Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2026-56210

Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id_CVE-2026-56210

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable ...

Red Hat Red Hat Enterprise Linux 10 CVE
CRITICAL 9.1 CVE-2026-56209

Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack_CVE-2026-56209

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable V...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2026-56208

Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode_CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.2 CVE-2026-49260

PhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)_CVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the ...

pontedilana php-weasyprint < 2.5.1 CVE
MEDIUM 5.5 CVE-2026-3196

Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation_CVE-2026-3196

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bou...

N/A N/A 8.2.0 CVE
HIGH 7.4 CVE-2026-3195

Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)_CVE-2026-3195

A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check wheth...

N/A N/A 8.2.0 CVE
MEDIUM 6.9 CVE-2026-55205

Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint_CVE-2026-55205

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that all...

nesquena hermes-webui CVE
HIGH 8.7 CVE-2026-55204

HAProxy – NULL Pointer Dereference in hpack_dht_insert Function_CVE-2026-55204

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c tha...

haproxy haproxy CVE
CRITICAL 9 CVE-2026-55203

HAProxy – Integer Overflow in FCGI Demux Record Length Field_CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffe...

haproxy haproxy CVE
MEDIUM 4.7 CVE-2026-54106

U.S. GAO EPDS and CBCA EDS network access control bypass_CVE-2026-54106

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE