Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.4 CVE-2026-48940

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48940

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `` tag; K2 s...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
LOW 2.3 CVE-2026-57522

Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates_CVE-2026-57522

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-co...

bitwarden server CVE
LOW 2.3 CVE-2026-7531

Use-after-free in PQC hybrid key-share handling_CVE-2026-7531

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 serv...

wolfSSL wolfSSL 5.8.0 CVE
LOW 2.3 CVE-2026-10512

X25519 x86_64 assembly final reduction leaves non-canonical field element_CVE-2026-10512

The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may no...

wolfSSL wolfSSL 5.6.4 CVE
LOW 2.3 CVE-2026-13350

CVE-2026-13350_CVE-2026-13350

Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

pretix Venueless 0.0.0 CVE
LOW 2 CVE-2026-55967

AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse_CVE-2026-55967

AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allo...

wolfSSL wolfSSL 4.8.0 CVE
LOW 3.7 CVE-2026-42004

EDNS options smuggling_CVE-2026-42004

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when ...

PowerDNS DNSdist 1.9.0 CVE
LOW 3.7 CVE-2026-40208

Denial of service via DoH3 queries_CVE-2026-40208

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

PowerDNS DNSdist 1.9.0 CVE
LOW 3.7 CVE-2026-40011

Prometheus denial of service via crafted DNS queries_CVE-2026-40011

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid outp...

PowerDNS DNSdist 1.9.0 CVE
LOW 2.7 CVE-2026-12755

CVE-2026-12755_CVE-2026-12755

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with...

Devolutions Server 2026.2.4.0 CVE