Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-20265

Insecure Default Domain Allowlist in Splunk AI Toolkit_CVE-2026-20265

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI T...

Splunk Splunk AI Toolkit 5.7 CVE
MEDIUM 4.3 CVE-2026-20178

CVE-2026-20178_CVE-2026-20178

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malic...

Cisco Cisco Webex App N/A CVE
LOW 3.7 CVE-2026-11525

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching_CVE-2026-11525

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather t...

undici undici CVE
HIGH 7.1 CVE-2026-55198

Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint_CVE-2026-55198

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to acces...

nesquena hermes-webui CVE
HIGH 7.1 CVE-2026-55197

Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint_CVE-2026-55197

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclos...

nesquena hermes-webui CVE
CRITICAL 9.1 CVE-2026-55196

Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass_CVE-2026-55196

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote a...

hermes-webui hermes-webui CVE
HIGH 8.6 CVE-2026-53871

Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie_CVE-2026-53871

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profi...

nesquena hermes-webui CVE
MEDIUM 6.8 CVE-2026-53870

Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files_CVE-2026-53870

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversa...

NousResearch hermes-agent CVE
HIGH 8.7 CVE-2026-53869

Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints_CVE-2026-53869

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin val...

NousResearch hermes-agent CVE
HIGH 7.5 CVE-2026-48818

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows_CVE-2026-48818

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as...

Kludex starlette < 1.1.0 CVE