Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-10802

keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption_CVE-2026-10802

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/co...

keystonejs keystone 20260319 CVE
HIGH 7.1 CVE-2025-52612

HCL iControl was affected by Export CSV – CSV Injection vulnerability._CVE-2025-52612

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was...

HCL iControl 4.0.0 CVE
LOW 3.1 CVE-2025-52611

HCL iControl was affected by Unhandled Exception – Stack Trace Disclosure vulnerability_CVE-2025-52611

HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being...

HCL iControl 4.0.0 CVE
LOW 3.7 CVE-2025-52609

HCL iControl was affected by Missing Security Headers vulnerability._CVE-2025-52609

HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS ...

HCL iControl 4.0.0 CVE
LOW 3.1 CVE-2025-52608

HCL iControl was affected by Missing Cookie Attributes vulnerability._CVE-2025-52608

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attr...

HCL iControl 4.0.0 CVE
MEDIUM 4.3 CVE-2025-52606

HCL iControl was affected by Weak Input Validation vulnerability. ._CVE-2025-52606

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic...

HCL iControl 4.0.0 CVE
HIGH 8.5 CVE-2025-12694

Local Privilege Escalation in VPN Client_CVE-2025-12694

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SY...

Forcepoint VPN Client CVE
MEDIUM 6.1 CVE-2026-8916

CVE-2026-8916_CVE-2026-8916

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd...

Samsung Open Source rlottie dcfde72eae1b0464dc0dd760aec00ada6a148635 CVE
MEDIUM 6.9 CVE-2026-50226

Firmware Theft & IMEI Spoofing via Connect-OTA_CVE-2026-50226

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50225

Account Creation Exhaustion_CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Acer Connect M6E 5G Portable WiFi Router * CVE