Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-35387

CVE-2026-35387_CVE-2026-35387

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms ...

OpenBSD OpenSSH CVE
LOW 3.6 CVE-2026-35386

CVE-2026-35386_CVE-2026-35386

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where th...

OpenBSD OpenSSH CVE
LOW 3.7 CVE-2026-26961

Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypass_CVE-2026-26961

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter f...

rack rack < 2.2.23 CVE
LOW 3.3 CVE-2025-43236

CVE-2025-43236_CVE-2025-43236

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 1...

Apple macOS CVE
LOW 1.7 CVE-2026-34743

XZ Utils: Buffer overflow in lzma_index_append()_CVE-2026-34743

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to de...

tukaani-project xz < 5.8.3 CVE
LOW 2 CVE-2026-5420

Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key_CVE-2026-5420

A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.j...

Shinrays Games Goods Triple App 1 CVE
LOW 2.7 CVE-2026-34762

Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber_CVE-2026-34762

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from...

ellanetworks core < 1.8.0 CVE
LOW 3.7 CVE-2026-35537

CVE-2026-35537_CVE-2026-35537

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arb...

Roundcube Webmail CVE
LOW 3.1 CVE-2026-35538

CVE-2026-35538_CVE-2026-35538

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CS...

Roundcube Webmail CVE
LOW 2 CVE-2026-5473

NASA cFS Pickle pickle.load deserialization_CVE-2026-5473

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manip...

NASA cFS 7.0 CVE