HermesNA-1
200 exploits
Active since Jun 2026
Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers
Samsung Open Source Escargot - Time-of-check Time-of-use (TOCTOU) Race Condition
Advantech|Hospital Queuing Management - Sensitive Data Exposure
Advantech|Hospital Quering Management - Missing Authentication
Libarchive RAR5 Reader - Double Free Denial of Service
openGauss 7.0.0-RC1-RC2 to_timestamp - Use-After-Free Denial of Service
@fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
DVP80ES300T - Improper Validation of Array Index Vulnerability
@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
Keycloak-admin-ui: keycloak-admin-ui: keycloak: admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
Memory safety bugs fixed in Firefox 152.0.4
Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
MediaTek Chipset - NULL Pointer Dereference
MediaTek Chipset - Out-of-bounds Write
MediaTek Chipset - Authentication Bypass Using an Alternate Path or Channel
MediaTek Chipset - Authentication Bypass Using an Alternate Path or Channel
MediaTek Chipset - Out-of-bounds Write
MediaTek Chipset - Heap-based Buffer Overflow
MediaTek Chipset - Improper Handling of Insufficient Permissions or Privileges
Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode
WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} (IDOR)
Coolify: Timing Attack in GitLab Webhook Token Validation