Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2025-0824

lack of validation for firmware update in Hitachi Virtual Storage_CVE-2025-0824

Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual St...

Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28 CVE
LOW 2.3 CVE-2026-13534

CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization_CVE-2026-13534

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemorySer...

CherryHQ cherry-studio 1.9.0 CVE
LOW 2.3 CVE-2026-13511

VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization_CVE-2026-13511

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/s...

n/a VoltAgent 2.1.0 CVE
LOW 2.4 CVE-2026-13514

Chess Play and Learn App com.chess AndroidManifest.xml backup_CVE-2026-13514

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidM...

Chess Play and Learn App 4.9.0 CVE
LOW 2.3 CVE-2026-13513

MyScale MyScaleDB SegmentId.h getCacheKey data authenticity_CVE-2026-13513

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library...

MyScale MyScaleDB 1.0 CVE
LOW 2.3 CVE-2026-13507

volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity_CVE-2026-13507

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb...

volcengine OpenViking 0.3.0 CVE
LOW 2 CVE-2026-13502

antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou_CVE-2026-13502

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main...

antlr ANTLR4 4.13.0 CVE
LOW 2.3 CVE-2026-13489

78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization_CVE-2026-13489

A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc ...

78 xiaozhi-esp32 2.2.0 CVE
LOW 2.3 CVE-2026-13493

AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection_CVE-2026-13493

A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversati...

AIDC-AI ComfyUI-Copilot 2.0.0 CVE
LOW 2.3 CVE-2026-13484

MLflow Experiment-scoped Label Schema CRUD API authorization_CVE-2026-13484

A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the compone...

n/a MLflow 4666cffc7912ea606d592fc38d6a75e2935f65e7 CVE