Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-56208

Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode_CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.2 CVE-2026-49260

PhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)_CVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the ...

pontedilana php-weasyprint < 2.5.1 CVE
MEDIUM 5.5 CVE-2026-3196

Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation_CVE-2026-3196

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bou...

N/A N/A 8.2.0 CVE
HIGH 7.4 CVE-2026-3195

Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)_CVE-2026-3195

A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check wheth...

N/A N/A 8.2.0 CVE
MEDIUM 6.9 CVE-2026-55205

Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint_CVE-2026-55205

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that all...

nesquena hermes-webui CVE
HIGH 8.7 CVE-2026-55204

HAProxy – NULL Pointer Dereference in hpack_dht_insert Function_CVE-2026-55204

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c tha...

haproxy haproxy CVE
CRITICAL 9 CVE-2026-55203

HAProxy – Integer Overflow in FCGI Demux Record Length Field_CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffe...

haproxy haproxy CVE
MEDIUM 4.7 CVE-2026-54106

U.S. GAO EPDS and CBCA EDS network access control bypass_CVE-2026-54106

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE
MEDIUM 6.9 CVE-2026-54105

U.S. GAO EPDS and CBCA EDS user information disclosure_CVE-2026-54105

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE
HIGH 8.8 CVE-2026-54104

U.S. GAO EPDS and CBCA EDS client-based privilege escalation_CVE-2026-54104

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic...

Government Accountability Office Electronic Protest Docketing System (EPDS) CVE