Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 CVE-2026-8916

CVE-2026-8916_CVE-2026-8916

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd...

Samsung Open Source rlottie dcfde72eae1b0464dc0dd760aec00ada6a148635 CVE
MEDIUM 6.9 CVE-2026-50226

Firmware Theft & IMEI Spoofing via Connect-OTA_CVE-2026-50226

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50225

Account Creation Exhaustion_CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 6.9 CVE-2026-50224

Unauthenticated IPv6 WAN Management Exposure_CVE-2026-50224

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API ...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.3 CVE-2026-50214

Shared Secret Quota Inflation_CVE-2026-50214

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost netw...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 6 CVE-2026-4881

CVE-2026-4881_CVE-2026-4881

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level ...

Octopus Deploy Octopus Server 2023.0.0 CVE
HIGH 7.6 CVE-2026-49771

WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability_CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL...

10Web Photo Gallery by 10Web n/a CVE
MEDIUM 6.1 CVE-2026-49510

CVE-2026-49510_CVE-2026-49510

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023...

Samsung Open Source rlottie 21292665023e5074b38254432716866d00f1985f CVE
MEDIUM 6.1 CVE-2026-47320

CVE-2026-47320_CVE-2026-47320

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Seriali...

Samsung Open Source rlottie eae37633fda13ac05b25c6c95aacea4bc33c80a3 CVE
MEDIUM 6.1 CVE-2026-47319

CVE-2026-47319_CVE-2026-47319

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: ...

Samsung Open Source rlottie 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd CVE