Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation_CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so Pa...

wolfSSL wolfSSL 5.6.4 CVE
HIGH 8.3 CVE-2026-55958

Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage_CVE-2026-55958

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG...

wolfSSL wolfSSL 5.4.0 CVE
HIGH 8.7 CVE-2026-11310

X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring_CVE-2026-11310

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-ope...

wolfSSL wolfSSL 5.8.4 CVE
HIGH 7.5 CVE-2025-61027

CVE-2025-61027_CVE-2025-61027

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61023

CVE-2025-61023_CVE-2025-61023

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 8.1 CVE-2026-9800

Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison_CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role...

Red Hat Red Hat Build of Keycloak CVE
HIGH 7.7 CVE-2026-9099

Keycloak: group-admin escalation to realm-admin_CVE-2026-9099

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authentica...

Red Hat Red Hat Build of Keycloak CVE
HIGH 7.3 CVE-2026-9086

Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass_CVE-2026-9086

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to cli...

Red Hat Red Hat Build of Keycloak CVE
HIGH 8.3 CVE-2026-55412

ToolJet Cloud – SSRF to Azure Cloud Infrastructure Compromise_CVE-2026-55412

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-l...

ToolJet ToolJet < 3.20.178-lts CVE
HIGH 7 CVE-2026-55092

Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts_CVE-2026-55092

Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the ...

aquasecurity trivy < 0.71.1 CVE