CVE-2026-105137Medium· 5.0▾ SunlitA vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be la…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55251Medium· 6.5NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
CVE-2026-100265Medium· 4.8In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
CVE-2026-102930High· 7.7virtualenv is a tool for creating isolated virtual python environments
CVE-2026-73595Medium· 4.7Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability
CVE-2026-100653Medium· 6.5vLLM is an inference and serving engine for large language models
CVE-2026-96455High· 8.8The Reachy Mini daemon exposes an HTTP API for managing the robot