Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2025-69755

CVE-2025-69755_CVE-2025-69755

An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via ...

n/a n/a n/a CVE
HIGH 7.1 CVE-2025-67448

CVE-2025-67448_CVE-2025-67448

The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user inp...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-67447

CVE-2025-67447_CVE-2025-67447

The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does...

Neterbit Neterbit NW-431F Router 20241014-IR03 and before CVE
MEDIUM 6.6 CVE-2026-48480

netty-incubator-codec-ohttp OHttpVersionChunkDraft’s Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation_CVE-2026-48480

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-...

netty netty-incubator-codec-ohttp < 0.0.22.Final CVE
HIGH 8.6 CVE-2026-41237

Froxlor has an incomplete fix for CVE-2026-30932_CVE-2026-41237

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowi...

froxlor froxlor < 2.3.7 CVE
HIGH 8.8 CVE-2026-41236

Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path_CVE-2026-41236

Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization pa...

froxlor froxlor = 2.3.6 CVE
HIGH 8.6 CVE-2026-41235

Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement_CVE-2026-41235

Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell ...

froxlor froxlor = 2.3.6 CVE
HIGH 7.6 CVE-2026-41234

Froxlor: BIND Zone File Injection via TXT Record Content_CVE-2026-41234

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline charact...

froxlor froxlor < 2.3.7 CVE
MEDIUM 5.3 CVE-2026-40898

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion_CVE-2026-40898

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HT...

quic-go quic-go < 0.59.1 CVE
MEDIUM 6.5 CVE-2026-36499

CVE-2026-36499_CVE-2026-36499

A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an ex...

n/a n/a n/a CVE