Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.7 CVE-2026-35067

CVE-2026-35067_CVE-2026-35067

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network...

Dell PowerFlex CVE
HIGH 7.1 CVE-2026-35066

CVE-2026-35066_CVE-2026-35066

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access co...

Dell PowerFlex CVE
HIGH 8.8 CVE-2026-35065

CVE-2026-35065_CVE-2026-35065

Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker...

Dell PowerFlex CVE
HIGH 8.1 CVE-2026-32804

CVE-2026-32804_CVE-2026-32804

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent netwo...

Dell PowerFlex CVE
HIGH 7.5 CVE-2026-22283

CVE-2026-22283_CVE-2026-22283

Dell PowerFlex Manager, version(s) Version prior to 4.8, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An u...

Dell PowerFlex CVE
MEDIUM 5.4 CVE-2026-12528

389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()_CVE-2026-12528

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) str...

Red Hat Red Hat Directory Server 11 CVE
HIGH 8.1 CVE-2026-11311

NGINX Gateway Fabric vulnerability_CVE-2026-11311

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator co...

F5 NGINX Gateway Fabric 2.5.0 CVE
MEDIUM 6.9 CVE-2026-10850

Plane 1.3.1 – Stored XSS in intake issue description_html_CVE-2026-10850

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item t...

Plane Plane 1.3.1 CVE
HIGH 8.1 CVE-2026-12290

Memory safety bug fixed in Thunderbird 152_CVE-2026-12290

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, a...

Mozilla Firefox 115.37 CVE
CRITICAL 9.1 CVE-2026-50203

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names_CVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP se...

Apache Software Foundation Apache Airflow SFTP provider CVE