Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 CVE-2026-35353

uutils coreutils mkdir Permission Exposure Race Condition with -m_CVE-2026-35353

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35346

uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization_CVE-2026-35346

The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses Strin...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35344

uutils coreutils dd Silent Data Corruption via Unconditional Truncation Error Suppression_CVE-2026-35344

The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result::ok() on truncation attemp...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35343

uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters_CVE-2026-35343

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The ...

Uutils coreutils CVE
LOW 3.3 CVE-2026-35342

uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR_CVE-2026-35342

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp w...

Uutils coreutils CVE
LOW 2.7 CVE-2025-9957

Incorrect Authorization in GitLab_CVE-2025-9957

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that ...

GitLab GitLab 11.2 CVE
LOW 3.5 CVE-2026-3254

Improper Restriction of Rendered UI Layers or Frames in GitLab_CVE-2026-3254

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an...

GitLab GitLab 18.11 CVE
LOW 3.7 PACKETSTORM:219545

📄 Dovecot 3.1.0 Authentication Bypass / User Enumeration_PACKETSTORM:219545

This Metasploit auxiliary module targets an LDAP injection vulnerability in Dovecot mail servers that can lead to authentication bypass or user enu...

N/A N/A PACKETSTORM
LOW 3.1 CVE-2026-33599

Out-of-bounds read in service discovery_CVE-2026-33599

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) op...

PowerDNS DNSdist 1.9.0 CVE
LOW 3.7 CVE-2026-33597

PRSD detection denial of service_CVE-2026-33597

PRSD detection denial of service

PowerDNS DNSdist 1.9.0 CVE