Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-54219

Stored XSS in UBB.threads_CVE-2026-54219

UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low...

UBB Systems UBB.threads CVE
MEDIUM 5.2 CVE-2026-9158

CVE-2026-9158_CVE-2026-9158

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling po...

Eclipse Foundation Eclipse 4diac 3.0.0 CVE
HIGH 8.5 CVE-2026-56012

WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability_CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows ...

David Lingren Media LIbrary Assistant n/a CVE
HIGH 7.1 CVE-2026-50141

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation_CVE-2026-50141

Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any auth...

woodpecker-ci woodpecker >= 3.0.0, < 3.14.1 CVE
MEDIUM 6.5 CVE-2026-42490

domctl lock open to abuse_CVE-2026-42490

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and man...

Xen Xen consult Xen advisory XSA-492 CVE
MEDIUM 5.3 CVE-2026-42489

domctl lock open to abuse_CVE-2026-42489

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and man...

Xen Xen consult Xen advisory XSA-492 CVE
HIGH 8.1 CVE-2026-42488

x86: mismatched mapcache metadata_CVE-2026-42488

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between ...

Xen Xen consult Xen advisory XSA-494 CVE
HIGH 7.9 CVE-2026-42487

x86 HVM I/O port list traversal_CVE-2026-42487

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_...

Xen Xen consult Xen advisory XSA-491 CVE
MEDIUM 5.7 CVE-2026-12539

Docker Sandboxes ICMP egress restriction bypass after daemon restart_CVE-2026-12539

Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt fr...

Docker Docker Sandboxes 0.14.0 CVE
MEDIUM 6 CVE-2026-12527

CVE-2026-12527_CVE-2026-12527

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFH...

Shenzhen Liandian Communication Technology LTD V380 IP Camera / AppFHE1_V1.0.6.0 AppFHE1_V1.0.6.020230803 CVE