Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.7 CVE-2026-57920

CVE-2026-57920_CVE-2026-57920

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

Peplink InControl CVE
HIGH 8 CVE-2026-40711

CVE-2026-40711_CVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) ...

Dell Container Storage Modules CVE
MEDIUM 5.4 CVE-2026-6658

Cross-site Scripting (XSS) in jupyter/nbconvert_CVE-2026-6658

A vulnerability in jupyter/nbconvert versions

jupyter jupyter/jupyter unspecified CVE
HIGH 7.1 CVE-2026-57918

CVE-2026-57918_CVE-2026-57918

libnfs through 6.0.2 before f0b109d has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a cra...

sahlberg libnfs CVE
HIGH 7.5 CVE-2026-57913

CVE-2026-57913_CVE-2026-57913

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

Johnson & Johnson Audit Tracking Management System CVE
HIGH 7.5 CVE-2026-57912

CVE-2026-57912_CVE-2026-57912

Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by in...

Johnson & Johnson Campus Recruiting CVE
MEDIUM 5.8 CVE-2026-57473

CVE-2026-57473_CVE-2026-57473

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of ...

Reolink Home Hub CVE
HIGH 8.5 CVE-2026-13325

Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces_CVE-2026-13325

A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the t...

Red Hat Red Hat OpenShift Virtualization 4 CVE
HIGH 7.1 CVE-2025-7958

CVE-2025-7958_CVE-2025-7958

A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using t...

Trellix Trellix Network Security NX, EX, FX, AX, and CMS 10.0.4 CVE
CRITICAL 9.8 CVE-2026-57881

GV-LPC2011/LPC2211 – unauthorized stack-based buffer overflow vulnerability (vlsvr)_CVE-2026-57881

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerab...

GeoVision Inc. GV-LPCLPC2011/2211 1.12 CVE