Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12814

Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection_CVE-2026-12814

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_...

Comfast CF-WR631AX V3 2.7.0.0 CVE
MEDIUM 5.3 CVE-2026-12813

activepieces File URL file.ts handleUrlFile server-side request forgery_CVE-2026-12813

A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/eng...

n/a activepieces 0.1 CVE
MEDIUM 5.3 CVE-2026-12821

FlowiseAI Flowise S3 Document Loader S3.ts path traversal_CVE-2026-12821

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/...

FlowiseAI Flowise 3.1.0 CVE
MEDIUM 5.3 CVE-2026-12815

coollabsio coolify Image Name os command injection_CVE-2026-12815

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation ...

coollabsio coolify 4.0.0 CVE
MEDIUM 5.3 CVE-2026-12807

Edimax BR-6478AC V2 POST Request setWAN command injection_CVE-2026-12807

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Ha...

Edimax BR-6478AC V2 1.23 CVE
MEDIUM 5.3 CVE-2026-12808

Edimax BR-6478AC V2 POST Request stainfo command injection_CVE-2026-12808

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Req...

Edimax BR-6478AC V2 1.23 CVE
MEDIUM 5.3 CVE-2026-12804

lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect_CVE-2026-12804

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Port...

n/a lemonldap-ng 2.0 CVE
HIGH 8.7 CVE-2026-12806

Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow_CVE-2026-12806

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSur...

Edimax BR-6478AC V2 1.23 CVE
MEDIUM 5.3 CVE-2026-12805

OFFIS DCMTK ofxml.cc parseFile heap-based overflow_CVE-2026-12805

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Exe...

OFFIS DCMTK 3.0 CVE
MEDIUM 4.9 CVE-2026-56412

CVE-2026-56412_CVE-2026-56412

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from with...

libexpat project libexpat CVE