroTik — RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never at…CVE-2026-87902EXPLOITED
WordPress — An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.p…CVE-2026-65660EXPLOITED
Microsoft — Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker…CVE-2026-71362EXPLOITED
Adobe — Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An at…CVE-2026-5430EXPLOITED
WSO2 — The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or suppor…CVE-2026-85102EXPLOITED
Check Point — Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unaut…CVE-2026-7273EXPLOITED
Zyxel — A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(AB…CVE-2025-39964EXPLOITED
Linux — In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Disallow concurrent writes in af_…Resources
CISA / USAKEV CatalogAuthoritative catalog of vulnerabilities actively exploited in the wild.NIST / USANVDNational Vulnerability Database — CVE enrichment with CVSS scores, CPE mapping, and CWE classification.EU RegulationCyber Resilience ActRegulation (EU) 2024/2847 — mandatory security requirements for products with digital elements.EU DirectiveNIS2 DirectiveDirective (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union.FIRSTPSIRT Services FrameworkReference framework for establishing and operating a Product Security Incident Response Team.MITRECVE ProgramCVE assignment, CNA ecosystem, and disclosure coordination.GitHubGHSACurated security advisories for open source — npm, PyPI, Maven, Go, Rust, NuGet and more.RSSLatest CVEsRSS feed of recently published CVEs with CVSS scores and enrichment.RSSCISA KEV FeedRSS feed of newly added Known Exploited Vulnerabilities from CISA.RSSLatest AdvisoriesRSS feed of recently published security advisories.PSIRT.COMCRA SummitPast research and events on the Cyber Resilience Act, with speakers from ENISA, Thales, Orange and others.
Mailing Lists
BugtraqEst. 1993
The original full-disclosure vulnerability mailing list. Bugtraq has been the primary channel for publishing detailed vulnerability information and exploit techniques for over three decades.
Subscribe[email protected]
Archivessecurityfocus.com
SecurityFocusBID Database
Home of the Bugtraq ID (BID) vulnerability database - over 75,000 entries cross-referenced with CVEs, providing historical vulnerability intelligence dating back to 1999.
BID LookupExample: BID-21
Coverage75,921 BIDs mapped
CommunityOpen Security
Join the security research community. Discuss vulnerabilities, share advisories, and collaborate on coordinated disclosure through the Bugtraq mailing lists.
Contact
For research inquiries, partnerships, or PSIRT collaboration:
[email protected]