Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-35098

Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK_CVE-2026-35098

KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform unlimited authentication re...

KTM System e-BOK CVE
MEDIUM 6.9 CVE-2026-35097

Weak Password Requirements in KTM System e-BOK_CVE-2026-35097

KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended chara...

KTM System e-BOK CVE
MEDIUM 5.1 CVE-2026-35096

Cross-Site Request Forgery (CSRF) in KTM System e-BOK_CVE-2026-35096

KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can c...

KTM System e-BOK CVE
MEDIUM 4.8 CVE-2026-35095

Session fixation in KTM System e-BOK_CVE-2026-35095

KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value rem...

KTM System e-BOK CVE
MEDIUM 5.9 CVE-2026-14178

openGauss存在非法内存访问导致DoS漏洞_CVE-2026-14178

openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 seqscan +...

openGauss-server openGauss-server-7.0.0-RC2 openGauss-server-7.0.0-RC2 CVE
MEDIUM 6.5 CVE-2026-51219

CVE-2026-51219_CVE-2026-51219

A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denia...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-49434

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker_CVE-2026-49434

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or...

Apache Software Foundation Apache ActiveMQ Broker CVE
CRITICAL 9.8 CVE-2026-8402

SQLi in Exagate’s SYSGUARD 6001_CVE-2026-8402

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer ...

Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 2.0.2 CVE
MEDIUM 5.9 CVE-2026-53692

Weak hahshing algorithm in Redeight CMS_CVE-2026-53692

Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically broken algorithm and lac...

Redeight Redeight CMS 1.0 CVE
HIGH 8.6 CVE-2026-53691

Remote Code Execution in Redeight CMS_CVE-2026-53691

An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST ...

Redeight Redeight CMS 1.0 CVE