Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-5107

FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control_CVE-2026-5107

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the comp...

FRRouting FRR 10.5.0 CVE
LOW 2.1 CVE-2026-28528

BlueKitchen BTstack < 1.8.1 AVRCP Browsing Target GET_FOLDER_ITEMS Handler OOB Read / Undefined Behavior_CVE-2026-28528

BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET_FOLDER_ITEMS handler that ...

BlueKitchen GmbH BTstack CVE
LOW 2.1 CVE-2026-28527

BlueKitchen BTstack < 1.8.1 AVRCP Controller GET_PLAYER_APPLICATION_SETTING_*_TEXT Handlers OOB Read_CVE-2026-28527

BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTR...

BlueKitchen GmbH BTstack CVE
LOW 2.1 CVE-2026-28526

BlueKitchen BTstack < 1.8.1 AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_* Handlers OOB Read_CVE-2026-28526

BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_ATT...

BlueKitchen GmbH BTstack CVE
LOW 3.8 CVE-2025-66215

OpenSC: Stack-buffer-overflow WRITE in card-oberthur_CVE-2025-66215

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time use...

OpenSC OpenSC < 0.27.0 CVE
LOW 3.9 CVE-2025-66038

OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers_CVE-2025-66038

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given...

OpenSC OpenSC < 0.27.0 CVE
LOW 3.9 CVE-2025-66037

OpenSC: Out of Bounds vulnerability_CVE-2025-66037

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes...

OpenSC OpenSC < 0.27.0 CVE
LOW 3.8 CVE-2025-49010

OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE_CVE-2025-49010

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time use...

OpenSC OpenSC < 0.27.0 CVE
LOW 3.3 CVE-2026-21716

CVE-2026-21716_CVE-2026-21716

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission check...

nodejs node 20.20.1 CVE
LOW 3.3 CVE-2026-21715

CVE-2026-21715_CVE-2026-21715

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all ...

nodejs node 20.20.1 CVE