Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2026-44367

Klaw: user lockout due to case sensitivity inconsistency_CVE-2026-44367

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registrati...

Aiven-Open klaw < 2.10.4 CVE
LOW 3.1 31971257-6727-

Exploit for CVE-2026-49009_31971257-6727-54F9-9D3A-E4BE531BE376

CVE-2026-49009 Mender Server - Authenticated Path Traversal to RCE...

N/A N/A GITHUBEXPLOIT
LOW 2.3 CVE-2026-10565

Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition_CVE-2026-10565

A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm...

n/a Open5GS 2.7.0 CVE
LOW 3.3 CVE-2025-48616

CVE-2025-48616_CVE-2025-48616

In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in th...

Google Android 16-qpr2 CVE
LOW 3.3 CVE-2026-28586

CVE-2026-28586_CVE-2026-28586

In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local inf...

Google Android 16-qpr2 CVE
LOW 3.3 CVE-2026-0056

CVE-2026-0056_CVE-2026-0056

In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclo...

Google Android 16-qpr2 CVE
LOW 3.3 CVE-2026-0050

CVE-2026-0050_CVE-2026-0050

In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead...

Google Android 16-qpr2 CVE
LOW 3.3 CVE-2026-0016

CVE-2026-0016_CVE-2026-0016

In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissio...

Google Android 16-qpr2 CVE
LOW 3.7 CVE-2026-24761

Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key_CVE-2026-24761

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Dat...

kiteworks Secure Data Forms < 9.3.0 CVE
LOW 3.7 CVE-2026-5419

Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal_CVE-2026-5419

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a re...

Red Hat Red Hat Enterprise Linux 10 0:3.8.10-4.el10_2 CVE