Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-24228

CVE-2026-24228_CVE-2026-24228

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of thi...

NVIDIA NeMo Framework Versions 0.0 to 2.7.2 CVE
HIGH 7.8 CVE-2026-24155

CVE-2026-24155_CVE-2026-24155

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code exec...

NVIDIA NeMo Framework Versions 0.0 to 2.7.2 CVE
MEDIUM 5.3 CVE-2026-12003

CPython >3.11 Insecure Input Validation resulting in privilege escalation_CVE-2026-12003

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and ...

Python Software Foundation CPython CVE
HIGH 8.6 CVE-2026-10649

Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression_CVE-2026-10649

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2025-71261

Harvester’s SUSE Virtualization Registration Client Vulnerable to MITM and DOS_CVE-2025-71261

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the ...

SUSE Harvester CVE
CRITICAL 9.1 CVE-2026-50887

CVE-2026-50887_CVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resou...

shlink shlink v5.0.1 CVE
CRITICAL 9.1 CVE-2026-50886

CVE-2026-50886_CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafte...

Project Firefly Project Firefly III v6.5.9 CVE
HIGH 7.5 CVE-2026-50885

CVE-2026-50885_CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints...

n/a n/a n/a CVE
CRITICAL 9.6 CVE-2026-50883

CVE-2026-50883_CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a cra...

matze matze wastebin v3.4.1 CVE
HIGH 7.5 CVE-2026-50882

CVE-2026-50882_CVE-2026-50882

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

n/a n/a n/a CVE