Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2025-22424

CVE-2025-22424_CVE-2025-22424

In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation ...

Google Android 16-qpr2 CVE
MEDIUM 5.9 CVE-2026-36610

CVE-2026-36610_CVE-2026-36610

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware con...

n/a n/a n/a CVE
MEDIUM 5.3 CVE-2026-22055

CVE-2026-22055_CVE-2026-22055

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauth...

NETAPP Active IQ OneCollect 2.7.3 CVE
MEDIUM 5.3 CVE-2026-22054

CVE-2026-22054_CVE-2026-22054

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform un...

NETAPP Active IQ Config Advisor 6.7.3 CVE
MEDIUM 6.9 CVE-2026-10771

crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery_CVE-2026-10771

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zb...

crmeb crmeb_java 1.4 CVE
MEDIUM 6.9 CVE-2026-10777

ealpha072 Student-Management-System Administrative Backend config.php improper authentication_CVE-2026-10777

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is som...

ealpha072 Student-Management-System 01451bd7a2f58cdda07bd0b86e3967582e3ecd08 CVE
LOW 2 CVE-2026-10775

sgl-project SGLang Cache data_hash denial of service_CVE-2026-10775

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache ...

sgl-project SGLang 0.5.0 CVE
MEDIUM 4.3 CVE-2026-36618

CVE-2026-36618_CVE-2026-36618

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-36611

CVE-2026-36611_CVE-2026-36611

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction ...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-36609

CVE-2026-36609_CVE-2026-36609

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the s...

n/a n/a n/a CVE