// psirt.com

PSIRT

Product Security Incident Response Team

Vulnerability intelligence and regulatory resources for security teams navigating NIS2, the Cyber Resilience Act, and coordinated disclosure.

View vulnerabilities  →
394,962CVEs indexed
2,147,446Security advisories
1,726CISA KEV entries

Vulnerabilities

CVE — Common Vulnerabilities CVE — Common VulnerabilitiesBrowse all →
CVE-2026-90970CRITICAL 9.9
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2…
2026-10-02
CVE-2026-39717MEDIUM 4.3
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…
2026-10-02
CVE-2026-5782MEDIUM 5.2
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS. This issue…
2026-10-02
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveragi…
2026-10-02
CVE-2026-39439MEDIUM 6.5
Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…
2026-10-02
CVE-2026-32584MEDIUM 5.3
Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click…
2026-10-02
CVE-2026-39444MEDIUM 5.4
Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Acc…
2026-10-02
CVE-2026-39600MEDIUM 4.7
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects A…
2026-10-02
CVE-2026-104638MEDIUM 5.3
A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is…
2026-10-02
CVE-2026-32585MEDIUM 6.5
Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This…
2026-10-02
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function…
2026-10-02
CVE-2026-104625MEDIUM 6.3
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a…
2026-10-02
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if clon…
2026-10-02
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-B…
2026-10-02
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5…
2026-10-02
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injec…
2026-10-02
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-ba…
2026-10-02
CVE-2026-19652CRITICAL 9.8
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_ha…
2026-10-02
CVE-2026-104614MEDIUM 6.3
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/p…
2026-10-02
CVE-2026-104613MEDIUM 6.3
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/prod…
2026-10-02
Advisories — OSV Database Advisories — OSV DatabaseBrowse all →
No summary available.
2026-10-02
No summary available.
2026-10-02
rmcp OAuth client fetches server-controlled resource_metadata URLs
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
No summary available.
2026-10-02
KEV — Known Exploited Vulnerabilities CISA
Zammad GmbH — Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the…
Added 2026-10-02Due 2026-10-05
Zammad GmbH — All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Added 2026-10-02Due 2026-10-05
Fortinet — An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8…
Added 2026-10-01Due 2026-10-04
Cisco — A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unau…
Added 2026-09-30Due 2026-10-03
Apple — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS…
Added 2026-09-29Due 2026-10-02
Citrix — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before…
Added 2026-09-27Due 2026-09-30
Citrix — Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC:…
Added 2026-09-27Due 2026-09-30
MikroTik — RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never at…
Added 2026-09-25Due 2026-09-28
WordPress — An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.p…
Added 2026-09-25Due 2026-09-28
Microsoft — Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker…
Added 2026-09-25Due 2026-09-28
Adobe — Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An at…
Added 2026-09-24Due 2026-09-27
CVE-2026-5430EXPLOITED
WSO2 — The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or suppor…
Added 2026-09-24Due 2026-09-27
Check Point — Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unaut…
Added 2026-09-22Due 2026-09-25
CVE-2026-7273EXPLOITED
Zyxel — A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(AB…
Added 2026-09-21Due 2026-09-24
Linux — In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_…
Added 2026-09-18Due 2026-09-21

Mailing Lists

BugtraqEst. 1993
The original full-disclosure vulnerability mailing list. Bugtraq has been the primary channel for publishing detailed vulnerability information and exploit techniques for over three decades.
SecurityFocusBID Database
Home of the Bugtraq ID (BID) vulnerability database - over 75,000 entries cross-referenced with CVEs, providing historical vulnerability intelligence dating back to 1999.
BID LookupExample: BID-21
Coverage75,921 BIDs mapped
CommunityOpen Security
Join the security research community. Discuss vulnerabilities, share advisories, and collaborate on coordinated disclosure through the Bugtraq mailing lists.

Contact

For research inquiries, partnerships, or PSIRT collaboration:

[email protected]