Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 CVE-2026-31928

Daktronics Controller Firmware Use of Hard-coded Credentials_CVE-2026-31928

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed ...

Daktronics VFC-DMP-5000 CVE
HIGH 7.1 CVE-2026-33560

Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type_CVE-2026-33560

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users t...

Daktronics VFC-DMP-5000 CVE
HIGH 7.8 CVE-2026-45195

GPU DDK – rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted_CVE-2026-45195

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the...

Imagination Technologies Graphics DDK 1.18 RTM CVE
HIGH 7.7 CVE-2026-21734

GPU DDK – libusc OOB write at TreeRemove during WebGPU shader compilation_CVE-2026-21734

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the G...

Imagination Technologies Graphics DDK 1.18 RTM CVE
HIGH 7.2 CVE-2026-13372

CVE-2026-13372_CVE-2026-13372

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allo...

Devolutions Remote Desktop Manager 2026.2.5 CVE
CRITICAL 9.9 CVE-2026-52785

OpenProject: SQL injection in timestamps functionality_CVE-2026-52785

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality...

opf openproject < 17.3.3 CVE
HIGH 8.8 CVE-2026-52784

OpenProject: CSRF on TARGET through /users/:id via POST parameter “user[admin]”_CVE-2026-52784

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POS...

opf openproject < 17.3.3 CVE
HIGH 8.2 CVE-2026-52783

OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others “storage..httpx_access_token” leads to Sensitive Data Exposure_CVE-2026-52783

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/Sh...

opf openproject < 17.3.3 CVE
CRITICAL 9.9 CVE-2026-52782

OpenProject: IDOR through /projects//settings/project_storages/ via PATCH parameter “storages_project_storage[project_folder_id]” leads to Access to Unauthorized Resources_CVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project...

opf openproject < 17.3.3 CVE
MEDIUM 6.4 CVE-2026-52781

OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter “description”_CVE-2026-52781

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants elements unrestricted dat...

opf openproject < 17.3.3 CVE