Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-10777

ealpha072 Student-Management-System Administrative Backend config.php improper authentication_CVE-2026-10777

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is som...

ealpha072 Student-Management-System 01451bd7a2f58cdda07bd0b86e3967582e3ecd08 CVE
LOW 2 CVE-2026-10775

sgl-project SGLang Cache data_hash denial of service_CVE-2026-10775

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache ...

sgl-project SGLang 0.5.0 CVE
MEDIUM 4.3 CVE-2026-36618

CVE-2026-36618_CVE-2026-36618

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-36611

CVE-2026-36611_CVE-2026-36611

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction ...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-36609

CVE-2026-36609_CVE-2026-36609

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the s...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-36604

CVE-2026-36604_CVE-2026-36604

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-50033

CVE-2026-50033_CVE-2026-50033

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9...

Acronis Acronis DeviceLock DLP unspecified CVE
HIGH 7.3 CVE-2026-44682

CVE-2026-44682_CVE-2026-44682

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9...

Acronis Acronis DeviceLock DLP unspecified CVE
HIGH 7.3 CVE-2026-44609

CVE-2026-44609_CVE-2026-44609

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9...

Acronis Acronis DeviceLock DLP unspecified CVE
MEDIUM 4.8 CVE-2026-43924

FOSSBilling has an open redirect via administrator-configured redirect targets_CVE-2026-43924

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL sche...

FOSSBilling FOSSBilling < 0.8.0 CVE