🔓 CVEs & KEV
-
CVE-2026-49849 — CVSS 9.1 — xShop 3.0.3 Critical RCE via Unrestricted File Upload
-
CVE-2026-48050 — CVSS 8.8 — Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state a...
-
CVE-2026-48106 — CVSS 8.3 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync m...
-
CVE-2026-48105 — CVSS 8.3 — Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths wit...
-
CVE-2026-49360 — CVSS 7.8 — Recce server has unauthenticated SQL execution that allows local file read/wr...
-
CVE-2026-47735 — CVSS 7.1 — Arc has an authenticated arbitrary local-file read via DuckDB I/O functions t...