Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-12189

Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme_CVE-2026-12189

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a ...

Moovit Bus & Public Transit App 1.18 CVE
MEDIUM 5.3 CVE-2026-12188

Grit42 Grit GritEntityController grit_entity_controller.rb sql injection_CVE-2026-12188

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app...

Grit42 Grit 0.1 CVE
HIGH 8.5 CVE-2026-12191

Comma AI Openpilot Pickle modeld.py pickle.loads deserialization_CVE-2026-12191

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld....

Comma AI Openpilot 0.11 CVE
MEDIUM 4.8 CVE-2026-12190

Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme_CVE-2026-12190

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc....

Genspark AI Workspace App 2.8.4 CVE
HIGH 8.5 CVE-2026-12193

VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow_CVE-2026-12193

A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetect...

VS Revo RevoUninstaller 2.5.* CVE
HIGH 8.7 CVE-2026-12192

GALAYOU Y4 Web Server buffer overflow_CVE-2026-12192

A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This manipulation causes buffer ov...

GALAYOU Y4 1.0.0 CVE
HIGH 8.7 CVE-2026-12186

GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection_CVE-2026-12186

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor...

GL.iNet GL-MT3000 4.4.0 CVE
HIGH 7.8 CVE-2026-54413

CVE-2026-54413_CVE-2026-54413

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in ...

driftregion iso14229 CVE
HIGH 7.8 CVE-2026-54412

CVE-2026-54412_CVE-2026-54412

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() functi...

LiamBindle MQTT-C CVE
MEDIUM 6.9 CVE-2026-54411

CVE-2026-54411_CVE-2026-54411

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in module...

Linux-PAM Linux-PAM CVE