Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-5188

Integer underflow in X.509 SAN parsing in wolfSSL_CVE-2026-5188

An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certifica...

wolfSSL wolfSSL CVE
LOW 2.9 CVE-2026-40228

CVE-2026-40228_CVE-2026-40228

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, i...

systemd systemd 259 CVE
LOW 2.3 CVE-2026-35648

OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions_CVE-2026-35648

OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when ...

OpenClaw OpenClaw CVE
LOW 3.7 CVE-2026-40097

Step CA affected by an index out of bounds panic in TPM attestation EKU validation_CVE-2026-40097

Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker c...

smallstep certificates >= 0.24.0, < 0.30.0-rc3 CVE
LOW 3.7 CVE-2026-40184

Unauthenticated Access to Uploaded Files in TREK_CVE-2026-40184

TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed i...

mauriceboe TREK < 2.7.2 CVE
LOW 3.7 CVE-2026-40194

phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()_CVE-2026-40194

phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operat...

phpseclib phpseclib < 1.0.28 CVE
LOW 2.9 CVE-2026-40354

CVE-2026-40354_CVE-2026-40354

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack...

Flatpak xdg-desktop-portal CVE
LOW 2.3 CVE-2026-27484

OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows_CVE-2026-27484

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender ident...

openclaw openclaw < 2026.2.18 CVE
LOW 2 CVE-2026-27467

BigBlueButton: Audio from participants to the server initially unmuted_CVE-2026-27467

BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client...

bigbluebutton bigbluebutton < 3.0.20 CVE
LOW 2.3 CVE-2026-27205

Flask session does not add `Vary: Cookie` header when accessed in some ways_CVE-2026-27205

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask s...

pallets flask < 3.1.3 CVE