Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.1 CVE-2026-0864

Configuration Injection via Carriage Return (\r) in write() method_CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the result...

Python Software Foundation CPython CVE
HIGH 7.5 CVE-2026-8379

Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download_CVE-2026-8379

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing una...

Unknown Frontend File Manager Plugin CVE
CRITICAL 9.1 CVE-2026-9733

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter_CVE-2026-9733

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specifi...

HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2 0.17 CVE
MEDIUM 5.3 CVE-2026-12969

Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation_CVE-2026-12969

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is ca...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.1 CVE-2026-11772

Reflected XSS in DRIMO CMS_CVE-2026-11772

DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in a...

DRIMO DRIMO CMS CVE
MEDIUM 6.8 CVE-2026-10609

Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization_CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output...

Red Hat Logging Subsystem for Red Hat OpenShift CVE
HIGH 7.4 CVE-2026-56815

CVE-2026-56815_CVE-2026-56815

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

rasta-mouse pwnlift CVE
CRITICAL 9.2 CVE-2026-35019

NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass_CVE-2026-35019

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers t...

NetComm Wireless Pty Ltd NF20MESH CVE
HIGH 8.7 CVE-2026-35018

NetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection_CVE-2026-35018

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated...

NetComm Wireless Pty Ltd NF20MESH R6B031 and earlier CVE
CRITICAL 9.4 CVE-2026-28496

FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE_CVE-2026-28496

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulne...

FOSSBilling FOSSBilling < 0.8.0 CVE