Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 CVE-2026-11423

Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation_CVE-2026-11423

A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in ...

Altium Altium Enterprise Server CVE
HIGH 7.1 CVE-2026-11422

Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering_CVE-2026-11422

Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows...

shd101wyy Markdown Preview Enhanced CVE
CRITICAL 9.8 CVE-2026-7762

Heap buffer overflow in dot11ah.ko S1G Capabilities IE processing_CVE-2026-7762

A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.1...

Morse Micro HaLowLink 2 CVE
CRITICAL 9.8 CVE-2026-7763

Heap buffer overflow in morse.ko TIM IE processing_CVE-2026-7763

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 ...

Morse Micro HaLowLink 2 CVE
MEDIUM 6.5 CVE-2026-37737

CVE-2026-37737_CVE-2026-37737

sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match wit...

n/a n/a n/a CVE
MEDIUM 5.3 CVE-2026-38978

CVE-2026-38978_CVE-2026-38978

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-37460

CVE-2026-37460_CVE-2026-37460

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a De...

n/a n/a n/a CVE
MEDIUM 6.3 CVE-2026-5589

Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem._CVE-2026-5589

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bo...

zephyrproject-rtos Zephyr * CVE
MEDIUM 4.3 CVE-2026-11178

CVE-2026-11178_CVE-2026-11178

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11177

CVE-2026-11177_CVE-2026-11177

Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures ...

Google Chrome 149.0.7827.53 CVE