Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-36605

CVE-2026-36605_CVE-2026-36605

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low number of crafted incomplete HT...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-20233

Cisco Webex Meetings Cross-Site Scripting Vulnerability_CVE-2026-20233

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-s...

Cisco Cisco Webex Meetings 39.7.7 CVE
HIGH 8.6 CVE-2026-20230

CVE-2026-20230_CVE-2026-20230

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified C...

Cisco Cisco Unified Communications Manager N/A CVE
MEDIUM 6.1 CVE-2026-20175

Cisco Finesse File Inclusion Vulnerability_CVE-2026-20175

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user ...

Cisco Cisco Finesse 11.0(1)ES_Rollback CVE
HIGH 8.4 CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction._CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that la...

Concrete CMS Concrete CMS 5.0 CVE
MEDIUM 4.4 CVE-2026-45702

OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic_CVE-2026-45702

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZo...

OP-TEE optee_os >= 4.3.0, < 4.11.0 CVE
MEDIUM 4.7 CVE-2026-45614

OP-TEE vulnerable to ECDH private key recovery_CVE-2026-45614

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZo...

OP-TEE optee_os < 4.11.0 CVE
MEDIUM 5.1 CVE-2026-42840

ERPNext 16.16.0 – Stored XSS in POS customer section via unescaped template literals_CVE-2026-42840

An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped renderin...

Frappe ERPNext 16.16.0 CVE
MEDIUM 4.8 CVE-2026-42839

ERPNext 16.16.0 – Stored XSS in POS cart item rendering_CVE-2026-42839

An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image field...

Frappe ERPNext 16.16.0 CVE
HIGH 8.8 CVE-2026-30650

CVE-2026-30650_CVE-2026-30650

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD...

Vivotek Vivotek FD8136 FD8136-VVTK-0300a CVE