Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 CVE-2026-47319

CVE-2026-47319_CVE-2026-47319

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: ...

Samsung Open Source rlottie 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd CVE
MEDIUM 6.1 CVE-2026-47318

CVE-2026-47318_CVE-2026-47318

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0d...

Samsung Open Source rlottie ce72b35a7ad0dded03051d3aa0ef75321c3bd035 CVE
MEDIUM 6.1 CVE-2026-47306

CVE-2026-47306_CVE-2026-47306

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before ...

Samsung Open Source rlottie e2d19e3b150e0e4a9586fa90b56fd3061cc98945 CVE
MEDIUM 6.1 CVE-2026-10305

CVE-2026-10305_CVE-2026-10305

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe76...

Samsung Open Source rlottie 223a2a41ba4f462e4abe767bebba49a366c9b9fd CVE
MEDIUM 6.9 CVE-2026-50210

Weak Static Cryptographic Initialization Vectors_CVE-2026-50210

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plai...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 4.9 CVE-2026-50219

CVE-2026-50219_CVE-2026-50219

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset ...

libexpat project libexpat CVE
MEDIUM 6.7 CVE-2026-10805

Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend_CVE-2026-10805

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malfo...

Red Hat Multicluster Engine for Kubernetes CVE
MEDIUM 6.9 CVE-2026-49204

Hard-coded AWS Cognito Testing Accounts_CVE-2026-49204

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.3 CVE-2026-49192

Summary Service Insecure Direct Object Reference_CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.8 CVE-2026-46447

CVE-2026-46447_CVE-2026-46447

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

OpenStack Ironic 17.0.0 CVE