Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-47388

NocoDB: Missing Ownership Check in MCP Attachment Read_CVE-2026-47388

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment pat...

nocodb nocodb < 2026.05.1 CVE
LOW 3.7 CVE-2026-56968

CVE-2026-56968_CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosur...

GNU GNU SASL CVE
LOW 2.9 CVE-2026-57062

CVE-2026-57062_CVE-2026-57062

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to...

GnuPG GnuPG CVE
LOW 3.5 CVE-2025-15619

HCL Connections is vulnerable to broken access control_CVE-2025-15619

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

HCLSoftware Connections 7.0, 8.0 CVE
LOW 3.7 CVE-2026-55654

Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination_CVE-2026-55654

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Applicati...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 3.1 MS:CVE-2026-12458

Chromium: CVE-2026-12458 Incorrect security UI in Passwords_MS:CVE-2026-12458

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 2.1 CVE-2026-47241

Net::IMAP: Denial of Service via incomplete raw argument validation_CVE-2026-47241

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands ac...

ruby net-imap >= 0.6.0, < 0.6.4.1 CVE
LOW 3.1 CVE-2026-53663

React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass_CVE-2026-53663

React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on PO...

remix-run react-router >= 7.12.0, < 7.15.1 CVE
LOW 3.7 CVE-2026-48931

CVE-2026-48931_CVE-2026-48931

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerab...

nodejs node 22.22.3 CVE
LOW 3.7 CVE-2026-54282

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname_CVE-2026-54282

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request....

Kludex starlette < 1.3.0 CVE