Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-7273

CVE-2026-7273_CVE-2026-7273

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-ba...

Zyxel GS1900-48HPv2 firmware <= 2.90(ABTQ.1)C0 CVE
MEDIUM 6.6 CVE-2026-42014

Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin_CVE-2026-42014

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vu...

Red Hat Red Hat Enterprise Linux 10 0:3.8.10-4.el10_2 CVE
MEDIUM 5.6 CVE-2026-1767

Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading to denial of service or information disclosure via malformed mp3 id3 tags_CVE-2026-1767

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker cou...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.6 CVE-2026-1766

Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and information disclosure via malformed mp3 files._CVE-2026-1766

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. Th...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.6 CVE-2026-1765

Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 files_CVE-2026-1765

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffe...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.6 CVE-2026-1764

Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads to denial of service or information disclosure when parsing mp3 files_CVE-2026-1764

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.5 CVE-2026-5064

HP One Agent Software – Security Update_CVE-2026-5064

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escal...

HP Inc. HP One Agent Software CVE
CRITICAL 9.1 CVE-2026-48714

i18next-http-middleware missingKeyHandler does not reject keys whose segments contain prototype-polluting names_CVE-2026-48714

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9....

i18next i18next-http-middleware < 3.9.7 CVE
CRITICAL 9.1 CVE-2026-48713

i18next-fs-backend: Prototype pollution via crafted missing-key string_CVE-2026-48713

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. v...

i18next i18next-fs-backend < 2.6.6 CVE
MEDIUM 6.1 CVE-2026-48157

Slim has Reflected XSS in the HtmlErrorRenderer_CVE-2026-48157

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses ...

slimphp Slim >= 4.4.0, < 4.15.2 CVE