Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2025-71328

Flowise – Unverified Password Change via Account Settings_CVE-2025-71328

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the acc...

Flowise Flowise CVE
HIGH 8.7 CVE-2025-71324

Flowise – Arbitrary File Read via chatId Parameter_CVE-2025-71324

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assist...

Flowise Flowise CVE
HIGH 8.8 25DE60F3-D53C-

Exploit for Path Traversal in Tp-Link Tapo_C260_Firmware_25DE60F3-D53C-5F5C-9C45-E27FA387E1AA

Tapo C260 RCE Chain CVE-2026-0651 / CVE-2026-0652 / CVE-2026-0653 Proof-of-concept exploit chain for TP-Link Tapo C260 IP camera achieving unauthen...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2025-61021

CVE-2025-61021_CVE-2025-61021

An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via cr...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61019

CVE-2025-61019_CVE-2025-61019

An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafte...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-12844

List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function_CVE-2026-12844

List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() collects the values returned by...

DROLSKY List::SomeUtils::XS CVE
HIGH 7.8 CVE-2026-54917

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access_CVE-2026-54917

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceb...

seaweedfs seaweedfs < 4.30 CVE
HIGH 7.1 CVE-2026-4930

DPA Countermeasures weakening on Series 3 devices_CVE-2026-4930

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryp...

silabs.com Simplicity SDK CVE
HIGH 7.1 CVE-2026-57520

Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint_CVE-2026-57520

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission t...

bitwarden server CVE
HIGH 8.2 CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation_CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so Pa...

wolfSSL wolfSSL 5.6.4 CVE