Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-10655

Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it_CVE-2026-10655

The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descriptor directly from the calli...

zephyrproject zephyr 4.2.0 CVE
MEDIUM 6.4 CVE-2026-10653

Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref_CVE-2026-10653

The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count...

zephyrproject zephyr 2.7.0 CVE
MEDIUM 4.8 CVE-2026-10652

Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)_CVE-2026-10652

Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which validated only the fixed RR hea...

zephyrproject zephyr 4.3.0 CVE
MEDIUM 5.5 CVE-2026-43722

CVE-2026-43722_CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be ab...

Apple iOS and iPadOS CVE
MEDIUM 6.5 CVE-2026-55956

Apache Tomcat: Security constraints for default servlet ignored method_CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-55955

Apache Tomcat: EncryptInterceptor not protected against replay attacks_CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.1 CVE-2026-50229

Apache Tomcat: XSS in number guess example_CVE-2026-50229

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-51218

CVE-2026-51218_CVE-2026-51218

A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial o...

n/a n/a n/a CVE
MEDIUM 4.9 CVE-2026-9576

Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export_CVE-2026-9576

The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export...

Unknown Fluent Booking CVE
MEDIUM 5.9 CVE-2026-11581

Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption_CVE-2026-11581

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it ...

Unknown Kali Forms — Contact Form & Drag-and-Drop Builder CVE