#1 · PT-2025-48817 · Meta · React-Server-Dom-Turbopack

Published

2025-12-03

·

Updated

2026-04-13

·

CVE-2025-55182

10

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions React versions 19.0.0 through 19.2.1 Next.js versions 15.x and 16.x
Description React Server Components (RSC) is affected by a critical remote code execution (RCE) vulnerability (CVE-2025-55182) with a CVSS score of 10.0. This vulnerability stems from unsafe deserialization of HTTP request payloads within Server Function endpoints. Exploitation allows unauthenticated attacke...
More

Exploit

Fix

RCE

LPE

DoS

Deserialization of Untrusted Data

1.9 K Posts
8.8 KReposts
9.9 M Audience
Graph

#2 · PT-2026-32093 · Adobe · Acrobat Reader

Michele Spagnuolo

·

Published

2026-04-08

·

Updated

2026-04-14

·

CVE-2026-34621

8.6

High

Base

AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier
Description Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability. This flaw could allow attackers to execute arbitrary code in the context of the current user when a malicious file...
More

Fix

RCE

Prototype Pollution

Buffer Overflow

139 Posts
257Reposts
118.7 K Audience
Graph

#3 · PT-2026-31721 · Wolfssl · Wolfssl

Nicholas Carlini

·

Published

2026-04-09

·

Updated

2026-04-14

·

CVE-2026-5194

None

Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 5.9.1
Description A security flaw exists in wolfSSL where missing hash/digest size and OID checks allow digests smaller than expected when verifying ECDSA certificates. This can lead to the acceptance of undersized digests during ECDSA signature verification, potentially reducing the security of certificate-based authentication. This issue affects ECDSA/ECC...
More

Fix

Improper Certificate Validation

17 Posts
124Reposts
126.3 K Audience
Graph

#4 · PT-2026-31594 · Marimo · Marimo

Published

2026-04-08

·

Updated

2026-04-14

·

CVE-2026-39987

None

Name of the Vulnerable Software and Affected Versions Marimo versions prior to 0.23.0
Description Marimo, a reactive Python notebook, contains a pre-authentication remote code execution (RCE) vulnerability in the '/terminal/ws' WebSocket endpoint. This endpoint lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints that cor...
More

Fix

RCE

Missing Authentication

72 Posts
103Reposts
59.4 K Audience
Graph

#5 · PT-2026-4775 · Microsoft · Office

Oruga00

+1

·

Published

2026-01-26

·

Updated

2026-04-14

·

CVE-2026-21509

7.8

High

Base

AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions: Microsoft Office versions 2016, 2019, Office LTSC 2021, 2024, and Microsoft 365 Apps for Enterprise.
Description: This vulnerability is a security feature bypass in Microsoft Office, allowing unauthorized attackers to bypass security features by exploiting a flaw in Object Linking and Embedding (OLE) handling. Attackers can achieve code execution by tricking users into opening spec...
More

Fix

RCE

458 Posts
1.1 KReposts
640.4 K Audience
Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph