Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction._CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that la...

Concrete CMS Concrete CMS 5.0 CVE
MEDIUM 4.4 CVE-2026-45702

OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic_CVE-2026-45702

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZo...

OP-TEE optee_os >= 4.3.0, < 4.11.0 CVE
MEDIUM 4.7 CVE-2026-45614

OP-TEE vulnerable to ECDH private key recovery_CVE-2026-45614

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZo...

OP-TEE optee_os < 4.11.0 CVE
MEDIUM 5.1 CVE-2026-42840

ERPNext 16.16.0 – Stored XSS in POS customer section via unescaped template literals_CVE-2026-42840

An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped renderin...

Frappe ERPNext 16.16.0 CVE
MEDIUM 4.8 CVE-2026-42839

ERPNext 16.16.0 – Stored XSS in POS cart item rendering_CVE-2026-42839

An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image field...

Frappe ERPNext 16.16.0 CVE
HIGH 8.8 CVE-2026-30650

CVE-2026-30650_CVE-2026-30650

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD...

Vivotek Vivotek FD8136 FD8136-VVTK-0300a CVE
MEDIUM 4.3 CVE-2026-10702

JIT miscompilation in the JavaScript Engine: JIT component_CVE-2026-10702

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

Mozilla Firefox 151.0.3 CVE
HIGH 7.5 CVE-2026-42504

Quadratic complexity in WordDecoder.DecodeHeader in mime_CVE-2026-42504

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

Go standard library mime CVE
MEDIUM 6.1 CVE-2026-6657

CORS Origin Validation Bypass in jupyter-server_CVE-2026-6657

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` co...

jupyter jupyter/jupyter unspecified CVE
HIGH 7 CVE-2026-44281

GLPI vulnerable to unauthorized reading of a specific asset object_CVE-2026-44281

GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user w...

glpi-project glpi >= 11.0.0, < 11.0.7 CVE