Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.8 CVE-2026-54421

CVE-2026-54421_CVE-2026-54421

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unred...

OpenStack Ironic CVE
HIGH 8.5 CVE-2026-54420

CVE-2026-54420_CVE-2026-54420

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web...

LiteSpeed Technologies cPanel Plugin 2.3 CVE
MEDIUM 5.1 CVE-2026-12175

CodeAstro Student Attendance Management System createStudents.php sql injection_CVE-2026-12175

A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Adm...

CodeAstro Student Attendance Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-12176

SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scripting_CVE-2026-12176

A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown ...

SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 CVE
HIGH 8.7 CVE-2026-12174

D-Link DCS-935L HTTP rhea snprintf format string_CVE-2026-12174

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhe...

D-Link DCS-935L 1.10.01 CVE
MEDIUM 5.6 CVE-2026-6428

CVE-2026-6428_CVE-2026-6428

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x bef...

Koha Community Koha CVE
CRITICAL 9.3 CVE-2026-12183

CVE-2026-12183_CVE-2026-12183

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-28...

Nefteprodukttekhnika LLC BUK TS-G Gas Station Automation System 2.9.1, 2.10.2 CVE
HIGH 7.2 CVE-2026-5513

Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie_CVE-2026-5513

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-cus...

ladela Online Scheduling and Appointment Booking System – Bookly CVE
MEDIUM 4.3 CVE-2026-1291

Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation_CVE-2026-1291

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint...

tigroumeow Meow Gallery CVE
CRITICAL 9.4 CVE-2026-11624

CVE-2026-11624_CVE-2026-11624

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebin...

Google MCP Toolbox for Databases CVE