Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.4 CVE-2026-47190

IPAM controller service account granted unnecessary full access to Secrets_CVE-2026-47190

IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole gra...

metal3-io ip-address-manager < 1.11.7 CVE
MEDIUM 5.3 CVE-2026-47182

Frappe: Broken Access Control on Private Files_CVE-2026-47182

Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file pa...

frappe frappe < 16.17.4 CVE
MEDIUM 5.8 CVE-2026-46690

unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race_CVE-2026-46690

unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB r...

spearman unbounded-spsc <= 0.2.0 CVE
CRITICAL 9.4 CVE-2026-45833

CVE-2026-45833_CVE-2026-45833

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on ...

Chroma ChromaDB 0.4.17 CVE
HIGH 8.8 CVE-2026-45832

CVE-2026-45832_CVE-2026-45832

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers...

Chroma ChromaDB 0.5.0 CVE
HIGH 8.8 CVE-2026-45831

CVE-2026-45831_CVE-2026-45831

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds...

Chroma ChromaDB 0.5.0 CVE
HIGH 8.8 CVE-2026-45830

CVE-2026-45830_CVE-2026-45830

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, wr...

Chroma ChromaDB 0.4.17 CVE
MEDIUM 5.3 CVE-2026-44976

Frappe: IDOR in update_onboarding_step_CVE-2026-44976

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue...

frappe frappe < 16.17.4 CVE
MEDIUM 5.3 CVE-2026-44975

Frappe: Missing authorization on reset form tours_CVE-2026-44975

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users...

frappe frappe < 15.107.2 CVE
MEDIUM 5.3 CVE-2026-44967

opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response_CVE-2026-44967

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full ...

open-telemetry opentelemetry-cpp < 1.27.0 CVE